Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-17 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2022-44345 | Sanitization Management System 1.0 view_quote ID sql injection (EUVD-2022-47290)
A vulnerability has been found in Sanitization Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-sms/admin/?page=quotes/view_quote. The manipulation of the argument ID leads to sql in
CVE-2022-44343 | ZhongBangKeJi CRMEB 4.4.4 information disclosure (EUVD-2022-47288)
A vulnerability was found in ZhongBangKeJi CRMEB 4.4.4. It has been declared as problematic. The affected element is an unknown function. Such manipulation leads to information disclosure. This vulnerability is documented as CVE-2022-44343.
CVE-2022-44321 | PicoC 3.2.2 lex.c LexSkipComment heap-based overflow (Issue 37 / EUVD-2022-47266)
A vulnerability was found in PicoC 3.2.2. It has been classified as critical. Affected is the function LexSkipComment of the file lex.c. The manipulation leads to heap-based buffer overflow. This vulnerability is listed as CVE-2022-44321. T
CVE-2022-44320 | PicoC 3.2.2 expression.c ExpressionCoerceFP heap-based overflow (Issue 37 / EUVD-2022-47265)
A vulnerability marked as critical has been reported in PicoC 3.2.2. This affects the function ExpressionCoerceFP of the file expression.c. Performing a manipulation results in heap-based buffer overflow. This vulnerability is known as CVE-
CVE-2025-35973 | Intel Processors Kernel/Hypervisor privileges management (Nessus ID 346889)
A vulnerability was found in Intel Processors. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Kernel/Hypervisor. This manipulation causes improper privilege management. This vulnerabi
CVE-2026-20917 | Intel Processors Hypervisor/Kernel information disclosure (Nessus ID 346889)
A vulnerability was found in Intel Processors. It has been classified as problematic. This affects an unknown part of the component Hypervisor/Kernel. The manipulation leads to information disclosure. This vulnerability is traded as CVE-202
CVE-2025-31936 | Intel Xeon 6 processors SMM/TDX privileges management (Nessus ID 346889 / WID-SEC-2026-2772)
A vulnerability marked as problematic has been reported in Intel Xeon 6 processors. Impacted is an unknown function of the component SMM/TDX. The manipulation leads to improper privilege management. This vulnerability is uniquely identified
CVE-2025-31938 | Intel Xeon 6 Scalable processors TDX access control (Nessus ID 346889)
A vulnerability was found in Intel Xeon 6 Scalable processors. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component TDX. The manipulation results in improper access controls. This
CVE-2026-70351 | Microsoft WebP Image Extension prior 1.2.31.0 integer overflow (Nessus ID 346896)
A vulnerability marked as critical has been reported in Microsoft WebP Image Extension. Affected by this vulnerability is an unknown functionality. This manipulation causes integer overflow. This vulnerability appears as CVE-2026-70351. The
CVE-2026-15913 | Fortra GoAnywhere MFT up to 7.10.1 path traversal (EUVD-2026-75175 / Nessus ID 346899)
A vulnerability classified as problematic was found in Fortra GoAnywhere MFT up to 7.10.1. This affects an unknown part. The manipulation results in path traversal. This vulnerability was named CVE-2026-15913. The attack may be performed fr
CVE-2026-84386 | Fortinet FortiClientWindows up to 7.2.15/7.4.7 access control (Nessus ID 346901)
A vulnerability marked as problematic has been reported in Fortinet FortiClientWindows up to 7.2.15/7.4.7. This affects an unknown function. The manipulation leads to improper access controls. This vulnerability is referenced as CVE-2026-84
CVE-2022-44319 | PicoC 3.2.2 cstdlib/string.c StdioBasePrintf heap-based overflow (Issue 37 / EUVD-2022-47264)
