Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-05 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-76218 | gitpython-developers GitPython up to 3.1.57 Repo Init Repo.init template initialization (Nessus ID 338207)
A vulnerability classified as critical was found in gitpython-developers GitPython up to 3.1.57. This issue affects the function Repo.init of the component Repo Init. The manipulation of the argument template results in improper initializat
CVE-2026-18504 | Fastify up to 5.12.0 input validation
A vulnerability was found in Fastify up to 5.12.0. It has been declared as critical. The impacted element is an unknown function. The manipulation results in improper input validation. This vulnerability is reported as CVE-2026-18504. The a
CVE-2026-47606 | NVIDIA Triton Inference Server up to 26.05 path traversal
A vulnerability was found in NVIDIA Triton Inference Server up to 26.05. It has been classified as critical. Affected is an unknown function. The manipulation leads to path traversal. This vulnerability is uniquely identified as CVE-2026-47
CVE-2026-24184 | NVIDIA Cumulus Linux Link Layer Discovery Protocol Daemon buffer overflow
A vulnerability was found in NVIDIA Cumulus Linux and classified as very critical. This impacts an unknown function of the component Link Layer Discovery Protocol Daemon. Executing a manipulation can lead to buffer overflow. This vulnerabil
CVE-2026-66780 | Red Hat Advanced Cluster Management for Kubernetes submariner-operator redirect
A vulnerability was found in Red Hat Advanced Cluster Management for Kubernetes. It has been declared as problematic. This affects an unknown part of the component submariner-operator. The manipulation results in open redirect. This vulnera
CVE-2026-73372 | Joomla! Project Joomla Extension up to 5.4.7/6.1.2 Contact privileges management (WID-SEC-2026-2926)
A vulnerability was found in Joomla! Project Joomla Extension up to 5.4.7/6.1.2. It has been declared as problematic. This issue affects some unknown processing of the component Contact. The manipulation results in improper privilege manage
CVE-2026-73336 | Joomla Extension up to 5.1.0/5.4.7/6.0.0/6.1.2 cross site scripting (WID-SEC-2026-2926)
A vulnerability was found in Joomla Extension up to 5.1.0/5.4.7/6.0.0/6.1.2. It has been rated as problematic. Impacted is an unknown function. This manipulation causes cross site scripting. This vulnerability is registered as CVE-2026-7333
CVE-2026-71573 | Joomla up to 5.4.7/6.1.2 CORS cross-domain policy (WID-SEC-2026-2926)
A vulnerability was found in Joomla up to 5.4.7/6.1.2 and classified as problematic. This affects an unknown part of the component CORS. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. This vulner
CVE-2026-72531 | Joomla Project Joomla Extension up to 4.0.0/5.4.7/6.0.0/6.1.2 Custom Fields improper authorization (WID-SEC-2026-2926)
A vulnerability was found in Joomla Project Joomla Extension up to 4.0.0/5.4.7/6.0.0/6.1.2. It has been classified as critical. This vulnerability affects unknown code of the component Custom Fields. The manipulation leads to improper autho
CVE-2026-71572 | Joomla! Project Joomla Extension up to 3.0.0/5.4.6/6.0.0/6.1.2 Download Views type confusion (WID-SEC-2026-2926)
A vulnerability has been found in Joomla! Project Joomla Extension up to 3.0.0/5.4.6/6.0.0/6.1.2 and classified as problematic. Affected by this issue is some unknown functionality of the component Download Views. Performing a manipulation
CVE-2026-84326 | Google Chrome up to 152.0.7977.65 V8 uninitialized pointer (Nessus ID 343082)
A vulnerability categorized as critical has been discovered in Google Chrome. Affected by this vulnerability is an unknown functionality of the component V8. Such manipulation leads to uninitialized pointer. This vulnerability is listed as
CVE-2026-84349 | Google Chrome up to 152.0.7977.65 Browser use after free (EUVD-2026-69734 / Nessus ID 343082)
A vulnerability categorized as critical has been discovered in Google Chrome. This vulnerability affects unknown code of the component Browser. Executing a manipulation can lead to use after free. This vulnerability is tracked as CVE-2026-8
CVE-2026-78183 | Bucardo DBD::Pg 3.21.0 quote.c quote_float heap-based overflow (Nessus ID 343084)
A vulnerability identified as critical has been detected in Bucardo DBD::Pg 3.21.0. Affected by this issue is the function quote_float of the file quote.c. The manipulation leads to heap-based buffer overflow. This vulnerability is document
CVE-2026-63633 | FreeRDP up to 3.27.x DSP Codec libfreerdp/codec/dsp.c freerdp_dsp_decode_opus heap-based overflow (Nessus ID 343085)
A vulnerability was found in FreeRDP up to 3.27.x and classified as problematic. The affected element is the function freerdp_dsp_decode_opus of the file libfreerdp/codec/dsp.c of the component DSP Codec. Such manipulation leads to heap-bas
CVE-2026-63652 | FreeRDP up to 3.27.x RDP Sound Server rdpsnd_main.c rdpsnd_server_recv_formats double free (Nessus ID 343085)
A vulnerability classified as very critical was found in FreeRDP up to 3.27.x. This affects the function rdpsnd_server_recv_formats of the file channels/rdpsnd/server/rdpsnd_main.c of the component RDP Sound Server. Executing a manipulation
CVE-2026-86098 | ntop nDPI up to 5.x ndpi_json_string_escape heap-based overflow (Nessus ID 343095)
A vulnerability labeled as critical has been found in ntop nDPI up to 5.x. This affects the function ndpi_json_string_escape. The manipulation results in heap-based buffer overflow. This vulnerability is reported as CVE-2026-86098. The atta
CVE-2026-86095 | Unidata NetCDF-C up to 4.10.1 HDF5 Attribute NC4_HDF5_inq_attname out-of-bounds write (Nessus ID 343092)
A vulnerability categorized as problematic has been discovered in Unidata NetCDF-C up to 4.10.1. Affected by this vulnerability is the function NC4_HDF5_inq_attname of the component HDF5 Attribute Handler. Executing a manipulation can lead
