🎯 CVE-2026-90303
📄 .md Alle CVEs anzeigen ✕

CVE-2026-90303: Schwachstellen-Eintrag (NVD)

In the Linux kernel, the following vulnerability has been resolved:

ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults

When CONFIG_DEBUG_USER=y, and cmdline "user_debug=31" is set,
a user fault may trigger show_pte() without any lock.
If another thread in the same process concurrently calls munmap(),
the page table pages may be freed while show_pte() is still traversing
them, causing a use-after-free in show_pte().

If CONFIG_ARM_LPAE=y, this may cause a kernel panic if the pages table
of PMD are freed when show_pte() is running.

Acquire mmap_write_lock() around show_pte() for user faults to fix the
contention.

For user faults, additionally restrict that show_pte() is called only
when the addr is a user-space address (addr < TASK_SIZE). This is because
the lock of tsk->mm only protects the virtual memory of user address space,
furthermore, dumping the page tables of a kernel-space address for user
faults is unnecessary and may have security implications.

Keep everything unchanged for kernel faults, because the kernel is
already in the "oops" state, acquiring a lock may risk a deadlock.

Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
🩹 Patch verfügbar (OSV):
🩹 Kernel ≥ 5.10.270 🩹 Kernel ≥ 5.15.221 🩹 Kernel ≥ 6.1.188 🩹 Kernel ≥ 6.6.157 🩹 Kernel ≥ 6.12.110 🩹 Kernel ≥ 6.18.52
📰 Eigene Berichterstattung: ➔ CVE-2026-90303 | Linux Kernel up to 7.2.5 show_pte use after free (Nessus ID 347
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
Veröffentlicht:17.09.2026
Aktualisiert:17.09.2026 17:17
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
2 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
2 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 94 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.857 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-302026-09-18
≥90 %00
≥50 %00
≥10 %00
<10 %300300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
EPSS 5.9%
CVE-2026-63349 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63349: CVE-2026-63349: Privilege Dropping Bypass and Denial of Service in AnyIO Subprocess Module

CVE-2026-63349: Privilege Dropping Bypass and Denial of Service in AnyIO Subprocess Module Vulnerability ID: CVE-2026-63349 CVSS Score: 7.0 Published: 2026-09-18 CVE-2026-63349 is a critical privilege-dropping bypass vulnerability in the An

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.4%
CVE-2026-90605 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90605 | Totolink A3002MU Hh-B20211125.1046 boa /boafrm/formFilter ip6addr buffer overflow

A vulnerability classified as very critical was found in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 31.3%
CVE-2026-90600 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90600 | itsourcecode Sales and Inventory System 1.0 /pages/inv_edit1.php ID sql injection

A vulnerability identified as critical has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. This vul

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.2%
CVE-2026-90596 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90596 | embedded-graphics up to 0.8.2 on 32-bit src/image/image_raw.rs new/bytes_per_row integer overflow (Issue 820)

A vulnerability was found in embedded-graphics up to 0.8.2 on 32-bit. It has been classified as critical. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.6%
CVE-2026-90595 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-90595 | wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0 OnlineController.java OnlineController.getOnlineInfo authorization (Issue 65)

A vulnerability was found in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0 and classified as critical. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.8%
CVE-2026-90582 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90582 | evanchiu serverless-todo 1.0.3/2.0.0 API Todo Endpoint src/index.js saveTodos event.body resource consumption (Issue 10)

A vulnerability categorized as problematic has been discovered in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.4%
CVE-2026-90583 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90583 | kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf Query String Rendering app/sw.py index qs cross site scripting (Issue 854)

A vulnerability identified as problematic has been detected in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Per

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.6%
CVE-2026-90577 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90577 | GPAC up to f1219cde MP4Box base_scenegraph.c gf_node_get_field heap-based overflow (Issue 3816)

A vulnerability has been found in GPAC up to f1219cde and classified as problematic. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulatio

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.1%
CVE-2026-90601 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90601 | getzep graphiti up to 0.30.2 REST API main.py improper authentication (Issue 1716)

A vulnerability labeled as critical has been found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.6%
CVE-2023-6710 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2023-6710 | Apache HTTP Server mod_proxy_cluster alias cross site scripting (EUVD-2023-58930 / EDB-52010)

A vulnerability was found in Apache HTTP Server. It has been declared as problematic. Affected by this issue is some unknown functionality of the component mod_proxy_cluster. The manipulation of the argument alias results in cross site scri

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
EPSS 21.9%
CVE-2026-8354 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-8354 | celomitan Gum Addon for Elementor Plugin up to 1.3.15 on WordPress pop_tag cross site scripting (EUVD-2026-83562)

