CVE-2026-88994: Schwachstellen-Eintrag (NVD)
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file containing PHP code can be reached. Exploitation requires the plugin's Lightspeed subsystem to be enabled, which is not the default.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-17 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-40534 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Video API cross site scripting (EUVD-2026-82789)
A vulnerability classified as problematic has been found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. Affected by this issue is some unknown functionality of the component Video API. The manipulation leads to cro
CVE-2026-40532 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Wallpaper Path information disclosure (EUVD-2026-82788)
A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 and classified as problematic. This vulnerability affects unknown code of the component Wallpaper Path. Such manipulation leads to information
CVE-2026-40537 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 PersonMail API server-side request forgery (EUVD-2026-82791)
A vulnerability classified as problematic was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. This affects an unknown part of the component PersonMail API. The manipulation results in server-side request forge
CVE-2026-40536 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Audio API path traversal (EUVD-2026-82790)
A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. It has been rated as problematic. The affected element is an unknown function of the component Audio API. The manipulation leads to path trav
CVE-2026-75157 | Apache Airflow Asset Queued Events Endpoint privileges management (EUVD-2026-82766)
A vulnerability labeled as problematic has been found in Apache Airflow. Affected is an unknown function of the component Asset Queued Events Endpoint. The manipulation results in improper privilege management. This vulnerability is known a
CVE-2026-21822 | HCL AppScan ASReportService path traversal (EUVD-2026-82851)
A vulnerability identified as critical has been detected in HCL AppScan. Affected by this vulnerability is an unknown functionality of the component ASReportService. Performing a manipulation results in path traversal. This vulnerability is
CVE-2025-13533 | wipeoutmedia CSS & JavaScript Toolbox Plugin up to 12.0.6 on WordPress Assignment Engine cross site scripting (EUVD-2025-210931)
A vulnerability, which was classified as problematic, has been found in wipeoutmedia CSS &amp; JavaScript Toolbox Plugin up to 12.0.6 on WordPress. Affected by this vulnerability is an unknown functionality of the component Assignment E
CVE-2026-18405 | jegtheme Jeg Kit for Elementor Plugin up to 3.2.16 on WordPress cross site scripting (EUVD-2026-82852)
A vulnerability, which was classified as problematic, was found in jegtheme Jeg Kit for Elementor Plugin up to 3.2.16 on WordPress. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting. This
CVE-2026-89058 | Red Hat RESTEasy prior 6.2.19.Final/7.0.5.Final CorsFilter cross-domain policy (EUVD-2026-82736)
A vulnerability was found in Red Hat RESTEasy. It has been declared as problematic. The impacted element is an unknown function of the component CorsFilter. Executing a manipulation can lead to permissive cross-domain policy with untrusted
CVE-2026-90884 | WP Recipe Maker Plugin up to 10.8.1 on WordPress notes cross site scripting (EUVD-2026-82853)
A vulnerability, which was classified as problematic, has been found in WP Recipe Maker Plugin up to 10.8.1 on WordPress. The affected element is an unknown function. Performing a manipulation of the argument notes results in cross site scr
CVE-2026-15797 | danieliser Popup Maker Plugin up to 1.24.0 on WordPress Select2 sanitize_text_field post_title cross site scripting (EUVD-2026-82854)
A vulnerability classified as problematic has been found in danieliser Popup Maker Plugin up to 1.24.0 on WordPress. This issue affects the function sanitize_text_field of the component Select2. This manipulation of the argument post_title
CVE-2026-87915 | danieliser Popup Maker Plugin up to 1.24.0 on WordPress Input Sanitization wp-admin/js/common.js jQuery.attr Name cross site scripting (EUVD-2026-82855)
A vulnerability classified as problematic was found in danieliser Popup Maker Plugin up to 1.24.0 on WordPress. Impacted is the function jQuery.attr of the file wp-admin/js/common.js of the component Input Sanitization. Such manipulation of
[UPDATE] [niedrig] expat: Schwachstelle ermöglicht Denial of Service
Ein lokaler Angreifer kann eine Schwachstelle in expat ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[UPDATE] [mittel] Red Hat CloudForms: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Benutzerrechten
Ein lokaler Angreifer kann eine Schwachstelle in Red Hat CloudForms ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen oder einen Denial of Service Angriff durchzuführen. Weiterlesen
