CVE-2026-87595: Schwachstellen-Eintrag (NVD)
Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-16 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-68772 | ZenML up to 0.94.6 CloudpickleMaterializer cloudpickle_materializer.py cloudpickle.load deserialization
A vulnerability was found in ZenML up to 0.94.6. It has been rated as problematic. Impacted is the function cloudpickle.load of the file cloudpickle_materializer.py of the component CloudpickleMaterializer. Performing a manipulation results
CVE-2026-5855 | Contiki-NG LwM2M TLV parser lwm2m-tlv.c lwm2m_tlv_read length out-of-bounds
A vulnerability, which was classified as very critical, has been found in Contiki-NG. This impacts the function lwm2m_tlv_read of the file os/services/lwm2m/lwm2m-tlv.c of the component LwM2M TLV parser. Performing a manipulation of the arg
CVE-2026-5856 | Contiki-NG mDNS Resolver resolv.c skip_name out-of-bounds
A vulnerability was found in Contiki-NG. It has been classified as critical. This affects the function skip_name of the file os/services/resolv/resolv.c of the component mDNS Resolver. This manipulation causes out-of-bounds read. The identi
CVE-2026-53977 | Bohdan Triapitsyn OpenChamber up to 1.11.7 Route bootstrap-runtime.js improper authentication
A vulnerability was found in Bohdan Triapitsyn OpenChamber up to 1.11.7. It has been rated as critical. The affected element is an unknown function of the file bootstrap-runtime.js of the component Route Handler. The manipulation leads to i
CVE-2026-53975 | Bohdan Triapitsyn OpenChamber up to 1.11.7 Command Execution /api/fs/exec spawn os command injection
A vulnerability, which was classified as critical, was found in Bohdan Triapitsyn OpenChamber up to 1.11.7. This vulnerability affects the function spawn of the file /api/fs/exec of the component Command Execution. The manipulation results
CVE-2026-53976 | Bohdan Triapitsyn OpenChamber up to 1.11.7 File Serving /api/fs/read resolveReadPathFromContext allowOutsideWorkspace path traversal
A vulnerability has been found in Bohdan Triapitsyn OpenChamber up to 1.11.7 and classified as critical. This issue affects the function resolveReadPathFromContext of the file /api/fs/read of the component File Serving. This manipulation of
CVE-2026-70617 | Spacebar Server Channels Recipient Endpoint authorization (dcfd910)
A vulnerability marked as critical has been reported in Spacebar Server. Affected by this vulnerability is an unknown functionality of the component Channels Recipient Endpoint. Performing a manipulation results in missing authorization. Th
CVE-2026-70618 | Spacebar Server Roles Member-Ids Endpoint improper authorization
A vulnerability classified as problematic has been found in Spacebar Server. This affects an unknown part of the component Roles Member-Ids Endpoint. The manipulation leads to improper authorization. This vulnerability is traded as CVE-2026
CVE-2022-4995 | Weaver Network E-cology up to 10.51 uploaderOperate.jsp secId/plandetailid unrestricted upload
A vulnerability, which was classified as critical, has been found in Weaver Network E-cology up to 10.51. This issue affects some unknown processing of the file /workrelate/plan/util/uploaderOperate.jsp. The manipulation of the argument sec
CVE-2022-44193 | Netgear R7000P 1.3.1.64 /usr/sbin/httpd starthour/startminute /endhour/endminute buffer overflow (EUVD-2022-47143)
A vulnerability labeled as critical has been found in Netgear R7000P 1.3.1.64. This issue affects some unknown processing of the file /usr/sbin/httpd. Such manipulation of the argument starthour/startminute /endhour/endminute leads to buffe
CVE-2022-44191 | Netgear R7000P 1.3.1.64 KEY1/KEY2 buffer overflow (EUVD-2022-47141)
A vulnerability identified as critical has been detected in Netgear R7000P 1.3.1.64. This vulnerability affects unknown code. This manipulation of the argument KEY1/KEY2 causes buffer overflow. This vulnerability is registered as CVE-2022-4
