🎯 CVE-2026-93373
📄 .md Alle CVEs anzeigen ✕

CVE-2026-93373: Schwachstellen-Eintrag (NVD)

Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)

Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📰 Eigene Berichterstattung: ➔ CVE-2026-93373 | Google Chrome up to 153.0.8010.47 Extensions use after free (Ne
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
Veröffentlicht:17.09.2026
Aktualisiert:17.09.2026 21:17
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 94 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.857 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-302026-09-18
≥90 %00
≥50 %00
≥10 %00
<10 %300300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
EPSS 22.4%
CVE-2025-27771 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-27771 | uptrain-ai UpTrain up to 0.7.1 add_prompts checks/metadata code injection (EUVD-2025-210735)

A vulnerability labeled as critical has been found in uptrain-ai UpTrain up to 0.7.1. This affects an unknown part of the component add_prompts. The manipulation of the argument checks/metadata results in code injection. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.6%
CVE-2025-27770 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-27770 | uptrain-ai UpTrain up to 0.7.1 checks/metadata code injection

A vulnerability identified as critical has been detected in uptrain-ai UpTrain up to 0.7.1. Affected by this issue is some unknown functionality. The manipulation of the argument checks/metadata leads to code injection. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.5%
CVE-2026-45699 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45699 | Netatalk up to 4.4.2 copydir stack-based overflow

A vulnerability was found in Netatalk up to 4.4.2. It has been declared as critical. The impacted element is the function copydir. Such manipulation leads to stack-based buffer overflow. This vulnerability is referenced as CVE-2026-45699. T

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.4%
CVE-2025-27621 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-27621 | UpTrain AI up to 0.7.1 Backend uptrain-access-token cross-domain policy

A vulnerability categorized as problematic has been discovered in UpTrain AI UpTrain up to 0.7.1. Affected by this vulnerability is an unknown functionality of the component Backend. Executing a manipulation of the argument uptrain-access-t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.4%
CVE-2025-27772 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-27772 | uptrain-ai UpTrain up to 0.7.1 checks/metadata code injection

A vulnerability classified as critical was found in uptrain-ai UpTrain up to 0.7.1. Affected by this vulnerability is an unknown functionality. The manipulation of the argument checks/metadata results in code injection. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.1%
CVE-2026-73846 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73846 | ondata ckan-mcp-server up to 0.4.111 Cache src/utils/cache.ts canonicalizeParams data authenticity

A vulnerability described as critical has been identified in ondata ckan-mcp-server up to 0.4.111. This vulnerability affects the function canonicalizeParams of the file src/utils/cache.ts of the component Cache. Executing a manipulation ca

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.6%
CVE-2026-49986 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-49986 | cdeust Cortex up to 3.17.0 Root Validation visualize_bootstrap.py _is_cortex_root CLAUDE_PROJECT_DIR code injection

A vulnerability was found in cdeust Cortex up to 3.17.0. It has been rated as problematic. This impacts the function _is_cortex_root of the file mcp_server/server/visualize_bootstrap.py of the component Root Validation. The manipulation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22.7%
CVE-2026-49826 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-49826 | Concourse up to 8.2.2 redirect

A vulnerability categorized as problematic has been discovered in Concourse up to 8.2.2. Affected is an unknown function. The manipulation results in open redirect. This vulnerability was named CVE-2026-49826. The attack may be performed fr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.3%
CVE-2026-46380 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-46380 | compliance-trestle Remote Fetching Subsystem server-side request forgery

A vulnerability was found in compliance-trestle. It has been rated as critical. This affects an unknown function of the component Remote Fetching Subsystem. Performing a manipulation results in server-side request forgery. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.9%
CVE-2026-73664 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73664 | FreePBX up to 17.0.10 publicKeySave AJAX endpoint Backup.class.php improper authorization

A vulnerability categorized as very critical has been discovered in FreePBX up to 17.0.10. This affects an unknown part of the file Backup.class.php of the component publicKeySave AJAX endpoint. Executing a manipulation can lead to improper

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.6%
CVE-2026-73428 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73428 | Basecamp Trix up to 2.1.17 HTMLParser/StringPiece StringPiece.fromJSON HTML injection

A vulnerability has been found in Basecamp Trix up to 2.1.17 and classified as problematic. The affected element is the function StringPiece.fromJSON of the component HTMLParser/StringPiece. The manipulation leads to HTML injection. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 31.4%
CVE-2026-73489 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73489 | Eugeny Russh up to 0.62.3 Parser encrypted.rs out-of-bounds

