🎯 CVE-2026-90525 MEDIUM 6.3 🔥 EPSS 2.3%
📄 .md Alle CVEs anzeigen ✕

CVE-2026-90525: Schwachstellen-Eintrag (NVD)

A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 🎯 High

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as…

🛡️ Empfohlene Mitigation: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. For example, consider using persistence layers such as Hibernate or Enterprise Java Beans, which can provide significant protection against SQL injection if used proper…
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 6.3
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Gering
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Gering
I · Integrität Gering
A · Verfügbarkeit Gering
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Veröffentlicht:13.09.2026
Aktualisiert:14.09.2026 20:56
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
2 🔴 Critical im Radar
2 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 163 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.524 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-14
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 24.5%
CVE-2026-43698 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43698 | Apple macOS up to 14.8.7/15.7.7/26.5 injection (Nessus ID 345686)

A vulnerability labeled as very critical has been found in Apple macOS up to 14.8.7/15.7.7/26.5. This issue affects some unknown processing. Executing a manipulation can lead to injection. This vulnerability is handled as CVE-2026-43698. It

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.1%
CVE-2026-43743 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43743 | Apple iOS/iPadOS/macOS up to 26.5.1 denial of service (Nessus ID 345686)

A vulnerability classified as problematic was found in Apple iOS, iPadOS and macOS up to 26.5.1. This issue affects some unknown processing. Executing a manipulation can lead to denial of service. This vulnerability is tracked as CVE-2026-4

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.3%
CVE-2026-64758 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-64758 | Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS up to 26.5 memory corruption (Nessus ID 345687)

A vulnerability, which was classified as very critical, has been found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS up to 26.5. This impacts an unknown function. This manipulation causes memory corruption. This vulnerability is r

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.5%
CVE-2026-43763 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43763 | Apple macOS up to 14.8.7/15.7.7/26.5 sandbox (Nessus ID 345687)

A vulnerability was found in Apple macOS up to 14.8.7/15.7.7/26.5 and classified as problematic. This affects an unknown part. Such manipulation leads to sandbox issue. This vulnerability is referenced as CVE-2026-43763. The attack can only

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21%
CVE-2026-28969 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-28969 | Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS up to 18.7.8/26.4 App use after free (Nessus ID 345687)

A vulnerability classified as critical has been found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS up to 18.7.8/26.4. Impacted is an unknown function of the component App. This manipulation causes use after free. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.2%
CVE-2026-89162 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89162 | PCRE PCRE2 up to 10.47 pcre2_serialize_encode information disclosure (WID-SEC-2026-3334)

A vulnerability has been found in PCRE PCRE2 up to 10.47 and classified as problematic. This affects the function pcre2_serialize_encode. This manipulation causes information disclosure. The identification of this vulnerability is CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.7%
CVE-2026-15588 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-15588 | GNOME glib2 GDBusServer denial of service (Nessus ID 335957 / WID-SEC-2026-2866)

A vulnerability was found in GNOME glib2 and classified as problematic. This affects an unknown function of the component GDBusServer. The manipulation results in denial of service. This vulnerability is known as CVE-2026-15588. Access to t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.4%
CVE-2026-85189 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85189 | RegularLabs Modals Extension up to 16.2.0 cross site scripting (EUVD-2026-77312)

A vulnerability identified as problematic has been detected in RegularLabs Modals Extension up to 16.2.0. This vulnerability affects unknown code of the component Modals. Performing a manipulation results in cross site scripting. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.8%
CVE-2026-81565 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81565 | Joomshaper SP Page Builder Extension up to 6.9.0 Media Upload upload folder path traversal (EUVD-2026-77383)

A vulnerability described as problematic has been identified in Joomshaper SP Page Builder Extension up to 6.9.0. The impacted element is the function Folder::create/File::upload of the component Media Upload. Such manipulation of the argum