CVE-2022-44190 | Netgear R7000P 1.3.1.64 enable_band_steering buffer overflow (EUVD-2022-47140)
A vulnerability categorized as critical has been discovered in Netgear R7000P 1.3.1.64. This affects an unknown part. The manipulation of the argument enable_band_steering results in buffer overflow. This vulnerability is cataloged as CVE-2
CVE-2022-44188 | Netgear R7000P 1.3.0.8 /usr/sbin/httpd enable_band_steering buffer overflow (EUVD-2022-47138)
A vulnerability was found in Netgear R7000P 1.3.0.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /usr/sbin/httpd. The manipulation of the argument enable_band_steering leads to buffer over
CVE-2026-69110 | Microck opencode-studio up to 2.4.3 missing authentication
A vulnerability categorized as critical has been discovered in Microck opencode-studio up to 2.4.3. Affected by this issue is some unknown functionality. The manipulation results in missing authentication. This vulnerability was named CVE-2
CVE-2026-69100 | dromara lamp-cloud up to 5.6.2 GlueFactory os command injection
A vulnerability was found in dromara lamp-cloud up to 5.6.2. It has been declared as very critical. Affected is an unknown function of the component GlueFactory. Executing a manipulation can lead to os command injection. This vulnerability
CVE-2025-71399 | better-auth Better Auth up to 1.4.4 Router privileges management (EUVD-2025-210590)
A vulnerability classified as critical has been found in better-auth Better Auth up to 1.4.4. This affects an unknown function of the component Router. The manipulation leads to improper privilege management. This vulnerability is traded as
CVE-2026-67326 | gitpython-developers GitPython up to 3.1.49 Config Writer config_writer section injection (EUVD-2026-51814 / Nessus ID 331643)
A vulnerability, which was classified as critical, was found in gitpython-developers GitPython up to 3.1.49. The impacted element is the function config_writer of the component Config Writer. Executing a manipulation of the argument section
CVE-2026-67309 | Traefik up to 3.7.7 RewriteTarget Middleware path traversal (EUVD-2026-51815)
A vulnerability identified as critical has been detected in Traefik up to 3.7.7. Affected by this vulnerability is an unknown functionality of the component RewriteTarget Middleware. Performing a manipulation results in path traversal. This
CVE-2026-20316 | Cisco Secure Firewall Management Center up to 10.0.1 Web Interface information disclosure (EUVD-2026-50404)
A vulnerability was found in Cisco Secure Firewall Management Center. It has been classified as problematic. Affected is an unknown function of the component Web Interface. Performing a manipulation results in information disclosure. This v
CVE-2026-92592 | craftcms Craft CMS up to 4.18.5/5.10.12 Twig template system redirect (EUVD-2026-81292)
A vulnerability identified as problematic has been detected in craftcms Craft CMS up to 4.18.5/5.10.12. The affected element is the function system of the component Twig template. The manipulation of the argument redirect leads to open redi
CVE-2026-92593 | craftcms Craft CMS up to 5.10.12 Redirect renderObjectTemplate returnUrl/redirect special elements in template engine (EUVD-2026-81293)
A vulnerability was found in craftcms Craft CMS up to 5.10.12. It has been rated as critical. This issue affects the function View::renderObjectTemplate of the component Redirect Handler. Performing a manipulation of the argument returnUrl/
CVE-2026-92594 | Craft CMS up to 5.10.x GraphQL Resolver Gql::canQueryUsers improper authorization (EUVD-2026-81294)
A vulnerability marked as problematic has been reported in Craft CMS up to 5.10.x. This vulnerability affects the function Gql::canQueryUsers of the component GraphQL Resolver. The manipulation leads to improper authorization. This vulnerab
CVE-2026-92595 | Nodemailer up to 9.1.0 Content Resolution MailMessage.resolveContent data/key/callback server-side request forgery (EUVD-2026-81295)