A vulnerability, which was classified as problematic, has been found in Eugeny Russh up to 0.62.3. This issue affects some unknown processing of the file russh/src/server/encrypted.rs of the component Parser. Performing a manipulation resul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.4%
CVE-2026-73420 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73420 | NextAuth.js auth-core-next-auth Email Normalization defaultNormalizer improper authentication

A vulnerability classified as critical was found in NextAuth.js auth-core-next-auth. This vulnerability affects the function defaultNormalizer of the component Email Normalization. Such manipulation leads to improper authentication. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.4%
CVE-2026-73417 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73417 | Jupyter JupyterLab up to 4.5.9/4.6.1 Notebook Extension index.ts code injection

A vulnerability labeled as problematic has been found in Jupyter JupyterLab up to 4.5.9/4.6.1. Affected is an unknown function of the file packages/notebook-extension/src/index.ts of the component Notebook Extension. Executing a manipulatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20%
CVE-2026-73660 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73660 | FreePBX prior 16.0.6/17.0.5.4 Text-To-Speech module agi-bin/propolys-tts.agi os command injection

A vulnerability has been found in FreePBX and classified as problematic. This affects an unknown function of the file agi-bin/propolys-tts.agi of the component Text-To-Speech module. The manipulation leads to os command injection. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.4%
CVE-2026-73416 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73416 | JupyterLab up to 4.5.9/4.6.1 PyPI Extension Manager manager.py privileges management

A vulnerability was found in JupyterLab up to 4.5.9/4.6.1 and classified as problematic. This issue affects some unknown processing of the file jupyterlab/extensions/manager.py of the component PyPI Extension Manager. Executing a manipulati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.4%
CVE-2026-73661 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-73661 | FreePBX up to 16.0.46/17.0.29 Framework Restore.php runRestore improper authentication

A vulnerability classified as problematic was found in FreePBX up to 16.0.46/17.0.29. Impacted is the function runRestore of the file amp_conf/htdocs/admin/libraries/Builtin/Restore.php of the component Framework Module. Such manipulation l

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.6%
CVE-2026-73663 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73663 | FreePBX up to 16.0.10/17.0.3 missedcall module missedcallnotify.php sql injection

A vulnerability, which was classified as critical, has been found in FreePBX up to 16.0.10/17.0.3. The affected element is an unknown function of the file agi-bin/missedcallnotify.php of the component missedcall module. Performing a manipul

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.6%
CVE-2026-73656 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73656 | Triggerdotdev Trigger.dev up to 4.5.5 Background Worker Deployment Service createDeploymentBackgroundWorkerV4.server.ts CreateDeploymentBackgroundWorkerServiceV4.call privileges management

A vulnerability, which was classified as critical, has been found in Triggerdotdev Trigger.dev up to 4.5.5. Impacted is the function CreateDeploymentBackgroundWorkerServiceV4.call of the file apps/webapp/app/v3/services/createDeploymentBack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.4%
CVE-2026-73662 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73662 | FreePBX up to 17.0.6 Music on Hold Music.class.php validateCustomConfiguration os command injection

A vulnerability classified as problematic has been found in FreePBX up to 17.0.6. This issue affects the function validateCustomConfiguration of the file Music.class.php of the component Music on Hold. This manipulation causes os command in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.6%
CVE-2026-73421 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73421 | nextauthjs next-auth up to 5.0.0-beta.31 Session Parsing improper authorization

A vulnerability marked as critical has been reported in nextauthjs next-auth up to 5.0.0-beta.31. Affected by this vulnerability is the function auth of the component Session Parsing. The manipulation leads to improper authorization. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18.1%
CVE-2026-20361 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-20361 | Cisco Nexus Dashboard up to 4.2.1 sql injection (Nessus ID 348238)

A vulnerability has been found in Cisco Nexus Dashboard and classified as critical. The affected element is an unknown function. The manipulation leads to sql injection. This vulnerability is referenced as CVE-2026-20361. Remote exploitatio

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
EPSS 25%
CVE-2026-20326 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-20326 | Cisco Nexus Dashboard up to 4.2.1 missing authentication (Nessus ID 348238)

A vulnerability classified as very critical was found in Cisco Nexus Dashboard. This vulnerability affects unknown code. Such manipulation leads to missing authentication. This vulnerability is uniquely identified as CVE-2026-20326. The att

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
EPSS 25.4%
CVE-2026-20325 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-20325 | Cisco Nexus Dashboard up to 4.2.1 command injection (Nessus ID 348238)

