🎯 CVE-2026-88994
📄 .md Alle CVEs anzeigen ✕

CVE-2026-88994: Schwachstellen-Eintrag (NVD)

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file containing PHP code can be reached. Exploitation requires the plugin's Lightspeed subsystem to be enabled, which is not the default.

Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📰 Eigene Berichterstattung: ➔ CVE-2026-88994 | All Bootstrap Blocks Plugin up to 1.3.31 on WordPress Block Att
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 6.6
AV · Angriffsvektor Netzwerk
AC · Komplexität Hoch
PR · Privilegien Hoch
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Veröffentlicht:18.09.2026
Aktualisiert:18.09.2026 07:16
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
2 🔴 Critical im Radar
1 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 105 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.868 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-17
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
EPSS 32.1%
CVE-2026-40534 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-40534 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Video API cross site scripting (EUVD-2026-82789)

A vulnerability classified as problematic has been found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. Affected by this issue is some unknown functionality of the component Video API. The manipulation leads to cro

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 5%
CVE-2026-40532 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-40532 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Wallpaper Path information disclosure (EUVD-2026-82788)

A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 and classified as problematic. This vulnerability affects unknown code of the component Wallpaper Path. Such manipulation leads to information

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22.9%
CVE-2026-40537 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-40537 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 PersonMail API server-side request forgery (EUVD-2026-82791)

A vulnerability classified as problematic was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. This affects an unknown part of the component PersonMail API. The manipulation results in server-side request forge

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.1%
CVE-2026-40536 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-40536 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Audio API path traversal (EUVD-2026-82790)

A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. It has been rated as problematic. The affected element is an unknown function of the component Audio API. The manipulation leads to path trav

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.9%
CVE-2026-75157 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-75157 | Apache Airflow Asset Queued Events Endpoint privileges management (EUVD-2026-82766)

A vulnerability labeled as problematic has been found in Apache Airflow. Affected is an unknown function of the component Asset Queued Events Endpoint. The manipulation results in improper privilege management. This vulnerability is known a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
EPSS 27.9%
CVE-2026-21822 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-21822 | HCL AppScan ASReportService path traversal (EUVD-2026-82851)

A vulnerability identified as critical has been detected in HCL AppScan. Affected by this vulnerability is an unknown functionality of the component ASReportService. Performing a manipulation results in path traversal. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.5%
CVE-2025-13533 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-13533 | wipeoutmedia CSS &amp; JavaScript Toolbox Plugin up to 12.0.6 on WordPress Assignment Engine cross site scripting (EUVD-2025-210931)

A vulnerability, which was classified as problematic, has been found in wipeoutmedia CSS &amp;amp; JavaScript Toolbox Plugin up to 12.0.6 on WordPress. Affected by this vulnerability is an unknown functionality of the component Assignment E

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 32.6%
CVE-2026-18405 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-18405 | jegtheme Jeg Kit for Elementor Plugin up to 3.2.16 on WordPress cross site scripting (EUVD-2026-82852)

A vulnerability, which was classified as problematic, was found in jegtheme Jeg Kit for Elementor Plugin up to 3.2.16 on WordPress. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 31.2%
CVE-2026-89058 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89058 | Red Hat RESTEasy prior 6.2.19.Final/7.0.5.Final CorsFilter cross-domain policy (EUVD-2026-82736)

A vulnerability was found in Red Hat RESTEasy. It has been declared as problematic. The impacted element is an unknown function of the component CorsFilter. Executing a manipulation can lead to permissive cross-domain policy with untrusted

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22.2%
CVE-2026-90884 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-90884 | WP Recipe Maker Plugin up to 10.8.1 on WordPress notes cross site scripting (EUVD-2026-82853)

A vulnerability, which was classified as problematic, has been found in WP Recipe Maker Plugin up to 10.8.1 on WordPress. The affected element is an unknown function. Performing a manipulation of the argument notes results in cross site scr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 20.1%
CVE-2026-15797 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-15797 | danieliser Popup Maker Plugin up to 1.24.0 on WordPress Select2 sanitize_text_field post_title cross site scripting (EUVD-2026-82854)

A vulnerability classified as problematic has been found in danieliser Popup Maker Plugin up to 1.24.0 on WordPress. This issue affects the function sanitize_text_field of the component Select2. This manipulation of the argument post_title

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 26.1%
CVE-2026-87915 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
WordPress

CVE-2026-87915 | danieliser Popup Maker Plugin up to 1.24.0 on WordPress Input Sanitization wp-admin/js/common.js jQuery.attr Name cross site scripting (EUVD-2026-82855)

A vulnerability classified as problematic was found in danieliser Popup Maker Plugin up to 1.24.0 on WordPress. Impacted is the function jQuery.attr of the file wp-admin/js/common.js of the component Input Sanitization. Such manipulation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [niedrig] expat: Schwachstelle ermöglicht Denial of Service