Critical pgAdmin Authentication Bypass Lets Attackers Login as Administrator Without Credentials
A critical vulnerability in pgAdmin 4 could allow unauthenticated remote attackers to impersonate arbitrary users, including existing administrator accounts, by supplying a malicious HTTP identity header. This vulnerability, tracked as CVE-
CVE-2026-4130 | NI SystemLink/SystemLink Server up to 26.5.0 missing encryption
A vulnerability, which was classified as problematic, was found in NI SystemLink and SystemLink Server up to 26.5.0. Affected by this vulnerability is an unknown functionality. The manipulation results in missing encryption of sensitive dat
CVE-2026-81048 | Dell ThinOS up to 2605_10.2615 command injection
A vulnerability was found in Dell ThinOS up to 2605_10.2615. It has been classified as very critical. Affected by this vulnerability is an unknown functionality. This manipulation causes command injection. This vulnerability is tracked as C
CVE-2026-4129 | NI SystemLink/SystemLink Server up to 26.5.0 access control
A vulnerability was found in NI SystemLink and SystemLink Server up to 26.5.0 and classified as critical. Affected is an unknown function. The manipulation results in improper access controls. This vulnerability is identified as CVE-2026-41
CVE-2026-85544 | Hikvision DS-KV8114 cryptographic issue
A vulnerability, which was classified as problematic, was found in Hikvision DS-KV9503, DS-KV6113, DS-KV6103, DS-KV6133, DS-KV8113, DS-KV8213, DS-KV8413, DS-KD8003, DS-KD8005, DS-KV6114, DS-KV6124, DS-KV6134 and DS-KV8114. This impacts an u
CVE-2026-61915 | Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 CalDAV double free
A vulnerability was found in Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component CalDAV. The manipulation results in double free. This vulnerability
CVE-2026-61910 | Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 Mailbox Mailbox/set privileges management (EUVD-2026-75130)
A vulnerability described as critical has been identified in Cyrus IMAP up to 3.8.7/3.10.3/3.12.3. Impacted is the function Mailbox/set of the component Mailbox. The manipulation results in improper privilege management. This vulnerability
CVE-2026-61909 | Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 CalDAV/CardDAV information disclosure
A vulnerability classified as problematic has been found in Cyrus IMAP up to 3.8.7/3.10.3/3.12.3. The affected element is an unknown function of the component CalDAV/CardDAV. This manipulation causes information disclosure. The identificati
CVE-2026-87817 | gitpython-developers GitPython up to 3.1.59 Git Directory Validation index.commit code injection (EUVD-2026-74843 / Nessus ID 344426)
A vulnerability, which was classified as critical, has been found in gitpython-developers GitPython up to 3.1.59. The impacted element is the function index.commit of the component Git Directory Validation. Performing a manipulation results
CVE-2026-61908 | Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 JMAP Blob ID out-of-bounds
A vulnerability was found in Cyrus IMAP up to 3.8.7/3.10.3/3.12.3 and classified as critical. This affects an unknown function of the component JMAP Blob ID Handler. Executing a manipulation can lead to out-of-bounds read. This vulnerabilit
CVE-2022-44411 | Web Based Quiz System 1.0 missing encryption (EUVD-2022-47354)
A vulnerability identified as problematic has been detected in Web Based Quiz System 1.0. This impacts an unknown function. Performing a manipulation results in missing encryption of sensitive data. This vulnerability is reported as CVE-202
CVE-2022-44414 | Automotive Shop Management System 1.0 manage_service.php ID sql injection (EUVD-2022-47357)
A vulnerability identified as critical has been detected in Automotive Shop Management System 1.0. This issue affects some unknown processing of the file /asms/admin/services/manage_service.php. This manipulation of the argument ID causes s
CVE-2022-44413 | Automotive Shop Management System 1.0 manage_mechanic.php ID sql injection (EUVD-2022-47356)
A vulnerability categorized as critical has been discovered in Automotive Shop Management System 1.0. This vulnerability affects unknown code of the file /asms/admin/mechanics/manage_mechanic.php. The manipulation of the argument ID results
CVE-2022-44403 | Automotive Shop Management System 1.0 manage_user ID sql injection (EUVD-2022-47346)
A vulnerability marked as critical has been reported in Automotive Shop Management System 1.0. Affected is an unknown function of the file /asms/admin/?page=user/manage_user. Performing a manipulation of the argument ID results in sql injec
CVE-2022-44402 | oretnom23 Automotive Shop Management System 1.0 Master.php?f=delete_transaction sql injection (EUVD-2022-47345)
A vulnerability was found in oretnom23 Automotive Shop Management System 1.0. It has been declared as critical. Impacted is an unknown function of the file /asms/classes/Master.php?f=delete_transaction. Executing a manipulation can lead to