A vulnerability described as critical has been identified in Nodemailer up to 9.1.0. This issue affects the function MailMessage.resolveContent of the component Content Resolution. The manipulation of the argument data/key/callback results
CVE-2026-92597 | Nodemailer up to 9.0.x Addressparser lib/addressparser input validation (EUVD-2026-81297)
A vulnerability was found in Nodemailer up to 9.0.x. It has been classified as critical. This affects an unknown function of the file lib/addressparser of the component Addressparser. The manipulation leads to improper input validation. Thi
CVE-2026-92596 | Nodemailer up to 9.0.x Addressparser resource consumption (EUVD-2026-81296)
A vulnerability was found in Nodemailer up to 9.0.x and classified as problematic. The impacted element is an unknown function of the component Addressparser. Executing a manipulation can lead to resource consumption. This vulnerability is
CVE-2026-92598 | Nodemailer up to 9.0.x Domain Resolver encoding error (EUVD-2026-81298)
A vulnerability labeled as critical has been found in Nodemailer up to 9.0.x. This affects an unknown part of the component Domain Resolver. Executing a manipulation can lead to encoding error. This vulnerability is handled as CVE-2026-9259
CVE-2026-92599 | hapijs joi up to 17.13.6/18.0.0-18.2.5 isoDate Joi.string.isoDate redos (EUVD-2026-81299)
A vulnerability was found in hapijs joi up to 17.13.6/18.0.0-18.2.5. It has been declared as problematic. This impacts the function Joi.string.isoDate of the component isoDate. The manipulation results in inefficient regular expression comp
CVE-2026-73447 | Arista EOS up to 4.36.0.1F Certz service/Bootz service os command injection (WID-SEC-2026-3287)
A vulnerability was found in Arista EOS up to 4.36.0.1F and classified as very critical. The impacted element is an unknown function of the component Certz service/Bootz service. Such manipulation leads to os command injection. This vulnera
CVE-2026-73446 | Arista EOS up to 4.36.1F Broadcast Interface resource consumption (WID-SEC-2026-3287)
A vulnerability classified as critical has been found in Arista EOS up to 4.36.1F. The impacted element is an unknown function of the component Broadcast Interface. Performing a manipulation results in resource consumption. This vulnerabili
CVE-2026-73444 | Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F VRRP improper authentication (WID-SEC-2026-3287)
A vulnerability marked as very critical has been reported in Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F. Impacted is an unknown function of the component VRRP. The manipulation leads to improper authentication. This vulnerability is t
CVE-2026-73443 | Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F VRRP authentication replay (WID-SEC-2026-3287)
A vulnerability, which was classified as critical, has been found in Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F. This impacts an unknown function of the component VRRP. The manipulation leads to authentication bypass by capture-replay
CVE-2026-73442 | Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F VRRP missing encryption (WID-SEC-2026-3287)
A vulnerability classified as problematic was found in Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F. This affects an unknown function of the component VRRP. Executing a manipulation can lead to missing encryption of sensitive data. The
CVE-2026-73440 | Arista EOS up to 4.36.1F SNMP improper authorization (WID-SEC-2026-3287)
A vulnerability was found in Arista EOS up to 4.32.x/4.33.9M/4.34.7.1M/4.35.5M/4.36.1F. It has been declared as critical. This affects an unknown function of the component SNMP. The manipulation results in improper authorization. This vulne
CVE-2026-73437 | Arista EOS up to 4.33.9M/4.34.7.1M/4.35.5M/4.36.1F DHCP denial of service (WID-SEC-2026-3287)
A vulnerability labeled as very critical has been found in Arista EOS up to 4.33.9M/4.34.7.1M/4.35.5M/4.36.1F. This issue affects some unknown processing of the component DHCP Handler. Executing a manipulation can lead to denial of service.