Ein lokaler Angreifer kann eine Schwachstelle in expat ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [mittel] Red Hat CloudForms: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Benutzerrechten

Ein lokaler Angreifer kann eine Schwachstelle in Red Hat CloudForms ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen oder einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 3.5%
CVE-2026-86863 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Critical pgAdmin Authentication Bypass Lets Attackers Login as Administrator Without Credentials

A critical vulnerability in pgAdmin 4 could allow unauthenticated remote attackers to impersonate arbitrary users, including existing administrator accounts, by supplying a malicious HTTP identity header. This vulnerability, tracked as CVE-

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.6%
CVE-2026-4130 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-4130 | NI SystemLink/SystemLink Server up to 26.5.0 missing encryption

A vulnerability, which was classified as problematic, was found in NI SystemLink and SystemLink Server up to 26.5.0. Affected by this vulnerability is an unknown functionality. The manipulation results in missing encryption of sensitive dat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.2%
CVE-2026-81048 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81048 | Dell ThinOS up to 2605_10.2615 command injection

A vulnerability was found in Dell ThinOS up to 2605_10.2615. It has been classified as very critical. Affected by this vulnerability is an unknown functionality. This manipulation causes command injection. This vulnerability is tracked as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.5%
CVE-2026-4129 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-4129 | NI SystemLink/SystemLink Server up to 26.5.0 access control

A vulnerability was found in NI SystemLink and SystemLink Server up to 26.5.0 and classified as critical. Affected is an unknown function. The manipulation results in improper access controls. This vulnerability is identified as CVE-2026-41

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23.3%
CVE-2026-85544 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85544 | Hikvision DS-KV8114 cryptographic issue

A vulnerability, which was classified as problematic, was found in Hikvision DS-KV9503, DS-KV6113, DS-KV6103, DS-KV6133, DS-KV8113, DS-KV8213, DS-KV8413, DS-KD8003, DS-KD8005, DS-KV6114, DS-KV6124, DS-KV6134 and DS-KV8114. This impacts an u

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23.2%
CVE-2026-61915 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-61915 | Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 CalDAV double free

A vulnerability was found in Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component CalDAV. The manipulation results in double free. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.5%
CVE-2026-61910 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-61910 | Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 Mailbox Mailbox/set privileges management (EUVD-2026-75130)

A vulnerability described as critical has been identified in Cyrus IMAP up to 3.8.7/3.10.3/3.12.3. Impacted is the function Mailbox/set of the component Mailbox. The manipulation results in improper privilege management. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.2%
CVE-2026-61909 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-61909 | Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 CalDAV/CardDAV information disclosure

A vulnerability classified as problematic has been found in Cyrus IMAP up to 3.8.7/3.10.3/3.12.3. The affected element is an unknown function of the component CalDAV/CardDAV. This manipulation causes information disclosure. The identificati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28%
CVE-2026-87817 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87817 | gitpython-developers GitPython up to 3.1.59 Git Directory Validation index.commit code injection (EUVD-2026-74843 / Nessus ID 344426)

A vulnerability, which was classified as critical, has been found in gitpython-developers GitPython up to 3.1.59. The impacted element is the function index.commit of the component Git Directory Validation. Performing a manipulation results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.8%
CVE-2026-61908 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-61908 | Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 JMAP Blob ID out-of-bounds

A vulnerability was found in Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 and classified as critical. This affects an unknown function of the component JMAP Blob ID Handler. Executing a manipulation can lead to out-of-bounds read. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.7%
CVE-2022-44411 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44411 | Web Based Quiz System 1.0 missing encryption (EUVD-2022-47354)

A vulnerability identified as problematic has been detected in Web Based Quiz System 1.0. This impacts an unknown function. Performing a manipulation results in missing encryption of sensitive data. This vulnerability is reported as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19%
CVE-2022-44414 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44414 | Automotive Shop Management System 1.0 manage_service.php ID sql injection (EUVD-2022-47357)

A vulnerability identified as critical has been detected in Automotive Shop Management System 1.0. This issue affects some unknown processing of the file /asms/admin/services/manage_service.php. This manipulation of the argument ID causes s

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18.9%
CVE-2022-44413 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44413 | Automotive Shop Management System 1.0 manage_mechanic.php ID sql injection (EUVD-2022-47356)

A vulnerability categorized as critical has been discovered in Automotive Shop Management System 1.0. This vulnerability affects unknown code of the file /asms/admin/mechanics/manage_mechanic.php. The manipulation of the argument ID results

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.4%
CVE-2022-44403 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44403 | Automotive Shop Management System 1.0 manage_user ID sql injection (EUVD-2022-47346)