A vulnerability was found in celomitan Gum Addon for Elementor Plugin up to 1.3.15 on WordPress. It has been declared as problematic. This affects an unknown function. The manipulation of the argument pop_tag results in cross site scripting

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 22.7%
CVE-2026-18346 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-18346 | TikTok Plugin up to 1.4.1 on WordPress authorization (EUVD-2026-83563)

A vulnerability was found in TikTok Plugin up to 1.4.1 on WordPress and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to authorization bypass. This vulnerability appears as CVE-2026-1

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 22.8%
CVE-2026-5410 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-5410 | davidanderson Redux Framework Plugin up to 4.5.13 on WordPress Spinner class-redux-spinner.php user_meta_save spinner cross site scripting (EUVD-2026-83561)

A vulnerability classified as problematic was found in davidanderson Redux Framework Plugin up to 4.5.13 on WordPress. This affects the function user_meta_save of the file class-redux-spinner.php of the component Spinner. The manipulation o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 22.7%
CVE-2026-9289 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-9289 | WordLift Plugin up to 3.54.10 on WordPress JSON-LD REST API /wordlift/v1/jsonld get_post access control (EUVD-2026-83565)

A vulnerability was found in WordLift Plugin up to 3.54.10 on WordPress. It has been classified as problematic. The impacted element is the function get_post of the file /wordlift/v1/jsonld of the component JSON-LD REST API. The manipulatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 28.7%
CVE-2026-9766 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-9766 | Empik for Woocommerce Plugin up to 1.5.1 on WordPress authorization (EUVD-2026-83566)

A vulnerability has been found in Empik for Woocommerce Plugin up to 1.5.1 on WordPress and classified as problematic. Impacted is an unknown function. Performing a manipulation of the argument _empik_logistic_klass/_empik_product_state/_em

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 5%
CVE-2026-1255 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-1255 | YS Innovations YS LeadGen Plugin up to 2.1.4 on WordPress ysleadgen_get_captured_data information disclosure (EUVD-2026-83564)

A vulnerability, which was classified as problematic, has been found in YS Innovations YS LeadGen Plugin up to 2.1.4 on WordPress. This vulnerability affects the function ysleadgen_get_captured_data. This manipulation causes information dis

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 20.6%
CVE-2026-1256 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-1256 | ysinnovations YS LeadGen Plugin up to 2.1.4 on WordPress cross site scripting (EUVD-2026-83567)

A vulnerability was found in ysinnovations YS LeadGen Plugin up to 2.1.4 on WordPress. It has been rated as problematic. This impacts an unknown function. This manipulation causes cross site scripting. This vulnerability is handled as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 32%
CVE-2026-76579 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-76579 | LiteSpeed Technologies LiteSpeed Cache Plugin up to 7.9 on WordPress ESI esi cross site scripting (EUVD-2026-83568)

A vulnerability classified as problematic has been found in LiteSpeed Technologies LiteSpeed Cache Plugin up to 7.9 on WordPress. Affected by this issue is some unknown functionality of the component ESI. The manipulation of the argument es

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 30.2%
CVE-2026-9613 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-9613 | Datalogics Ecommerce Delivery Plugin up to 2.6.65 on WordPress authorization (EUVD-2026-83569)

A vulnerability, which was classified as critical, was found in Datalogics Ecommerce Delivery Plugin up to 2.6.65 on WordPress. This issue affects some unknown processing. Such manipulation leads to authorization bypass. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 32.2%
CVE-2026-9858 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-9858 | wpexpertshub Partial Shipment for WooCommerce Plugin up to 3.4 on WordPress AJAX handlers woocommerce-partial-shipment.php order_id improper authorization (EUVD-2026-83570)

A vulnerability described as critical has been identified in wpexpertshub Partial Shipment for WooCommerce Plugin up to 3.4 on WordPress. Affected by this vulnerability is an unknown functionality of the file woocommerce-partial-shipment.ph

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 27.2%
CVE-2026-93742 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93742 | Totolink A3002MU Hh-B20211125.1046 /boafrm/formWsc localPin command injection (EUVD-2026-83583)

A vulnerability marked as very critical has been reported in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.6%
CVE-2026-78030 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-78030 | DBI up to 1.652 require dbm_type/dbm_mldbm code injection (EUVD-2026-83584)

A vulnerability was found in DBI up to 1.652. It has been rated as critical. This issue affects the function require. The manipulation of the argument dbm_type/dbm_mldbm leads to code injection. This vulnerability is traded as CVE-2026-7803

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.4%
CVE-2026-90716 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90716 | marcobambini Gravity up to 0.9.7 Number Parser gravity_parser.c parse_number_expression out-of-bounds (Issue 446)