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.5%
CVE-2026-79700 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79700 | Joomshaper SP Page Builder Pro Extension up to 5.1.4/6.9.0 optin_form captcha_question/captcha_answer improper authentication (EUVD-2026-77382)

A vulnerability marked as critical has been reported in Joomshaper SP Page Builder Pro Extension up to 5.1.4/6.9.0. The affected element is an unknown function of the component optin_form. This manipulation of the argument captcha_question/

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.5%
CVE-2026-90880 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90880 | D-Link DSL-3782 2016-07-28 Diagnostics Diagnostics.asp system Addr command injection (EUVD-2026-78270)

A vulnerability was found in D-Link DSL-3782 2016-07-28. It has been rated as critical. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30%
CVE-2026-81566 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81566 | Joomshaper SP Page Builder Extension up to 6.9.0 Menu Item Creation save menuid access control (EUVD-2026-77385)

A vulnerability classified as problematic has been found in Joomshaper SP Page Builder Extension up to 6.9.0. This affects the function Save of the component Menu Item Creation. Performing a manipulation of the argument menuid results in im

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.3%
CVE-2026-85190 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85190 | RegularLabs Quick Index Extension up to 1.0.0/5.0.4 cross site scripting (EUVD-2026-77314)

A vulnerability classified as problematic has been found in RegularLabs Quick Index Extension up to 1.0.0/5.0.4. The impacted element is an unknown function. This manipulation causes cross site scripting. This vulnerability is registered as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.3%
CVE-2026-79701 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79701 | Joomshaper SP Page Builder Extension up to 6.9.0 CAPTCHA Plugin onCheckAnswer view_type improper authentication (EUVD-2026-77426)

A vulnerability, which was classified as problematic, has been found in Joomshaper SP Page Builder Extension up to 6.9.0. Affected is the function onCheckAnswer of the component CAPTCHA Plugin. The manipulation of the argument view_type lea

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.7%
CVE-2026-90881 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90881 | D-Link DIR-882 up to 20260814 CGI Binary /HNAP1/dllog.cgi main information disclosure (EUVD-2026-78271)

A vulnerability categorized as problematic has been discovered in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 84.8%
CVE-2026-76461 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWee

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 23.4%
CVE-2026-89161 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89161 | PCRE PCRE2 up to 10.47 JIT Match pcre2_jit_match use after free (WID-SEC-2026-3334)

A vulnerability labeled as problematic has been found in PCRE PCRE2 up to 10.47. The affected element is the function pcre2_jit_match of the component JIT Match. The manipulation results in use after free. This vulnerability is reported as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.7%
CVE-2026-89158 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89158 | PCRE PCRE2 up to 10.47 pcre2_compile_32 integer overflow (WID-SEC-2026-3334)

A vulnerability classified as critical has been found in PCRE PCRE2 up to 10.47. This impacts the function pcre2_compile_32. Performing a manipulation results in integer overflow. This vulnerability is known as CVE-2026-89158. Remote exploi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22%
CVE-2026-89157 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89157 | PCRE PCRE2 up to 10.47 pcre2_pattern_convert out-of-bounds write (WID-SEC-2026-3334)

A vulnerability described as problematic has been identified in PCRE PCRE2 up to 10.47. This affects the function pcre2_pattern_convert. Such manipulation leads to out-of-bounds write. This vulnerability is traded as CVE-2026-89157. An atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.4%
CVE-2026-89156 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89156 | PCRE PCRE2 up to 10.47 JIT Fallback pcre2_match out-of-bounds (WID-SEC-2026-3334)

A vulnerability marked as critical has been reported in PCRE PCRE2 up to 10.47. The impacted element is the function pcre2_match of the component JIT Fallback. This manipulation causes out-of-bounds read. This vulnerability appears as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2026-89160 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89160 | PCRE PCRE2 up to 10.47 pcre2_match out-of-bounds (WID-SEC-2026-3334)