A vulnerability marked as critical has been reported in Automotive Shop Management System 1.0. Affected is an unknown function of the file /asms/admin/?page=user/manage_user. Performing a manipulation of the argument ID results in sql injec

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22.8%
CVE-2022-44402 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44402 | oretnom23 Automotive Shop Management System 1.0 Master.php?f=delete_transaction sql injection (EUVD-2022-47345)

A vulnerability was found in oretnom23 Automotive Shop Management System 1.0. It has been declared as critical. Impacted is an unknown function of the file /asms/classes/Master.php?f=delete_transaction. Executing a manipulation can lead to

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32%
CVE-2026-83561 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-83561 | Complianz GDPR/CCPA Cookie Consent Banner Plugin up to 7.5.4 on WordPress Elementor Cookie Blocker Regex cross site scripting (EUVD-2026-82792)

A vulnerability described as problematic has been identified in Complianz GDPR and CCPA Cookie Consent Banner Plugin up to 7.5.4 on WordPress. This vulnerability affects unknown code of the component Elementor Cookie Blocker Regex. The mani

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 30.6%
CVE-2026-85410 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-85410 | pixarlabs Master Addons for Elementor Plugin up to 3.2.2 on WordPress popup_id authorization (EUVD-2026-82793)

A vulnerability has been found in pixarlabs Master Addons for Elementor Plugin up to 3.2.2 on WordPress and classified as problematic. Impacted is an unknown function. Performing a manipulation of the argument popup_id results in authorizat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 3%
CVE-2026-40533 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-40533 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Desktop API information disclosure (EUVD-2026-82794)

A vulnerability labeled as problematic has been found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. This impacts an unknown function of the component Desktop API. Such manipulation leads to information disclosure.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18.3%
CVE-2026-40535 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-40535 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Desktop API path traversal (EUVD-2026-82795)

A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. It has been declared as critical. Impacted is an unknown function of the component Desktop API. Executing a manipulation can lead to path tra

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.6%
CVE-2026-40538 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-40538 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Auto block excessive authentication (EUVD-2026-82796)

A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. It has been classified as problematic. This issue affects some unknown processing of the component Auto block. Performing a manipulation resu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.2%
CVE-2026-40539 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-40539 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Email API certificate validation (EUVD-2026-82797)

A vulnerability marked as problematic has been reported in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. Affected is an unknown function of the component Email API. Performing a manipulation results in improper certi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.5%
CVE-2026-69797 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69797 | Microsoft Office 365 Apps for Enterprise use after free (Nessus ID 344563)

A vulnerability, which was classified as problematic, was found in Microsoft Office 365 Apps for Enterprise, Office LTSC, Office LTSC for Mac and PowerPoint. Affected is an unknown function. Such manipulation leads to use after free. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 31.6%
CVE-2026-83941 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-83941 | Microsoft Entra improper authorization

A vulnerability was found in Microsoft Entra. It has been declared as critical. This vulnerability affects unknown code. Executing a manipulation can lead to improper authorization. This vulnerability is registered as CVE-2026-83941. It is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 25.2%
CVE-2026-69820 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69820 | Microsoft Windows up to 11 26H1 Hello buffer overflow

A vulnerability was found in Microsoft Windows up to 11 26H1. It has been rated as very critical. Affected is an unknown function of the component Hello. The manipulation leads to buffer overflow. This vulnerability is referenced as CVE-202

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 26.2%
CVE-2026-72980 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-72980 | Microsoft Windows up to Server 2025 Windows Hello uncontrolled search path

A vulnerability categorized as critical has been discovered in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component Windows Hello. Such manipulation leads to uncontrolled search path. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 30%
CVE-2026-69874 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69874 | Microsoft Windows up to Server 2025 ALPC privileges management

A vulnerability identified as critical has been detected in Microsoft Windows up to Server 2025. This issue affects some unknown processing of the component ALPC. This manipulation causes improper privilege management. This vulnerability ap

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 2.9%
CVE-2026-69832 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69832 | Microsoft Windows up to Server 2025 Win32K information disclosure

A vulnerability has been found in Microsoft Windows and classified as problematic. This impacts an unknown function of the component Win32K. This manipulation causes information disclosure. This vulnerability is tracked as CVE-2026-69832. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 24.8%
CVE-2026-77491 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-77491 | Microsoft Windows up to Server 2025 GDI out-of-bounds

A vulnerability categorized as problematic has been discovered in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component GDI. Executing a manipulation can lead to out-of-bounds read. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 25%
CVE-2026-69739 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69739 | Microsoft Office out-of-bounds

A vulnerability was found in Microsoft Office. It has been declared as problematic. This impacts an unknown function. The manipulation results in out-of-bounds read. This vulnerability is identified as CVE-2026-69739. The attack can be exec

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 28.1%
CVE-2026-67643 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-67643 | Microsoft SQL Server heap-based overflow

A vulnerability classified as very critical has been found in Microsoft SQL Server. This vulnerability affects unknown code. The manipulation leads to heap-based buffer overflow. This vulnerability is uniquely identified as CVE-2026-67643.