A vulnerability classified as problematic has been found in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Number Parser. Performing a manipulat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.8%
CVE-2026-78299 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-78299 | Eclipse Embedded CDT up to 5.x/6.7 path traversal

A vulnerability has been found in Eclipse Embedded CDT up to 5.x/6.7 and classified as critical. This issue affects some unknown processing. Performing a manipulation results in path traversal. This vulnerability is cataloged as CVE-2026-78

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.2%
CVE-2026-9812 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-9812 | Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 Playbooks authorization

A vulnerability has been found in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Playbooks. This manipulation causes authorization bypass.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.6%
CVE-2026-13417 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-13417 | Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 Boards fields.properties unusual condition

A vulnerability identified as problematic has been detected in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0. This issue affects some unknown processing of the component Boards. The manipulation of the argument fields.properties leads to i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.5%
CVE-2026-10556 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-10556 | Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 Calendar Plugin unusual condition

A vulnerability, which was classified as problematic, has been found in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0. The impacted element is an unknown function of the component Calendar Plugin. Performing a manipulation results in impro

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.7%
CVE-2026-90705 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90705 | D-Link DWR-M921 1.1.52 Boa Dispatch Table /boafrm/formsysCmd os command injection

A vulnerability was found in D-Link DWR-M921 1.1.52 and classified as critical. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lea

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.1%
CVE-2026-90710 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-90710 | taisan tarzan-cms 1.0.0 Theme Download Function ThemeService.java openConnection httpUrl server-side request forgery (IK768M)

A vulnerability categorized as critical has been discovered in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Fu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.5%
CVE-2026-90695 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90695 | SourceCodester Inventory Management System 1.0 Vendor Management /api/vendors_handler.php cross site scripting

A vulnerability classified as problematic has been found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24%
CVE-2026-90700 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90700 | itsourcecode Sales and Inventory System 1.0 /pages/pro_edit1.php prodcode sql injection

A vulnerability was found in itsourcecode Sales and Inventory System 1.0 and classified as critical. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. This v

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18%
CVE-2026-90690 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90690 | 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04 API Tools Endpoint hexstrike_server.py subprocess.Popen os command injection (Issue 224)

A vulnerability categorized as critical has been discovered in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Too

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.1%
CVE-2026-29811 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-29811 | CyberPanel up to 2.4.3 comparison using wrong factors

A vulnerability labeled as problematic has been found in CyberPanel up to 2.4.3. Affected is an unknown function. Executing a manipulation can lead to comparison using wrong factors. This vulnerability is handled as CVE-2026-29811. The atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.9%
CVE-2026-90573 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90573 | GPAC up to f1219cde MP4Box scenegraph/vrml_tools.c gf_sg_mfurl_del null pointer dereference (Issue 3814)

A vulnerability classified as problematic has been found in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer derefe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.4%
CVE-2026-90575 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90575 | PHPGurukul Small CRM 4.0 Login Success /crm/login.php unserialize geopluginURL deserialization

A vulnerability, which was classified as problematic, has been found in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.8%
CVE-2026-90619 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90619 | 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04 Execute Endpoint hexstrike_server.py code/script os command injection (Issue 222)

A vulnerability classified as critical has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.6%
CVE-2026-90613 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90613 | GPAC up to f1219cde MP4Box isomedia/stbl_read.c stbl_GetSampleInfos assertion (Issue 3822)

A vulnerability categorized as problematic has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.1%
CVE-2026-90608 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90608 | Totolink A3002MU Hh-B20211125.1046 boa /boafrm/formPortFw service_type buffer overflow

A vulnerability has been found in Totolink A3002MU Hh-B20211125.1046 and classified as very critical. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument ser

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.5%
CVE-2026-90598 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90598 | jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2 UserController.java UserController.updateUser userid authorization (Issue 172)

A vulnerability was found in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. It has been rated as critical. The impacted element is the function UserController.updateUser of the file UserController.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.3%
CVE-2026-90603 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90603 | Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0 S3 Upload /api/upload-binary x-proxy-target-url unrestricted upload (Issue 310)

A vulnerability described as critical has been identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.6%
CVE-2026-90580 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90580 | FlowiseAI Flowise up to 3.0.2 Evaluations Endpoint index.ts axios.post Host/X-Forwarded-Proto server-side request forgery (Issue 6687)

A vulnerability was found in FlowiseAI Flowise up to 3.0.2. It has been declared as critical. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations E

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.9%
CVE-2026-90593 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90593 | embedded-graphics up to 0.8.2 src/image/image_raw.rs ImageRaw::draw_sub_image width integer overflow (Issue 821)