CVE-2026-83561 | Complianz GDPR/CCPA Cookie Consent Banner Plugin up to 7.5.4 on WordPress Elementor Cookie Blocker Regex cross site scripting (EUVD-2026-82792)
A vulnerability described as problematic has been identified in Complianz GDPR and CCPA Cookie Consent Banner Plugin up to 7.5.4 on WordPress. This vulnerability affects unknown code of the component Elementor Cookie Blocker Regex. The mani
CVE-2026-85410 | pixarlabs Master Addons for Elementor Plugin up to 3.2.2 on WordPress popup_id authorization (EUVD-2026-82793)
A vulnerability has been found in pixarlabs Master Addons for Elementor Plugin up to 3.2.2 on WordPress and classified as problematic. Impacted is an unknown function. Performing a manipulation of the argument popup_id results in authorizat
CVE-2026-40533 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Desktop API information disclosure (EUVD-2026-82794)
A vulnerability labeled as problematic has been found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. This impacts an unknown function of the component Desktop API. Such manipulation leads to information disclosure.
CVE-2026-40535 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Desktop API path traversal (EUVD-2026-82795)
A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. It has been declared as critical. Impacted is an unknown function of the component Desktop API. Executing a manipulation can lead to path tra
CVE-2026-40538 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Auto block excessive authentication (EUVD-2026-82796)
A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. It has been classified as problematic. This issue affects some unknown processing of the component Auto block. Performing a manipulation resu
CVE-2026-40539 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Email API certificate validation (EUVD-2026-82797)
A vulnerability marked as problematic has been reported in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. Affected is an unknown function of the component Email API. Performing a manipulation results in improper certi
CVE-2026-69797 | Microsoft Office 365 Apps for Enterprise use after free (Nessus ID 344563)
A vulnerability, which was classified as problematic, was found in Microsoft Office 365 Apps for Enterprise, Office LTSC, Office LTSC for Mac and PowerPoint. Affected is an unknown function. Such manipulation leads to use after free. This v
CVE-2026-83941 | Microsoft Entra improper authorization
A vulnerability was found in Microsoft Entra. It has been declared as critical. This vulnerability affects unknown code. Executing a manipulation can lead to improper authorization. This vulnerability is registered as CVE-2026-83941. It is
CVE-2026-69820 | Microsoft Windows up to 11 26H1 Hello buffer overflow
A vulnerability was found in Microsoft Windows up to 11 26H1. It has been rated as very critical. Affected is an unknown function of the component Hello. The manipulation leads to buffer overflow. This vulnerability is referenced as CVE-202
CVE-2026-72980 | Microsoft Windows up to Server 2025 Windows Hello uncontrolled search path
A vulnerability categorized as critical has been discovered in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component Windows Hello. Such manipulation leads to uncontrolled search path. This vulnerabi
CVE-2026-69874 | Microsoft Windows up to Server 2025 ALPC privileges management
A vulnerability identified as critical has been detected in Microsoft Windows up to Server 2025. This issue affects some unknown processing of the component ALPC. This manipulation causes improper privilege management. This vulnerability ap
CVE-2026-69832 | Microsoft Windows up to Server 2025 Win32K information disclosure
A vulnerability has been found in Microsoft Windows and classified as problematic. This impacts an unknown function of the component Win32K. This manipulation causes information disclosure. This vulnerability is tracked as CVE-2026-69832. T
CVE-2026-77491 | Microsoft Windows up to Server 2025 GDI out-of-bounds
A vulnerability categorized as problematic has been discovered in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component GDI. Executing a manipulation can lead to out-of-bounds read. This vulnerabilit
CVE-2026-69739 | Microsoft Office out-of-bounds
A vulnerability was found in Microsoft Office. It has been declared as problematic. This impacts an unknown function. The manipulation results in out-of-bounds read. This vulnerability is identified as CVE-2026-69739. The attack can be exec
CVE-2026-67643 | Microsoft SQL Server heap-based overflow
A vulnerability classified as very critical has been found in Microsoft SQL Server. This vulnerability affects unknown code. The manipulation leads to heap-based buffer overflow. This vulnerability is uniquely identified as CVE-2026-67643.