CVE-2026-19655 | Arista EOS up to 4.33.9M/4.34.7.1M/4.35.5M DHCP Relay Service input validation (WID-SEC-2026-3287)
A vulnerability marked as critical has been reported in Arista EOS up to 4.33.9M/4.34.7.1M/4.35.5M. Affected by this issue is some unknown functionality of the component DHCP Relay Service. This manipulation causes improper input validation
CVE-2020-20212 | MikroTik RouterOS 6.44.5 /nova/bin/console null pointer dereference
A vulnerability described as problematic has been identified in MikroTik RouterOS 6.44.5. The impacted element is an unknown function of the file /nova/bin/console. Such manipulation leads to null pointer dereference. This vulnerability is
CVE-2020-20211 | MikroTik RouterOS 6.44.5 /nova/bin/console denial of service
A vulnerability marked as problematic has been reported in MikroTik RouterOS 6.44.5. The affected element is an unknown function of the file /nova/bin/console. This manipulation causes denial of service. This vulnerability appears as CVE-20
CVE-2017-17537 | MikroTik RouterBOARD 6.39.2/6.40.5 TCP Service 53 input validation (EDB-43200 / ID 860320)
A vulnerability was found in MikroTik RouterBOARD 6.39.2/6.40.5. It has been rated as problematic. This vulnerability affects unknown code of the component TCP Service 53. The manipulation leads to improper input validation. This vulnerabil
CVE-2017-6297 | MikroTik RouterOS 6.37.4/6.83.3 L2TP Client IPsec 7pk security (BID-96447 / ID 103115)
A vulnerability categorized as critical has been discovered in MikroTik RouterOS 6.37.4/6.83.3. This affects an unknown part of the component L2TP Client. The manipulation results in 7pk security features (IPsec). This vulnerability was nam
CVE-2023-27169 | Xpand IT Write-Back Manager 2.3.1 hash predictable salt (EUVD-2023-30949)
A vulnerability marked as problematic has been reported in Xpand IT Write-Back Manager 2.3.1. This impacts an unknown function. Performing a manipulation results in use of a one-way hash with a predictable salt. This vulnerability was named
CVE-2023-27170 | Xpand IT Write-Back Manager 2.3.1 siteName path traversal (EUVD-2023-30950)
A vulnerability has been found in Xpand IT Write-Back Manager 2.3.1 and classified as critical. This issue affects some unknown processing. Performing a manipulation of the argument siteName results in path traversal. This vulnerability is
CVE-2024-33668 | Zammad up to 6.2.x Upload Cache excessive authentication
A vulnerability classified as problematic was found in Zammad up to 6.2.x. This affects an unknown part of the component Upload Cache. Executing a manipulation can lead to improper restriction of excessive authentication attempts. This vuln
CVE-2022-44187 | Netgear R7000P 1.3.0.8 wan_dns1_pri buffer overflow (EUVD-2022-47137)
A vulnerability was found in Netgear R7000P 1.3.0.8. It has been declared as critical. Affected by this vulnerability is the function wan_dns1_pri. Executing a manipulation can lead to buffer overflow. This vulnerability is tracked as CVE-2
CVE-2022-44186 | Netgear R7000P 1.3.1.64 /usr/sbin/httpd wan_dns1_pri buffer overflow (EUVD-2022-47136)
A vulnerability was found in Netgear R7000P 1.3.1.64. It has been classified as critical. Affected is an unknown function of the file /usr/sbin/httpd. Performing a manipulation of the argument wan_dns1_pri results in buffer overflow. This v
CVE-2022-44184 | Netgear R7000P 1.3.0.8 /usr/sbin/httpd wan_dns1_sec buffer overflow (EUVD-2022-47134)
A vulnerability has been found in Netgear R7000P 1.3.0.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/httpd. Performing a manipulation of the argument wan_dns1_sec results in b
CVE-2022-44183 | Tenda AC18 15.03.05.19 formSetWifiGuestBasic buffer overflow (EUVD-2022-47133)
A vulnerability described as critical has been identified in Tenda AC18 15.03.05.19. Affected is the function formSetWifiGuestBasic. Executing a manipulation can lead to buffer overflow. The identification of this vulnerability is CVE-2022-
CVE-2026-85880 | Microsoft Windows up to Server 2022 ALPC heap-based overflow (EUVD-2026-73365)
A vulnerability was found in Microsoft Windows up to Server 2022. It has been declared as very critical. The impacted element is an unknown function of the component ALPC. Such manipulation leads to heap-based buffer overflow. This vulnerab
CVE-2026-61588 | djust-org djust up to 1.0.6 information disclosure (EUVD-2026-81304)
A vulnerability categorized as problematic has been discovered in djust-org djust up to 1.0.6. Affected by this vulnerability is an unknown functionality. Such manipulation leads to information disclosure. This vulnerability is traded as CV
CVE-2026-61589 | djust-org djust up to 1.0.6 Tenant Resolution ViewRuntime._build_request information disclosure (EUVD-2026-81306)
A vulnerability, which was classified as problematic, was found in djust-org djust up to 1.0.6. Impacted is the function ViewRuntime._build_request of the component Tenant Resolution. Such manipulation leads to information disclosure. This
CVE-2026-61596 | djust-org djust up to 1.0.6 Render Entry Points get_object/has_object_permission authorization (EUVD-2026-81305)
A vulnerability, which was classified as critical, has been found in djust-org djust up to 1.0.6. This issue affects the function get_object/has_object_permission of the component Render Entry Points. This manipulation causes authorization
CVE-2026-61599 | djust-org djust up to 1.0.6 Live Transport __import__ view input validation (EUVD-2026-81307)
A vulnerability classified as critical was found in djust-org djust up to 1.0.6. This vulnerability affects the function __import__ of the component Live Transport. The manipulation of the argument view results in improper input validation.
