🎯 CVE-2026-90682
📄 .md Alle CVEs anzeigen ✕

CVE-2026-90682: Schwachstellen-Eintrag (NVD)

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Improper Restriction of Operations within the Bounds of a Memory Buffer 🎯 High

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

🛡️ Empfohlene Mitigation: Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid. For example, many languages that perform their own memory management, such as Java and Perl, are not subject to buffer overflows. Other languages, such as Ada and C#, typically provide overflow prot…
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 5.3
AV · Angriffsvektor Lokal
AC · Komplexität Gering
PR · Privilegien Gering
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Gering
I · Integrität Gering
A · Verfügbarkeit Gering
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Veröffentlicht:14.09.2026
Aktualisiert:15.09.2026 14:17
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 123 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.484 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-16
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
5.8 MEDIUM
EPSS 4.6%
CVE-2026-65017 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-65017 | Apache Airflow Config API information disclosure

A vulnerability labeled as problematic has been found in Apache Airflow. Affected is an unknown function of the component Config API. Executing a manipulation can lead to information disclosure. The identification of this vulnerability is C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 31.7%
CVE-2026-67587 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-67587 | Apache Airflow deserialization

A vulnerability identified as critical has been detected in Apache Airflow. This impacts an unknown function. Performing a manipulation results in deserialization. This vulnerability was named CVE-2026-67587. The attack may be initiated rem

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
5.8 MEDIUM
EPSS 2.4%
CVE-2026-54183 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-54183 | Apache Airflow information disclosure (EUVD-2026-57310)

A vulnerability categorized as problematic has been discovered in Apache Airflow. This affects an unknown function. Such manipulation leads to information disclosure. This vulnerability is uniquely identified as CVE-2026-54183. The attack c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-59242 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-59242 | Apache Airflow XCom deserialize endpoint deserialization

A vulnerability was found in Apache Airflow. It has been rated as critical. The impacted element is an unknown function of the component XCom deserialize endpoint. This manipulation causes deserialization. This vulnerability is handled as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
5.8 MEDIUM
EPSS 5.5%
CVE-2026-59244 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-59244 | Apache Airflow Secrets masker information disclosure (EUVD-2026-57316)

A vulnerability was found in Apache Airflow. It has been declared as problematic. The affected element is an unknown function of the component Secrets masker. The manipulation results in information disclosure. This vulnerability is known a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 28.9%
CVE-2026-58076 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-58076 | Apache Airflow Exception Deserialization BaseSerialization.deserialize deserialization (EUVD-2026-57315)

A vulnerability classified as critical has been found in Apache Airflow. Affected is the function BaseSerialization.deserialize of the component Exception Deserialization. The manipulation leads to deserialization. This vulnerability is lis

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 30.9%
CVE-2026-67260 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-67260 | Apache Airflow Scheduler next_kwargs deserialization

A vulnerability was found in Apache Airflow. It has been classified as critical. Impacted is an unknown function of the component Scheduler. The manipulation of the argument next_kwargs leads to deserialization. This vulnerability is traded

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 25.2%
CVE-2026-18708 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18708 | MongoDB up to 7.0.39/8.0.28/8.3.7 JavaScript Scripting Engine code injection

A vulnerability, which was classified as problematic, was found in MongoDB up to 7.0.39/8.0.28/8.3.7. The affected element is an unknown function of the component JavaScript Scripting Engine. Such manipulation leads to code injection. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.1%
CVE-2026-68868 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-68868 | Apache Airflow Secret Manager Backend privileges management

A vulnerability identified as problematic has been detected in Apache Airflow. Affected by this vulnerability is an unknown functionality of the component Secret Manager Backend. Performing a manipulation results in improper privilege manag

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 30.5%
CVE-2026-18706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18706 | MongoDB Server up to 8.3.7 GraphLookup Aggregation Stage use after free