Pixel-Update schnell installieren: <b>Hacker</b> nutzen Sicherheitslücke bereits aus - t3n
Google veröffentlicht wichtiges Pixel-Update: Eine Zero-Click-Sicherheitslücke wird bereits aktiv von Hackern ausgenutzt. Jetzt installieren. Weiterlesen
Pixel-Update schnell installieren: Hacker nutzen Sicherheitslücke bereits aus
Google hat ein neues Update für seine Pixel-Smartphones veröffentlicht. Neben praktischen Funktionen enthält die Aktualisierung aber auch einen wichtigen Fix für eine aktiv ausgenutzte Sicherheitslücke. Was dazu bekannt ist. weiterlesen auf
Pixel-Update schnell installieren: Hacker nutzen Sicherheitslücke bereits aus
Google hat ein neues Update für seine Pixel-Smartphones veröffentlicht. Neben praktischen Funktionen enthält die Aktualisierung aber auch einen wichtigen Fix für eine aktiv ausgenutzte Sicherheitslücke. Was dazu bekannt ist. Weiterlesen
Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek. Weiter
USN-8715-2: Linux kernel (AWS FIPS) vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta
USN-8714-3: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - OCFS2 file system; - SCTP protocol; (CVE-2026-53043, CVE-2
CVE-2025-10072 | Portabilis i-Educar up to 2.10 enturmar access control (EUVD-2025-27098)
A vulnerability marked as critical has been reported in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing a manipulation results in improper access controls.
CVE-2025-65024 | Portabilis i-Educar up to 2.10.0 agenda_admin_cad.php cod_agenda sql injection (GHSA-6c8p-xqcv-rghx)
A vulnerability has been found in Portabilis i-Educar up to 2.10.0 and classified as critical. This vulnerability affects unknown code of the file ieducar/intranet/agenda_admin_cad.php. The manipulation of the argument cod_agenda leads to s
CVE-2025-65023 | Portabilis i-Educar up to 2.10.0 funcionario_vinculo_cad.php cod_funcionario_vinculo sql injection (GHSA-8rv6-x8h9-fjfc)
A vulnerability, which was classified as critical, was found in Portabilis i-Educar up to 2.10.0. This affects an unknown part of the file ieducar/intranet/funcionario_vinculo_cad.php. Executing a manipulation of the argument cod_funcionari
[UPDATE] [mittel] vim: Schwachstelle ermöglicht Codeausführung
Ein Angreifer kann eine Schwachstelle in vim ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[UPDATE] [hoch] vim: Schwachstelle ermöglicht Codeausführung
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vim ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
CVE-2022-44401 | Online Tours & Travels Management System 1.0 /tour/admin/file.php unrestricted upload (EUVD-2022-47344)
A vulnerability described as very critical has been identified in Online Tours &amp; Travels Management System 1.0. This affects an unknown function of the file /tour/admin/file.php. The manipulation results in unrestricted upload. This
CVE-2022-44400 | oretnom23 Purchase Order Management System 1.0 ?page=system_info unrestricted upload (EUVD-2022-47343)
A vulnerability was found in oretnom23 Purchase Order Management System 1.0. It has been declared as very critical. Impacted is an unknown function of the file /purchase_order/admin/?page=system_info. Such manipulation leads to unrestricted
CVE-2022-44399 | Poultry Farm Management System 1.0 category.php del sql injection (EUVD-2022-47342)
A vulnerability marked as critical has been reported in Poultry Farm Management System 1.0. The impacted element is an unknown function of the file /Redcock-Farm/farm/category.php. The manipulation of the argument del leads to sql injection
CVE-2022-44393 | oretnom23 Sanitization Management System 1.0 view_service ID sql injection (EUVD-2022-47336)
A vulnerability was found in oretnom23 Sanitization Management System 1.0. It has been rated as critical. The affected element is an unknown function of the file /php-sms/admin/?page=services/view_service. This manipulation of the argument
CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day
Google says a Pixel modem zero-day was under targeted exploitation. CISA has added CVE-2026-58704 to KEV as users are urged to patch. The post CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day appeared first on TechRepublic. Weit