A vulnerability classified as problematic was found in PCRE PCRE2 up to 10.47. Affected is the function pcre2_match. Executing a manipulation can lead to out-of-bounds read. This vulnerability is handled as CVE-2026-89160. The attack can be

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26%
CVE-2026-90698 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90698 | memcached 1.6.41/1.6.42/1.6.43 mcmc Tokenizer proto_text.c try_read_command_asciiauth out-of-bounds (WID-SEC-2026-3336)

A vulnerability, which was classified as problematic, was found in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.6%
CVE-2026-87910 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87910 | Python up to 3.15.x filter return value (WID-SEC-2026-3335)

A vulnerability identified as critical has been detected in Python up to 3.15.x. This affects the function filter. This manipulation causes unchecked return value. This vulnerability is handled as CVE-2026-87910. The attack can be initiated

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-87575 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87575 | Google Chrome up to 152.0.7977.82 Loader access control

A vulnerability described as critical has been identified in Google Chrome. Affected by this issue is some unknown functionality of the component Loader. Such manipulation leads to improper access controls. This vulnerability is documented

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.3%
CVE-2026-87595 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87595 | Google Chrome up to 152.0.7977.82 server-side request forgery

A vulnerability has been found in Google Chrome and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to server-side request forgery. This vulnerability is traded as CVE-2026-87595. It is p

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.4%
CVE-2026-65351 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65351 | Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 denial of service

A vulnerability has been found in Apple iOS, iPadOS and macOS and classified as critical. This impacts an unknown function. The manipulation leads to denial of service. This vulnerability is traded as CVE-2026-65351. It is possible to initi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.6%
CVE-2026-87608 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87608 | Google Chrome up to 152.0.7977.82 FedCM certificate validation

A vulnerability marked as problematic has been reported in Google Chrome. Affected by this issue is some unknown functionality of the component FedCM. Performing a manipulation results in improper certificate validation. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27%
CVE-2026-87571 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87571 | Google Chrome up to 152.0.7977.82 Loader certificate validation

A vulnerability categorized as problematic has been discovered in Google Chrome. This affects an unknown function of the component Loader. Executing a manipulation can lead to improper certificate validation. This vulnerability is tracked a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.9%
CVE-2022-51018 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-51018 | pmmp PocketMine-MP up to 3.26.4/4.0.4 resource consumption

A vulnerability was found in pmmp PocketMine-MP up to 3.26.4/4.0.4. It has been classified as problematic. Affected by this issue is some unknown functionality. This manipulation causes resource consumption. This vulnerability is registered

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.5%
CVE-2026-67398 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-67398 | WebPros WHMCS up to 8.12.2/8.13.7/9.0.7 2Checkout Payment Gateway improper authorization (EUVD-2026-70849)

A vulnerability categorized as problematic has been discovered in WebPros WHMCS up to 8.12.2/8.13.7/9.0.7. The impacted element is an unknown function of the component 2Checkout Payment Gateway. The manipulation results in improper authoriz

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.1%
CVE-2026-64705 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-64705 | Apple macOS up to 14.8.6/15.7.6 buffer overflow

A vulnerability classified as very critical has been found in Apple macOS up to 14.8.6/15.7.6. Affected by this vulnerability is an unknown functionality. The manipulation leads to buffer overflow. This vulnerability is traded as CVE-2026-6

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21%
CVE-2026-63310 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63310 | NLTK up to 3.9.2 Downloader integrity check (EUVD-2026-64335 / Nessus ID 339002)

This issue seems to be a false positive. Please check the referenced sources and consider omitting this entry entirely. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 84.8%
CVE-2026-76461 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Hackers Exploit Critical Cisco Secure Email Gateway Vulnerability in the Wild to Run Malicious Code

Cisco has issued an urgent warning regarding an actively exploited zero-day vulnerability in its Secure Email Gateway appliances that allows remote, unauthenticated attackers to execute arbitrary commands with highest-level root privileges.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
5.8 MEDIUM
EPSS 4.8%
CVE-2026-65347 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65347 | Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 Image Processing denial of service