A vulnerability has been found in MongoDB Server up to 8.3.7 and classified as problematic. Affected by this issue is some unknown functionality of the component GraphLookup Aggregation Stage. The manipulation leads to use after free. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-18709 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18709 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Transaction Coordinator behavioral workflow

A vulnerability described as very critical has been identified in MongoDB Server up to 7.0.39/8.0.28/8.3.7. This affects an unknown part of the component Transaction Coordinator. Executing a manipulation can lead to enforcement of behaviora

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.1%
CVE-2026-18707 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18707 | MongoDB up to 8.3.7 Aggregation assertion (Nessus ID 343459)

A vulnerability marked as problematic has been reported in MongoDB up to 8.3.7. The affected element is an unknown function of the component Aggregation. The manipulation leads to reachable assertion. This vulnerability is uniquely identifi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.4%
CVE-2026-18701 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18701 | MongoDB up to 7.0.39/8.0.28/8.3.7 Query Subsystem denial of service

A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7 and classified as problematic. Affected by this issue is some unknown functionality of the component Query Subsystem. Such manipulation leads to denial of service. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.3%
CVE-2026-18705 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18705 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Atlas Vector Search privileges management

A vulnerability has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7 and classified as problematic. The impacted element is an unknown function of the component Atlas Vector Search. Performing a manipulation results in improper privil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.7%
CVE-2026-18704 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18704 | MongoDB up to 8.3.7 Aggregation Framework improper authorization

A vulnerability marked as problematic has been reported in MongoDB up to 8.3.7. Affected by this issue is some unknown functionality of the component Aggregation Framework. Performing a manipulation results in improper authorization. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.2%
CVE-2026-18700 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18700 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Geospatial Validation use after free

A vulnerability labeled as problematic has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected by this vulnerability is an unknown functionality of the component Geospatial Validation. Such manipulation leads to use after free.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28%
CVE-2026-18698 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18698 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 improper authorization

A vulnerability identified as very critical has been detected in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected is an unknown function. This manipulation causes improper authorization. This vulnerability appears as CVE-2026-18698. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.3%
CVE-2026-18696 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18696 | MongoDB up to 7.0.39/8.0.28/8.3.7 Authorization Check applyOps improper authorization

A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7. It has been rated as critical. This affects the function applyOps of the component Authorization Check. The manipulation leads to improper authorization. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.3%
CVE-2026-18697 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18697 | MongoDB up to 7.0.39/8.0.28/8.3.7 Aggregation Framework denial of service

A vulnerability categorized as problematic has been discovered in MongoDB up to 7.0.39/8.0.28/8.3.7. This impacts an unknown function of the component Aggregation Framework. The manipulation results in denial of service. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.2%
CVE-2026-18699 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18699 | MongoDB up to 7.0.39/8.0.28/8.3.7 Query Planner denial of service

A vulnerability classified as problematic has been found in MongoDB up to 7.0.39/8.0.28/8.3.7. Affected by this vulnerability is an unknown functionality of the component Query Planner. Performing a manipulation results in denial of service

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.6%
CVE-2026-18702 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18702 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Diagnostic Logging improper authorization

A vulnerability classified as critical was found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected by this issue is some unknown functionality of the component Diagnostic Logging. Executing a manipulation can lead to improper authorizat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.2%
CVE-2026-18703 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18703 | MongoDB Server up to 8.3.7 certificate validation

A vulnerability, which was classified as problematic, was found in MongoDB Server up to 8.3.7. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to improper certificate validation. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.8%
CVE-2022-44249 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44249 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 UploadFirmwareFile FileName command injection (EUVD-2022-47198)

A vulnerability identified as critical has been detected in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected is the function UploadFirmwareFile. This manipulation of the argument FileName causes command injection. The identification of this

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.7%
CVE-2022-44250 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44250 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setOpModeCfg Hostname command injection (EUVD-2022-47199)

A vulnerability labeled as critical has been found in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected by this vulnerability is the function setOpModeCfg. Such manipulation of the argument Hostname leads to command injection. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.2%
CVE-2022-44236 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44236 | Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807 weak password (EUVD-2022-47186)