Magento-Backdoor „StyleSmuggler“: Ungepatchte Zero-Day trifft Adobe Commerce
LONDON (IT BOLTWISE) – Eine ungesicherte Zero-Day-Lücke in Magento Open Source und Adobe Commerce wird offenbar aktiv ausgenutzt. Die Sicherheitsfirma Sansec nennt die Schwachstelle „StyleSmuggler“ und beschreibt eine Kette, die ohne Login
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advi
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
Broadcom schließt kritische Lücke in VMware Workstation und Fusion (CVE-2026-59346)
LONDON (IT BOLTWISE) – Broadcom hat Sicherheitsupdates für VMware Workstation und VMware Fusion veröffentlicht und schließt dabei zwei Lücken, darunter einen kritischen Integer-Overflow mit CVSS 9,3. Unter bestimmten Bedingungen kann ein An
Elementor Pro WordPress Flaw Exploited to Upload Webshells and Execute Commands
A critical vulnerability in the Elementor Pro WordPress plugin is being actively exploited to upload malicious PHP files and execute commands remotely on the affected websites. The vulnerability, tracked as CVE-2026-32475, affects the Ele
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026
Switchvox Vulnerability Triggers Active Exploitation Risk
Sangoma Switchvox CVE-2026-9586 is a serious unauthenticated SQL injection flaw that can lead to remote code execution, and Horizon3 says it has already seen real-world exploitation attempts. The issue was patched in Switchvox 8.4.0.2, ma
CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft
CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. This article has been indexed from Security Archives – TechRepublic Read the original article: C
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. This article has been indexed from SecurityWeek Read the original article: Elementor Pro WordP
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o
PaperCut-Schwachstellen: Angreifer stehlen Anmeldedaten an Schulen und Universitäten
LONDON (IT BOLTWISE) – Angreifer nutzen neu gemeldete PaperCut-Schwachstellen, um an Schulen und Universitäten in den USA und Europa Zugangsdaten auszuspähen. In den Beobachtungen wurden CVE-2026-81578 und CVE-2026-82078 für Authentifizieru
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect
PostgreSQL stoppt Codeausführung via Logical Decoding: neuer Whitelist-Parameter
LONDON (IT BOLTWISE) – PostgreSQL schließt eine seit 2014 bekannte Schwachstelle (CVE-2026-6471), die mit dem REPLICATION-Attribut beliebigen Code im Backend-Prozess ausführen konnte. Die Absicherung erfolgt über einen neuen Parameter outpu
PostgreSQL fixiert CVE-2026-6471: REPLICATION-Benutzer können Code als DB-User ausführen
LONDON (IT BOLTWISE) – PostgreSQL hat ein Sicherheitsproblem mit der logischen Replikation geschlossen, das einem Konto mit REPLICATION-Attribut die Ausführung beliebigen Codes als OS-User des Datenbankservers ermöglicht. Betroffen sind Ver
HPE Patches Critical RCE Vulnerabilities in AOS-CX
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen
CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft
CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. The post CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft appeared firs
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. Weiterlesen
[NEU] [niedrig] Checkmk: Schwachstelle ermöglicht Denial of Service
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Checkmk Agent Receiver ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code
TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices. The fla
Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code
TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices. The fla
[NEU] [UNGEPATCHT] [mittel] xpdf: Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in xpdf ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Codeausführung
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Dell integrated Dell Remote Access Controller ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ollama ausnutzen, um Informationen offenzulegen. Weiterlesen
[NEU] [hoch] util-linux: Schwachstelle ermöglicht Privilegieneskalation
Ein lokaler Angreifer kann eine Schwachstelle in util-linux ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen
[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Manipulation von Dateien
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoNetwork ausnutzen, um Dateien zu manipulieren. Weiterlesen
[NEU] [UNGEPATCHT] [mittel] bluez: Schwachstelle ermöglicht Codeausführung
Ein Angreifer in Bluetooth-Reichweite kann eine Schwachstelle in bluez ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
Google patches actively exploited Chrome zero-day (CVE-2026-85046)
Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thur
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover ap
[UPDATE] [hoch] Dell BSAFE: Schwachstelle ermöglicht Denial of Service
Ein Angreifer kann eine Schwachstelle in Dell BSAFE ausnutzen, um einen Denial of Service zu verursachen Weiterlesen
Google Patches 6th Chrome Zero-Day of 2026
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek. Weiterlesen
WordPress: Super Forms und Elementor Pro von RCE-Angriffen betroffen
LONDON (IT BOLTWISE) – Angreifer nutzen zwei kritische Lücken in WordPress-Plugins, um ohne Anmeldung Dateien mit PHP-Inhalt hochzuladen und anschließend Remote Code Execution auszuführen. Laut Wordfence wurden bereits über 250.000 bzw. 190
[UPDATE] [mittel] Red Hat Enterprise Linux (iperf3): Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
Google fixes actively exploited Chrome V8 zero-day vulnerability
Google has released a Chrome security update addressing 12 vulnerabilities, including a high-severity V8 flaw that is being actively exploited in attacks. The fixes are included in Chrome 152.0.7977.82/.83 for Windows and macOS and version