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Pixel-Update schnell installieren: <b>Hacker</b> nutzen Sicherheitslücke bereits aus - t3n

Google veröffentlicht wichtiges Pixel-Update: Eine Zero-Click-Sicherheitslücke wird bereits aktiv von Hackern ausgenutzt. Jetzt installieren. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Pixel-Update schnell installieren: Hacker nutzen Sicherheitslücke bereits aus

Google hat ein neues Update für seine Pixel-Smartphones veröffentlicht. Neben praktischen Funktionen enthält die Aktualisierung aber auch einen wichtigen Fix für eine aktiv ausgenutzte Sicherheitslücke. Was dazu bekannt ist. weiterlesen auf

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Pixel-Update schnell installieren: Hacker nutzen Sicherheitslücke bereits aus

Google hat ein neues Update für seine Pixel-Smartphones veröffentlicht. Neben praktischen Funktionen enthält die Aktualisierung aber auch einen wichtigen Fix für eine aktiv ausgenutzte Sicherheitslücke. Was dazu bekannt ist. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 76.5%
CVE-2026-58138 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Critical Orkes Conductor Vulnerability Exploited in Attacks

CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek. Weiter

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.6%
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

USN-8715-2: Linux kernel (AWS FIPS) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 23.8%
CVE-2026-53043 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

USN-8714-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - OCFS2 file system; - SCTP protocol; (CVE-2026-53043, CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 22.4%
CVE-2025-10072 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10072 | Portabilis i-Educar up to 2.10 enturmar access control (EUVD-2025-27098)

A vulnerability marked as critical has been reported in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing a manipulation results in improper access controls.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.6%
CVE-2025-65024 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-65024 | Portabilis i-Educar up to 2.10.0 agenda_admin_cad.php cod_agenda sql injection (GHSA-6c8p-xqcv-rghx)

A vulnerability has been found in Portabilis i-Educar up to 2.10.0 and classified as critical. This vulnerability affects unknown code of the file ieducar/intranet/agenda_admin_cad.php. The manipulation of the argument cod_agenda leads to s

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.7%
CVE-2025-65023 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-65023 | Portabilis i-Educar up to 2.10.0 funcionario_vinculo_cad.php cod_funcionario_vinculo sql injection (GHSA-8rv6-x8h9-fjfc)

A vulnerability, which was classified as critical, was found in Portabilis i-Educar up to 2.10.0. This affects an unknown part of the file ieducar/intranet/funcionario_vinculo_cad.php. Executing a manipulation of the argument cod_funcionari

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [mittel] vim: Schwachstelle ermöglicht Codeausführung

Ein Angreifer kann eine Schwachstelle in vim ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [hoch] vim: Schwachstelle ermöglicht Codeausführung

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vim ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30%
CVE-2022-44401 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44401 | Online Tours &amp; Travels Management System 1.0 /tour/admin/file.php unrestricted upload (EUVD-2022-47344)

A vulnerability described as very critical has been identified in Online Tours &amp;amp; Travels Management System 1.0. This affects an unknown function of the file /tour/admin/file.php. The manipulation results in unrestricted upload. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.8%
CVE-2022-44400 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44400 | oretnom23 Purchase Order Management System 1.0 ?page=system_info unrestricted upload (EUVD-2022-47343)

A vulnerability was found in oretnom23 Purchase Order Management System 1.0. It has been declared as very critical. Impacted is an unknown function of the file /purchase_order/admin/?page=system_info. Such manipulation leads to unrestricted

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.2%
CVE-2022-44399 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44399 | Poultry Farm Management System 1.0 category.php del sql injection (EUVD-2022-47342)

A vulnerability marked as critical has been reported in Poultry Farm Management System 1.0. The impacted element is an unknown function of the file /Redcock-Farm/farm/category.php. The manipulation of the argument del leads to sql injection

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.8%
CVE-2022-44393 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44393 | oretnom23 Sanitization Management System 1.0 view_service ID sql injection (EUVD-2022-47336)

A vulnerability was found in oretnom23 Sanitization Management System 1.0. It has been rated as critical. The affected element is an unknown function of the file /php-sms/admin/?page=services/view_service. This manipulation of the argument

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 88.7%
CVE-2026-58704 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day

Google says a Pixel modem zero-day was under targeted exploitation. CISA has added CVE-2026-58704 to KEV as users are urged to patch. The post CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day appeared first on TechRepublic. Weit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.