A vulnerability classified as critical has been found in Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807. Impacted is an unknown function. This manipulation causes weak password requirements. This vulnerability is registered as CVE-2022-44236

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.5%
CVE-2026-19490 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Detecting and Containing CVE-2026-19490: A Defender's Checklist for NetScaler SAML Bypass

Detecting and Containing CVE-2026-19490: A Defender&#039;s Checklist for NetScaler SAML Bypass Most authentication bypasses announce themselves through failed logins. CVE-2026-19490 does the opposite. An attacker who exploits it produces a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31%
CVE-2022-44235 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44235 | Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807 cross site scripting (EUVD-2022-47185)

A vulnerability was found in Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. This manipulation causes cross site scripting. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.9%
CVE-2022-44232 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44232 | libming 0.4.8 decompile.c getInt denial of service (EUVD-2022-47182)

A vulnerability was found in libming 0.4.8. It has been classified as problematic. The affected element is the function getInt of the file decompile.c. The manipulation leads to denial of service. This vulnerability is traded as CVE-2022-44

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.4%
CVE-2022-44216 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44216 | Gnuboard 5.5.4/5.5.5 Change Password permission (EUVD-2022-47166)

A vulnerability was found in Gnuboard 5.5.4/5.5.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. Such manipulation leads to permission issues. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.6%
CVE-2022-44215 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44215 | Titan FTP Server up to 19.0 redirect (EUVD-2022-47165)

A vulnerability classified as problematic was found in Titan FTP Server up to 19.0. This issue affects some unknown processing. The manipulation results in open redirect. This vulnerability is identified as CVE-2022-44215. The attack can on

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.3%
CVE-2022-44213 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44213 | ZKTeco ZKBio ECO ADMS up to 3.1-164 cross site scripting (EUVD-2022-47163)

A vulnerability was found in ZKTeco ZKBio ECO ADMS up to 3.1-164 and classified as problematic. This affects an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2022-44213. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.5%
CVE-2022-44212 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44212 | GL.iNet Goodcloud 1.0 Admin Panel access control (EUVD-2022-47162)

A vulnerability labeled as critical has been found in GL.iNet Goodcloud 1.0. This issue affects some unknown processing of the component Admin Panel. Such manipulation leads to improper access controls. This vulnerability is listed as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.5%
CVE-2022-44211 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44211 | GL.iNet Goodcloud 1.1 Setting access control (EUVD-2022-47161)

A vulnerability identified as critical has been detected in GL.iNet Goodcloud 1.1. This vulnerability affects unknown code of the component Setting Handler. This manipulation causes improper access controls. This vulnerability is tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28%
CVE-2022-44201 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44201 | D-Link DIR823G 1.02B05 command injection (EUVD-2022-47151)

A vulnerability was found in D-Link DIR823G 1.02B05 and classified as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to command injection. The identification of this vulnerability is CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.6%
CVE-2022-44200 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44200 | Netgear R7000P 1.3.0.8/1.3.1.64 stamode_dns1_pri/stamode_dns1_sec buffer overflow (EUVD-2022-47150)

A vulnerability, which was classified as critical, was found in Netgear R7000P 1.3.0.8/1.3.1.64. Affected is an unknown function. Such manipulation of the argument stamode_dns1_pri/stamode_dns1_sec leads to buffer overflow. This vulnerabili

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.6%
CVE-2022-44199 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44199 | Netgear R7000P 1.3.1.64 openvpn_server_ip buffer overflow (EUVD-2022-47149)

A vulnerability, which was classified as critical, has been found in Netgear R7000P 1.3.1.64. This impacts an unknown function. This manipulation of the argument openvpn_server_ip causes buffer overflow. This vulnerability is handled as CVE

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.4%
CVE-2022-44198 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44198 | Netgear R7000P 1.3.1.64 openvpn_push1 buffer overflow (EUVD-2022-47148)