A vulnerability was found in Apple iOS, iPadOS and macOS. It has been declared as critical. Affected by this issue is some unknown functionality of the component Image Processing. Such manipulation leads to denial of service. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.6%
CVE-2026-65339 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65339 | Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 privileges management

A vulnerability was found in Apple iOS, iPadOS and macOS. It has been rated as problematic. This affects an unknown part. Performing a manipulation results in improper privilege management. This vulnerability was named CVE-2026-65339. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-65343 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65343 | Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 use after free

A vulnerability was found in Apple iOS, iPadOS and macOS and classified as very critical. The impacted element is an unknown function. Executing a manipulation can lead to use after free. This vulnerability is handled as CVE-2026-65343. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26%
CVE-2026-65346 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65346 | Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 integer overflow (EUVD-2026-60509)

A vulnerability was found in Apple iOS, iPadOS and macOS. It has been classified as very critical. This affects an unknown function. The manipulation leads to integer overflow. This vulnerability is uniquely identified as CVE-2026-65346. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.3%
CVE-2026-65349 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65349 | Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 out-of-bounds

A vulnerability was found in Apple iOS, iPadOS and macOS. It has been classified as very critical. Affected by this vulnerability is an unknown functionality. This manipulation causes out-of-bounds read. This vulnerability is handled as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.9%
CVE-2026-65341 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65341 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 memory corruption

A vulnerability, which was classified as very critical, was found in Apple iOS, iPadOS and macOS. This affects an unknown function. Executing a manipulation can lead to memory corruption. This vulnerability appears as CVE-2026-65341. The at

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.1%
CVE-2026-65340 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65340 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 denial of service

A vulnerability, which was classified as critical, has been found in Apple iOS, iPadOS and macOS. The impacted element is an unknown function. Performing a manipulation results in denial of service. This vulnerability is reported as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.3%
CVE-2026-65337 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65337 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 State Management input validation

A vulnerability classified as problematic has been found in Apple iOS, iPadOS and macOS. Impacted is an unknown function of the component State Management. This manipulation causes improper input validation. This vulnerability is registered

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-65338 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65338 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 memory corruption

A vulnerability classified as critical was found in Apple iOS, iPadOS and macOS. The affected element is an unknown function. Such manipulation leads to memory corruption. This vulnerability is documented as CVE-2026-65338. The attack can b

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.5%
CVE-2026-65336 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65336 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 State Management input validation

A vulnerability described as problematic has been identified in Apple iOS, iPadOS and macOS. This issue affects some unknown processing of the component State Management. The manipulation results in improper input validation. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.5%
CVE-2026-65335 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65335 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 State Management denial of service

A vulnerability marked as critical has been reported in Apple iOS, iPadOS and macOS. This vulnerability affects unknown code of the component State Management. The manipulation leads to denial of service. This vulnerability is listed as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.4%
CVE-2026-65330 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-65330 | Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 Kernel memory corruption (Nessus ID 335968)

A vulnerability was found in Apple iOS, iPadOS and macOS and classified as very critical. Affected is an unknown function of the component Kernel. The manipulation results in memory corruption. This vulnerability is known as CVE-2026-65330.

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.6%
CVE-2026-64781 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-64781 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 input validation (Nessus ID 335968)

A vulnerability categorized as critical has been discovered in Apple iOS, iPadOS and macOS. This affects an unknown function. The manipulation results in improper input validation. This vulnerability is identified as CVE-2026-64781. The att

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2026-64782 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-64782 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 memory corruption (Nessus ID 335968)

A vulnerability identified as very critical has been detected in Apple iOS, iPadOS and macOS. This impacts an unknown function. This manipulation causes memory corruption. This vulnerability is tracked as CVE-2026-64782. The attack is possi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.1%
CVE-2026-65329 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65329 | Apple iOS/iPadOS up to 26.6.0 improper authentication