A vulnerability, which was classified as critical, was found in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 67.4%
CVE-2026-59822 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Rotating Secrets After an AI-Tooling Compromise: A Checklist for the September 2026 KEV Wave

Rotating Secrets After an AI-Tooling Compromise: A Checklist for the September 2026 KEV Wave Three of the seven vulnerabilities CISA added to its Known Exploited Vulnerabilities catalog on September 2, 2026 targeted AI and workflow tooling:

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22.9%
CVE-2026-28326 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

SolarWinds fixt ARM-Fall mit Hard-Coded-Key: Patch für CVE-2026-28326

LONDON (IT BOLTWISE) – SolarWinds hat Sicherheitsupdates für den Access Rights Manager (ARM) veröffentlicht, um eine kritische Schwachstelle zu schließen. Die Lücke mit der Kennung CVE-2026-28326 beruht auf einem hard-codierten statischen S

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23%
CVE-2026-90508 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90508 | Chengdu Qilu Technology Ludashi 6.1026.4715.714 Message Dispatch ProtectFilter64.sys MessageNotifyCallback authorization

A vulnerability was found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. It has been rated as problematic. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.4%
CVE-2026-90514 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90514 | SourceCodester School Registration and Fee System 1.0 save_stud.php Status sql injection

A vulnerability described as critical has been identified in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to s

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 5.8%
CVE-2026-90503 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90503 | Chengdu Qilu Technology Ludashi 6.1026.4715.714 ComputerZ_x64.sys sub_11008 PhysicalAddress information disclosure

A vulnerability, which was classified as problematic, was found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument Ph

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.2%
CVE-2026-90498 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90498 | lenve vhr 1.0-SNAPSHOT vhr.sql default credentials

A vulnerability marked as critical has been reported in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. This vulnerability is referenced

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.9%
CVE-2026-90496 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-90496 | Fengoffice Feng Office up to 3.11.13.11 Reorder Handlers MoreController.class.php update_system_module_order/update_dimension_order modules/dims sql injection

A vulnerability identified as problematic has been detected in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 24.3%
CVE-2026-90506 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90506 | vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46 Save Account Job race condition

A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. It has been classified as problematic. This impacts an unknown function of the component Save Account Job. This manipulation causes race co

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.5%
CVE-2026-90511 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90511 | GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea listSplit Interface BooksServlet.java column sql injection

A vulnerability labeled as critical has been found in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18.8%
CVE-2026-90501 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90501 | lenve vhr 1.0-SNAPSHOT HrMapper.xml HrInfoController.updateHr Password privileges management

A vulnerability classified as critical was found in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege managemen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.3%
CVE-2021-43818 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2021-43818 | lxml up to 4.6.4 lxml.html cross site scripting (GHSA-55x5-fj6c-h6m8 / Nessus ID 348247)

A vulnerability was found in lxml up to 4.6.4. It has been rated as problematic. This affects an unknown part of the file lxml.html. The manipulation leads to cross site scripting. This vulnerability is traded as CVE-2021-43818. It is possi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18.2%
CVE-2026-81000 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-81000 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Tun tun_get_user align allocation of resources (Nessus ID 348261)

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as very critical. This affects the function tun_get_user of the component Tun. The manipulation of the argument align leads to allocation of resources

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 25.7%
CVE-2026-88859 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-88859 | Red Hat Enterprise Linux Trusted JavaScript cross site scripting (Nessus ID 348257)

A vulnerability identified as problematic has been detected in Red Hat Enterprise Linux. This affects an unknown part of the component Trusted JavaScript Handler. This manipulation causes cross site scripting. The identification of this vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 23.8%
CVE-2026-80844 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80844 | Linux Kernel up to 7.2.2 xfrm ipv6_rearrange_rthdr out-of-bounds (Nessus ID 348261)

A vulnerability categorized as very critical has been discovered in Linux Kernel up to 7.2.2. Affected is the function ipv6_rearrange_rthdr of the component xfrm. Executing a manipulation can lead to out-of-bounds read. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 2.4%
CVE-2026-91147 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-91147 | Red Hat Enterprise Linux/OpenShift Dev Spaces cockpit-ws denial of service (Nessus ID 348262)

A vulnerability, which was classified as critical, was found in Red Hat Enterprise Linux and OpenShift Dev Spaces. This affects an unknown part of the component cockpit-ws. The manipulation results in denial of service. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 79.9%
CVE-2026-28326 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.7%
CVE-2026-61591 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
djust-org

CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes — e.g. flip `is_admin

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restor

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.7%
CVE-2026-61592 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
djust-org

CVE-2026-61592 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the vict

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.