A vulnerability classified as very critical has been found in Cisco Nexus Dashboard. This affects an unknown part. This manipulation causes command injection. This vulnerability is handled as CVE-2026-20325. The attack can be initiated remo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
EPSS 22.3%
CVE-2026-20322 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-20322 | Cisco Nexus Dashboard up to 4.2.1 access control (Nessus ID 348238)

A vulnerability described as very critical has been identified in Cisco Nexus Dashboard. Affected by this issue is some unknown functionality. The manipulation results in improper access controls. This vulnerability is known as CVE-2026-203

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
EPSS 32.8%
CVE-2024-1086 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-1086: Celah Keamanan Kernel Linux Berisiko Tinggi Akses Root

Apa itu CVE-2024-1086? CVE-2024-1086 adalah kerentanan keamanan kritis pada kernel Linux. Kerentanan ini sangat serius, memungkinkan penyerang lokal meningkatkan hak akses hingga tingkat root, mengambil alih kendali penuh sistem terinfeksi.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 25.7%
CVE-2026-59714 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-59714 | open-webui Open WebUI Chat Completion API improper authorization

A vulnerability marked as critical has been reported in open-webui Open WebUI. The affected element is an unknown function of the component Chat Completion API. The manipulation leads to improper authorization. This vulnerability is referen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.4%
CVE-2026-45725 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45725 | oscal-compass compliance-trestle up to 3.12.1/4.0.2 Remote Fetching Cache Mechanism path traversal

A vulnerability classified as problematic was found in oscal-compass compliance-trestle up to 3.12.1/4.0.2. This impacts an unknown function of the component Remote Fetching Cache Mechanism. Such manipulation leads to path traversal. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.4%
CVE-2026-73655 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-73655 | Trigger.dev up to 4.5.1 Google Authentication googleAuth.server.ts addGoogleStrategy improper authentication

A vulnerability marked as critical has been reported in Trigger.dev up to 4.5.1. Affected by this issue is the function addGoogleStrategy of the file apps/webapp/app/services/googleAuth.server.ts of the component Google Authentication. Perf

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.2%
CVE-2026-73649 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73649 | shepherdwind Velocity.js up to 2.1.6 Property-Read Expressions references.ts getReferences os command injection

A vulnerability, which was classified as critical, was found in shepherdwind Velocity.js up to 2.1.6. This issue affects the function getReferences of the file src/compile/references.ts of the component Property-Read Expressions. Executing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.1%
CVE-2026-73644 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73644 | OpenIdentityPlatform OpenDJ up to 5.1.1 SASL PlainSASLMechanismHandler.java improper authorization

A vulnerability was found in OpenIdentityPlatform OpenDJ up to 5.1.1. It has been classified as very critical. The impacted element is an unknown function of the file opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASL

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 31.9%
CVE-2026-45774 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45774 | oscal-compass compliance-trestle up to 3.12.1/4.0.2 Profile Import Mechanism resolve imports[].href path traversal

A vulnerability labeled as problematic has been found in oscal-compass compliance-trestle up to 3.12.1/4.0.2. Impacted is the function resolve of the component Profile Import Mechanism. Executing a manipulation of the argument imports[].hre

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 6.8%
CVE-2026-73654 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73654 | triggerdotdev trigger.dev up to 4.5.5 Run Metadata operations.ts JSONHeroPath.set operation.key denial of service

A vulnerability has been found in triggerdotdev trigger.dev up to 4.5.5 and classified as problematic. This impacts the function JSONHeroPath.set of the file packages/core/src/v3/runMetadata/operations.ts of the component Run Metadata. Perf

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.9%
CVE-2026-73650 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73650 | svg SVGO up to 2.8.2/3.3.3/4.0.1 removeScripts cross site scripting

A vulnerability was found in svg SVGO up to 2.8.2/3.3.3/4.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component removeScripts. Executing a manipulation can lead to cross site s

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22.7%
CVE-2026-73651 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73651 | TypeORM up to 0.3.30/1.0.x Migration Generate Command MigrationGenerateCommand.ts generate COMMENT/DEFAULT code injection

A vulnerability, which was classified as problematic, has been found in TypeORM up to 0.3.30/1.0.x. The affected element is the function Generate of the file src/commands/MigrationGenerateCommand.ts of the component Migration Generate Comma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18.9%
CVE-2026-73652 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73652 | vantage6 up to 5.0.2 algorithm-store permission

A vulnerability, which was classified as critical, was found in vantage6 up to 5.0.2. The impacted element is an unknown function of the component algorithm-store. The manipulation results in permission issues. This vulnerability was named

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18%
CVE-2026-73643 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73643 | nodeca js-yaml up to 5.2.1 Parser src/parser/parser.ts readFlowCollection infinite loop (Nessus ID 335459)