A vulnerability classified as critical was found in Netgear R7000P 1.3.1.64. This affects an unknown function. The manipulation of the argument openvpn_push1 results in buffer overflow. This vulnerability is known as CVE-2022-44198. Access

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.7%
CVE-2022-44197 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44197 | Netgear R7000P 1.3.0.8 openvpn_server_ip buffer overflow (EUVD-2022-47147)

A vulnerability classified as critical has been found in Netgear R7000P 1.3.0.8. The impacted element is an unknown function. The manipulation of the argument openvpn_server_ip leads to buffer overflow. This vulnerability is traded as CVE-2

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.1%
CVE-2022-44196 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44196 | Netgear R7000P 1.3.0.8 openvpn_push1 buffer overflow (EUVD-2022-47146)

A vulnerability described as critical has been identified in Netgear R7000P 1.3.0.8. The affected element is an unknown function. Executing a manipulation of the argument openvpn_push1 can lead to buffer overflow. This vulnerability appears

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.9%
CVE-2022-44194 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44194 | Netgear R7000P 1.3.0.8 apmode_dns1_pri/apmode_dns1_sec buffer overflow (EUVD-2022-47144)

A vulnerability marked as critical has been reported in Netgear R7000P 1.3.0.8. Impacted is an unknown function. Performing a manipulation of the argument apmode_dns1_pri/apmode_dns1_sec results in buffer overflow. This vulnerability is rep

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.7%
CVE-2026-20349 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance Software Remote Access SSL VPN service denial of service

A vulnerability was found in Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software and classified as critical. Affected by this issue is some unknown functionality of the component Remote Acc

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 31.5%
CVE-2026-69116 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-69116 | xpf0000 FlyEnv up to 4.17.x Html Sanitization injection

A vulnerability, which was classified as problematic, has been found in xpf0000 FlyEnv up to 4.17.x. This vulnerability affects unknown code of the component Html Sanitization. Performing a manipulation results in injection. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.3%
CVE-2026-69114 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-69114 | Spacebar Server Message Deletion Handlers permission

A vulnerability classified as problematic was found in Spacebar Server. This affects an unknown part of the component Message Deletion Handlers. Such manipulation leads to permission issues. This vulnerability is traded as CVE-2026-69114. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.1%
CVE-2026-71967 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71967 | OP-TEE OS up to 4.10.0 Widevine PTA is_user_ta_ctx null pointer dereference

A vulnerability was found in OP-TEE OS up to 4.10.0. It has been declared as critical. Affected is the function is_user_ta_ctx of the component Widevine PTA. Such manipulation leads to null pointer dereference. This vulnerability is listed

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.9%
CVE-2026-18694 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18694 | MongoDB up to 7.0.39/8.0.28/8.3.7 Geospatial Query Processing memory corruption

A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7. It has been declared as critical. The impacted element is an unknown function of the component Geospatial Query Processing. Executing a manipulation can lead to memory corrupti

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.9%
CVE-2026-18695 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18695 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 denial of service

A vulnerability, which was classified as problematic, has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected is an unknown function. Performing a manipulation results in denial of service. This vulnerability is identified as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2026-69112 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-69112 | Hugging Face Accelerate up to 1.14.0 Sharded Checkpoint Index weight_map path traversal

A vulnerability, which was classified as critical, was found in Hugging Face Accelerate up to 1.14.0. Affected by this issue is the function load_checkpoint_in_model/load_checkpoint_and_dispatch of the component Sharded Checkpoint Index. Su

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31%
CVE-2026-18691 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18691 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Intra-cluster Connection Setup improper authentication

A vulnerability has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7 and classified as critical. This issue affects some unknown processing of the component Intra-cluster Connection Setup. This manipulation causes improper authenticat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-18692 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18692 | MongoDB Server up to 8.3.7 Timeseries use after free

A vulnerability was found in MongoDB Server up to 8.3.7 and classified as critical. Impacted is an unknown function of the component Timeseries Handler. Such manipulation leads to use after free. This vulnerability is listed as CVE-2026-186