A vulnerability was found in PicoC 3.2.2 and classified as critical. This impacts the function StdioBasePrintf in the library cstdlib/string.c. Executing a manipulation can lead to heap-based buffer overflow. This vulnerability is tracked a
CVE-2022-44318 | PicoC 3.2.2 cstdlib/string.c StringStrcat heap-based overflow (Issue 37 / EUVD-2022-47263)
A vulnerability has been found in PicoC 3.2.2 and classified as critical. This affects the function StringStrcat in the library cstdlib/string.c. Performing a manipulation results in heap-based buffer overflow. This vulnerability is identif
CVE-2022-44316 | PicoC 3.2.2 lex.c LexGetStringConstant heap-based overflow (Issue 37 / EUVD-2022-47261)
A vulnerability, which was classified as critical, has been found in PicoC 3.2.2. The affected element is the function LexGetStringConstant of the file lex.c. This manipulation causes heap-based buffer overflow. The identification of this v
CVE-2022-44317 | PicoC 3.2.2 cstdlib/stdio.c StdioOutPutc heap-based overflow (Issue 37 / EUVD-2022-47262)
A vulnerability, which was classified as critical, was found in PicoC 3.2.2. The impacted element is the function StdioOutPutc in the library cstdlib/stdio.c. Such manipulation leads to heap-based buffer overflow. This vulnerability is refe
CVE-2026-89813 | Linux Kernel up to 7.2.4 KIQ ring drm/amdgpu amdgpu_device_pre_asic_reset race condition (WID-SEC-2026-3438)
A vulnerability was found in Linux Kernel up to 7.2.4 and classified as critical. Affected by this issue is the function amdgpu_device_pre_asic_reset of the file drm/amdgpu of the component KIQ ring. Such manipulation leads to race conditio
CVE-2026-89812 | Linux Kernel MES ring amdgpu_device_pre_asic_reset infinite loop (WID-SEC-2026-3438)
A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function amdgpu_device_pre_asic_reset of the component MES ring. This manipulation causes infinite loop. This vulnerability is
CVE-2026-89811 | Linux Kernel up to 6.18.50/7.2.4/7.3-rc1 amdkfd/MES Queue Management amdkfd evict_process_queues_cpsch/suspend_queues race condition (WID-SEC-2026-3438)
A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.18.50/7.2.4/7.3-rc1. This impacts the function evict_process_queues_cpsch/suspend_queues of the file drivers/gpu/drm/amd/amdkfd of the component
CVE-2026-89810 | Linux Kernel up to 6.18.50/7.2.4 amdkfd drm/amdkfd svm_migrate_copy_to_ram allocation of resources (WID-SEC-2026-3438)
A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.18.50/7.2.4. Impacted is the function svm_migrate_copy_to_ram of the file drm/amdkfd of the component amdkfd. The manipulation results in allocation of
CVE-2026-89808 | Linux Kernel up to 6.18.50/7.2.4 amdkfd svm_migrate_copy_memory_gart uninitialized variable (WID-SEC-2026-3438)
A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4. It has been rated as very critical. This issue affects the function svm_migrate_copy_memory_gart of the file drivers/gpu/drm/amd/amdkfd of the component amdkfd. The manipulation
CVE-2026-89809 | Linux Kernel up to 7.2.4/7.3-rc1 amdkfd mqds pqm_debugfs_mqds pqn null pointer dereference (WID-SEC-2026-3438)
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 7.2.4/7.3-rc1. Affected is the function pqm_debugfs_mqds of the file /sys/kernel/debug/kfd/mqds of the component amdkfd. The manipulation of the argument
CVE-2026-89807 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 amdkfd amdkfd.c create_queue_cpsch/create_queue_nocpsch null pointer dereference (WID-SEC-2026-3438)
A vulnerability was found in Linux Kernel up to 6.12.109/6.18.50/7.2.4. It has been declared as problematic. This vulnerability affects the function create_queue_cpsch/create_queue_nocpsch of the file drivers/gpu/drm/amd/amdkfd/amdkfd.c of
CVE-2026-89806 | Linux Kernel up to 6.18.50/7.2.4/7.3-rc1 Sysfb drm/sysfb integer overflow (WID-SEC-2026-3438)