A vulnerability categorized as problematic has been discovered in nodeca js-yaml up to 5.2.1. Affected is the function readFlowCollection of the file src/parser/parser.ts of the component Parser. Executing a manipulation can lead to infinit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18%
CVE-2026-73648 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73648 | rails rails-html-sanitizer up to 1.7.0 PermitScrubber cross-domain policy

A vulnerability labeled as problematic has been found in rails rails-html-sanitizer up to 1.7.0. Affected by this issue is some unknown functionality of the component PermitScrubber. The manipulation results in permissive cross-domain polic

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.7%
CVE-2026-73645 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73645 | OpenZeppelin Confidential Contracts up to 0.3.0 ERC7984ERC20Wrapper ERC7984ERC20Wrapper.sol wrap/onTransferReceived integer overflow

A vulnerability was found in OpenZeppelin Confidential Contracts up to 0.3.0. It has been declared as problematic. This affects the function wrap/onTransferReceived of the file contracts/token/ERC7984/extensions/ERC7984ERC20Wrapper.sol of t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22.4%
CVE-2026-73564 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73564 | fatedier frp up to 0.70.0 SSH Tunnel Gateway pkg/ssh/server.go TunnelServer.handleNewChannel integer overflow

A vulnerability labeled as problematic has been found in fatedier frp up to 0.70.0. This impacts the function TunnelServer.handleNewChannel of the file pkg/ssh/server.go of the component SSH Tunnel Gateway. Executing a manipulation can lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.2%
CVE-2026-48702 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48702 | Sigstore Rekor up to 1.5.1 APK File pkg/types/alpine/apk.go Package.Unmarshal allocation of resources

A vulnerability labeled as problematic has been found in Sigstore Rekor up to 1.5.1. This affects the function Package.Unmarshal of the file pkg/types/alpine/apk.go of the component APK File Handler. The manipulation results in allocation o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.9%
CVE-2026-73569 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73569 | NaturalIntelligence fast-xml-parser up to 5.10.0 XML Parser OrderedObjParser.js addInputEntities resource consumption

A vulnerability was found in NaturalIntelligence fast-xml-parser up to 5.10.0 and classified as problematic. The affected element is the function addInputEntities of the file src/xmlparser/OrderedObjParser.js of the component XML Parser. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.4%
CVE-2026-73567 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73567 | JuneAndGreen sm-crypto up to 0.4.x SM2 src/sm2/utils.js sm2.generateKeyPairHex random values

A vulnerability classified as problematic was found in JuneAndGreen sm-crypto up to 0.4.x. This affects the function sm2.generateKeyPairHex of the file src/sm2/utils.js of the component SM2. Such manipulation leads to insufficiently random

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.5%
CVE-2026-73562 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73562 | Automattic Mongoose up to 6.13.9/7.8.9/8.24.0/9.7.1 Update Casting body prototype pollution

A vulnerability classified as critical has been found in Automattic Mongoose up to 6.13.9/7.8.9/8.24.0/9.7.1. Affected by this issue is the function Schema.prototype.path/Schema.prototype._getPathType of the component Update Casting. This m

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23.1%
CVE-2026-73563 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73563 | Backstage up to 0.29.1 Dynamic Client Registration redirect

A vulnerability identified as problematic has been detected in Backstage up to 0.29.1. This affects an unknown function of the component Dynamic Client Registration. Performing a manipulation of the argument... Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.7%
CVE-2026-73568 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73568 | libp2p py-libp2p up to 0.7.0 yamux yamux.py handle_incoming infinite loop

A vulnerability was found in libp2p py-libp2p up to 0.7.0. It has been rated as problematic. The affected element is the function handle_incoming of the file libp2p/stream_muxer/yamux/yamux.py of the component yamux. This manipulation cause

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.9%
CVE-2026-73509 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73509 | OpenListTeam OpenList up to 4.2.3 Path Normalization fsbatch.go api/fs/batch_rename src_name path traversal

A vulnerability was found in OpenListTeam OpenList up to 4.2.3. It has been rated as critical. Affected is the function api/fs/batch_rename of the file server/handles/fsbatch.go of the component Path Normalization. This manipulation of the

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.4%
CVE-2026-49856 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-49856 | vmoranv jshookmcp 0.3.1 server-side request forgery

A vulnerability has been found in vmoranv jshookmcp 0.3.1 and classified as problematic. Impacted is an unknown function. This manipulation causes server-side request forgery. This vulnerability is handled as CVE-2026-49856. The attack can