A vulnerability described as critical has been identified in Apple iOS and iPadOS up to 26.6.0. This impacts an unknown function. Such manipulation leads to improper authentication. This vulnerability is documented as CVE-2026-65329. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.1%
CVE-2026-65334 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65334 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 memory corruption (Nessus ID 335968)

A vulnerability labeled as critical has been found in Apple iOS, iPadOS and macOS. This affects an unknown part. Executing a manipulation can lead to memory corruption. This vulnerability is tracked as CVE-2026-65334. The attack can be laun

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-65333 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65333 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 State Management resource consumption (Nessus ID 335968)

A vulnerability identified as critical has been detected in Apple iOS, iPadOS and macOS. Affected by this issue is some unknown functionality of the component State Management. Performing a manipulation results in resource consumption. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.2%
CVE-2026-65332 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65332 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 denial of service (Nessus ID 335968)

A vulnerability categorized as critical has been discovered in Apple iOS, iPadOS and macOS. Affected by this vulnerability is an unknown functionality. Such manipulation leads to denial of service. This vulnerability is referenced as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4%
CVE-2026-65331 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65331 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 denial of service (Nessus ID 335968)

A vulnerability was found in Apple iOS, iPadOS and macOS. It has been rated as critical. Affected is an unknown function. This manipulation causes denial of service. The identification of this vulnerability is CVE-2026-65331. It is possible

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.8%
CVE-2026-64788 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-64788 | Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 memory corruption (Nessus ID 335968)

A vulnerability described as very critical has been identified in Apple iOS, iPadOS and macOS. Affected by this issue is some unknown functionality. Executing a manipulation can lead to memory corruption. This vulnerability is registered as

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.7%
CVE-2026-64787 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-64787 | Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 use after free (Nessus ID 335968 / WID-SEC-2026-2940)

A vulnerability marked as critical has been reported in Apple iOS, iPadOS and macOS. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in use after free. This vulnerability is cataloged as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.3%
CVE-2026-64784 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-64784 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 out-of-bounds (Nessus ID 335968)

A vulnerability labeled as very critical has been found in Apple iOS, iPadOS and macOS. Affected is an unknown function. Such manipulation leads to out-of-bounds read. This vulnerability is listed as CVE-2026-64784. The attack may be perfor

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.2%
CVE-2026-64760 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-64760 | Apple iOS/iPadOS up to 18.7.9 Kernel information disclosure

A vulnerability, which was classified as problematic, has been found in Apple iOS and iPadOS up to 18.7.9. This issue affects some unknown processing of the component Kernel. This manipulation causes information disclosure. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 31.3%
CVE-2026-64779 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-64779 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 memory corruption (Nessus ID 335968)

A vulnerability was found in Apple iOS, iPadOS and macOS. It has been declared as very critical. The affected element is an unknown function. Executing a manipulation can lead to memory corruption. The identification of this vulnerability i

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.7%
CVE-2026-64778 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-64778 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 information disclosure (Nessus ID 335968)

A vulnerability was found in Apple iOS, iPadOS and macOS. It has been classified as problematic. Impacted is an unknown function. Performing a manipulation results in information disclosure. This vulnerability was named CVE-2026-64778. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.4%
CVE-2026-64715 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-64715 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 use after free (Nessus ID 335968)

A vulnerability was found in Apple iOS, iPadOS and macOS and classified as very critical. This issue affects some unknown processing. Such manipulation leads to use after free. This vulnerability is uniquely identified as CVE-2026-64715. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.1%
CVE-2026-43794 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43794 | Apple iOS/iPadOS/macOS prior 18.7.10/26.6.1/26.6.2 memory corruption (Nessus ID 335968)

A vulnerability, which was classified as very critical, has been found in Apple iOS, iPadOS and macOS. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption. This vulnerability is traded as CVE-20

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.