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.6%
CVE-2026-18693 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18693 | MongoDB up to 7.0.39/8.0.28/8.3.7 Timeseries memory corruption

A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7. It has been classified as critical. The affected element is an unknown function of the component Timeseries Handler. Performing a manipulation results in memory corruption. Thi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-76460 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-76460 | Cisco Identity Services Engine Software API improper authentication

A vulnerability classified as very critical was found in Cisco Identity Services Engine Software and ISE Passive Identity Connector. This affects an unknown function of the component API. Such manipulation leads to improper authentication.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 28.1%
CVE-2026-68772 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-68772 | ZenML up to 0.94.6 CloudpickleMaterializer cloudpickle_materializer.py cloudpickle.load deserialization

A vulnerability was found in ZenML up to 0.94.6. It has been rated as problematic. Impacted is the function cloudpickle.load of the file cloudpickle_materializer.py of the component CloudpickleMaterializer. Performing a manipulation results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.9%
CVE-2026-5855 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-5855 | Contiki-NG LwM2M TLV parser lwm2m-tlv.c lwm2m_tlv_read length out-of-bounds

A vulnerability, which was classified as very critical, has been found in Contiki-NG. This impacts the function lwm2m_tlv_read of the file os/services/lwm2m/lwm2m-tlv.c of the component LwM2M TLV parser. Performing a manipulation of the arg

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.7%
CVE-2026-5856 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-5856 | Contiki-NG mDNS Resolver resolv.c skip_name out-of-bounds

A vulnerability was found in Contiki-NG. It has been classified as critical. This affects the function skip_name of the file os/services/resolv/resolv.c of the component mDNS Resolver. This manipulation causes out-of-bounds read. The identi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.1%
CVE-2026-53977 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-53977 | Bohdan Triapitsyn OpenChamber up to 1.11.7 Route bootstrap-runtime.js improper authentication

A vulnerability was found in Bohdan Triapitsyn OpenChamber up to 1.11.7. It has been rated as critical. The affected element is an unknown function of the file bootstrap-runtime.js of the component Route Handler. The manipulation leads to i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.9%
CVE-2026-53975 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-53975 | Bohdan Triapitsyn OpenChamber up to 1.11.7 Command Execution /api/fs/exec spawn os command injection

A vulnerability, which was classified as critical, was found in Bohdan Triapitsyn OpenChamber up to 1.11.7. This vulnerability affects the function spawn of the file /api/fs/exec of the component Command Execution. The manipulation results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.7%
CVE-2026-53976 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-53976 | Bohdan Triapitsyn OpenChamber up to 1.11.7 File Serving /api/fs/read resolveReadPathFromContext allowOutsideWorkspace path traversal

A vulnerability has been found in Bohdan Triapitsyn OpenChamber up to 1.11.7 and classified as critical. This issue affects the function resolveReadPathFromContext of the file /api/fs/read of the component File Serving. This manipulation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-70617 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70617 | Spacebar Server Channels Recipient Endpoint authorization (dcfd910)

A vulnerability marked as critical has been reported in Spacebar Server. Affected by this vulnerability is an unknown functionality of the component Channels Recipient Endpoint. Performing a manipulation results in missing authorization. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.7%
CVE-2026-70618 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70618 | Spacebar Server Roles Member-Ids Endpoint improper authorization

A vulnerability classified as problematic has been found in Spacebar Server. This affects an unknown part of the component Roles Member-Ids Endpoint. The manipulation leads to improper authorization. This vulnerability is traded as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.3%
CVE-2022-4995 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-4995 | Weaver Network E-cology up to 10.51 uploaderOperate.jsp secId/plandetailid unrestricted upload

A vulnerability, which was classified as critical, has been found in Weaver Network E-cology up to 10.51. This issue affects some unknown processing of the file /workrelate/plan/util/uploaderOperate.jsp. The manipulation of the argument sec

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.