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24%
CVE-2026-49857 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-49857 | ymw0407 auth-fetch-mcp up to 3.0.1 src/security.ts isPrivateV6 server-side request forgery

A vulnerability marked as critical has been reported in ymw0407 auth-fetch-mcp up to 3.0.1. Affected is the function isPrivateV6 of the file src/security.ts. This manipulation causes server-side request forgery. This vulnerability is regist

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32%
CVE-2026-49820 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-49820 | GetProbo up to 0.193.0 saferedirect path.Clean continue

A vulnerability categorized as problematic has been discovered in GetProbo Probo up to 0.193.0. The impacted element is the function path.Clean of the component saferedirect. Executing a manipulation of the argument continue can lead to ope

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.4%
CVE-2026-49481 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-49481 | seriousm4x UpSnap up to 5.3.x Device Management ip/mac os command injection

A vulnerability, which was classified as critical, has been found in seriousm4x UpSnap up to 5.3.x. Affected by this issue is some unknown functionality of the component Device Management. Performing a manipulation of the argument ip/mac re

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.7%
CVE-2026-49827 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-49827 | SMEWebify WebErpMesv2 up to 1.19 File Upload scan_file input validation

A vulnerability was found in SMEWebify WebErpMesv2 up to 1.19. It has been rated as critical. This impacts an unknown function of the component File Upload. This manipulation of the argument scan_file causes improper input validation. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.7%
CVE-2026-73291 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73291 | seerr-team Seerr up to 3.3.x ImageProxy server/lib/imageproxy.ts path.join path traversal

A vulnerability has been found in seerr-team Seerr up to 3.3.x and classified as critical. Affected by this issue is the function path.join of the file server/lib/imageproxy.ts of the component ImageProxy. Performing a manipulation results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 5.4%
CVE-2026-73296 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-73296 | Microsoft UFO up to 3.0.7 Mobile MCP Server mobile_mcp_server.py information disclosure (EUVD-2026-57323)

A vulnerability was found in Microsoft UFO up to 3.0.7. It has been declared as problematic. This affects the function create_mobile_data_collection_server/create_mobile_action_server of the file ufo/client/mcp/http_servers/mobile_mcp_serve

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 18.3%
CVE-2026-73500 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73500 | etcd-io etcd up to 3.5.32/3.6.13/3.7.0 TLS Listener listener_tls.go tls.Conn.Handshake infinite loop

A vulnerability was found in etcd-io etcd up to 3.5.32/3.6.13/3.7.0. It has been classified as problematic. This affects the function tls.Conn.Handshake of the file client/pkg/transport/listener_tls.go of the component TLS Listener. The man

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.1%
CVE-2026-73501 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73501 | getkin kin-openapi up to 0.143.x ValidationHandler validation_handler.go ValidationHandler.Load improper authentication

A vulnerability was found in getkin kin-openapi up to 0.143.x and classified as critical. Affected by this issue is the function ValidationHandler.Load of the file openapi3filter/validation_handler.go of the component ValidationHandler. Exe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.7%
CVE-2026-73499 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73499 | etcd-io etcd up to 3.5.32/3.6.13/3.7.0 Range Permission Cache range_perm_cache.go isRangeOpPermitted permission

A vulnerability has been found in etcd-io etcd up to 3.5.32/3.6.13/3.7.0 and classified as problematic. Affected by this vulnerability is the function isRangeOpPermitted of the file server/auth/range_perm_cache.go of the component Range Per

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 31.9%
CVE-2026-73298 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-73298 | Microsoft Container Migration Solution Accelerator up to 2.1.2 resource injection

A vulnerability labeled as critical has been found in Microsoft Container Migration Solution Accelerator up to 2.1.2. Affected by this issue is some unknown functionality. Such manipulation leads to improper control of resource identifiers.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 25.1%
CVE-2026-73498 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73498 | sooperset mcp-atlassian up to 0.21.x Attachments attachments.py _upload_attachment_direct file_path path traversal

A vulnerability identified as problematic has been detected in sooperset mcp-atlassian up to 0.21.x. This vulnerability affects the function _upload_attachment_direct of the file src/mcp_atlassian/confluence/attachments.py of the component

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.2%
CVE-2026-73297 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-73297 | Microsoft UFO up to 3.0.7 url_security.py _is_blocked_ip server-side request forgery (EUVD-2026-57325)

A vulnerability was found in Microsoft UFO up to 3.0.7. It has been rated as critical. This vulnerability affects the function _is_blocked_ip of the file ufo/utils/url_security.py. This manipulation causes server-side request forgery. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.