CVE-2026-57173 | vllm-project vLLM up to 0.23.x Audio Decoder /v1/chat/completions AudioMediaIO.load_bytes resource consumption (EUVD-2026-80880)
A vulnerability, which was classified as problematic, has been found in vllm-project vLLM up to 0.23.x. This affects the function AudioMediaIO.load_bytes of the file /v1/chat/completions of the component Audio Decoder. Performing a manipula
CVE-2026-59193 | getgrav Grav up to 1.x ZIP Archive extractTo denial of service (EUVD-2026-42951)
A vulnerability identified as problematic has been detected in getgrav Grav up to 1.x. This affects the function extractTo of the component ZIP Archive Handler. The manipulation leads to denial of service. This vulnerability is documented a
CVE-2026-63128 | modelcontextprotocol rust-sdk up to 1.x Streamable HTTP Server tower.rs handle_post initialization (EUVD-2026-80823)
A vulnerability was found in modelcontextprotocol rust-sdk up to 1.x. It has been declared as problematic. This issue affects the function StreamableHttpService::handle_post of the file crates/rmcp/src/transport/streamable_http_server/tower
CVE-2026-63127 | Model Context Protocol RMCP SDK up to 1.x OAuth Implementation auth.rs discover_oauth_server_via_resource_metadata improper authorization (EUVD-2026-80824)
A vulnerability classified as problematic was found in Model Context Protocol RMCP SDK up to 1.x. This impacts the function discover_oauth_server_via_resource_metadata of the file crates/rmcp/src/transport/auth.rs of the component OAuth Imp
CVE-2026-63671 | nuxt-content mdc up to 0.22.0 Sanitizer parseMarkdown allowDangerousHtml cross site scripting (EUVD-2026-80789)
A vulnerability, which was classified as problematic, has been found in nuxt-content mdc up to 0.22.0. The impacted element is the function parseMarkdown of the component Sanitizer. This manipulation of the argument allowDangerousHtml cause
CVE-2026-61709 | OpenFGA up to 1.18.0 ListUsers API list_users_rpc.go expandIntersection improper authorization (EUVD-2026-80777)
A vulnerability categorized as problematic has been discovered in OpenFGA up to 1.18.0. This affects the function expandIntersection of the file pkg/server/commands/listusers/list_users_rpc.go of the component ListUsers API. Executing a man
CVE-2026-58657 | Grav up to 2.0.0-rc.9 Media Action processMediaActions resize injection (EUVD-2026-42267)
A vulnerability labeled as problematic has been found in Grav up to 2.0.0-rc.9. This affects the function Excerpts::processMediaActions of the component Media Action Handler. The manipulation of the argument resize results in injection. Thi
CVE-2026-65388 | Apple containerization up to 0.40.x information disclosure (EUVD-2026-81274)
A vulnerability classified as problematic has been found in Apple containerization up to 0.40.x. Impacted is an unknown function. This manipulation causes information disclosure. The identification of this vulnerability is CVE-2026-65388. I
CVE-2026-92802 | kanbn kan up to 0.6.0 GitHub Project Import Endpoint improper authorization (EUVD-2026-81062)
A vulnerability identified as problematic has been detected in kanbn kan up to 0.6.0. This affects an unknown part of the component GitHub Project Import Endpoint. This manipulation causes improper authorization. This vulnerability is track