A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4/7.3-rc1. It has been classified as very critical. This affects an unknown part of the file drm/sysfb of the component Sysfb. Performing a manipulation results in integer overflow
CVE-2022-44315 | PicoC 3.2.2 expression.c ExpressionAssign heap-based overflow (Issue 37 / EUVD-2022-47260)
A vulnerability classified as critical was found in PicoC 3.2.2. Impacted is the function ExpressionAssign of the file expression.c. The manipulation results in heap-based buffer overflow. This vulnerability was named CVE-2022-44315. The at
CVE-2022-44314 | PicoC 3.2.2 cstdlib/string.c StringStrncpy heap-based overflow (Issue 37 / EUVD-2022-47259)
A vulnerability classified as critical has been found in PicoC 3.2.2. This issue affects the function StringStrncpy in the library cstdlib/string.c. The manipulation leads to heap-based buffer overflow. This vulnerability is uniquely identi
CVE-2022-44313 | PicoC 3.2.2 expression.c ExpressionCoerceUnsignedInteger heap-based overflow (Issue 37 / EUVD-2022-47258)
A vulnerability labeled as critical has been found in PicoC 3.2.2. Affected by this issue is the function ExpressionCoerceUnsignedInteger of the file expression.c. Such manipulation leads to heap-based buffer overflow. This vulnerability is
CVE-2022-44312 | PicoC 3.2.2 expression.c ExpressionCoerceInteger heap-based overflow (Issue 37 / EUVD-2022-47257)
A vulnerability identified as critical has been detected in PicoC 3.2.2. Affected by this vulnerability is the function ExpressionCoerceInteger of the file expression.c. This manipulation causes heap-based buffer overflow. This vulnerabilit
CVE-2022-44311 | html2xhtml 1.3 HTML File procesador.c elm_close out-of-bounds (Issue 19 / EUVD-2022-47256)
A vulnerability categorized as problematic has been discovered in html2xhtml 1.3. Affected is the function elm_close of the file procesador.c of the component HTML File Handler. The manipulation results in out-of-bounds read. This vulnerabi
CVE-2022-44299 | SiteServerCMS 7.1.3 information disclosure (Issue 3491 / EUVD-2022-47246)
A vulnerability was found in SiteServerCMS 7.1.3 and classified as problematic. This affects an unknown part. Executing a manipulation can lead to information disclosure. The identification of this vulnerability is CVE-2022-44299. The attac
CVE-2022-44298 | SiteServer CMS 7.1.3 sql injection (Issue 3492 / EUVD-2022-47245)
A vulnerability labeled as critical has been found in SiteServer CMS 7.1.3. Impacted is an unknown function. The manipulation results in sql injection. This vulnerability is reported as CVE-2022-44298. The attacker must have access to the l
CVE-2022-44297 | SiteServer CMS 7.1.3 sql injection (Issue 3490 / EUVD-2022-47244)
A vulnerability was found in SiteServer CMS 7.1.3. It has been classified as critical. The impacted element is an unknown function. Performing a manipulation results in sql injection. This vulnerability is reported as CVE-2022-44297. The at
CVE-2022-44296 | oretnom23 Sanitization Management System 1.0 manage_remark.php ID sql injection (EUVD-2022-47243)
A vulnerability classified as critical has been found in oretnom23 Sanitization Management System 1.0. The affected element is an unknown function of the file /php-sms/admin/quotes/manage_remark.php. Performing a manipulation of the argumen
CVE-2022-44295 | oretnom23 Sanitization Management System 1.0 assign_team.php ID sql injection (EUVD-2022-47242)
A vulnerability described as critical has been identified in oretnom23 Sanitization Management System 1.0. Impacted is an unknown function of the file /php-sms/admin/orders/assign_team.php. Such manipulation of the argument ID leads to sql
How to Protect Your Linux System from Flatpak Security Issues (2026)
Flatpak 1.18.1 patched 10 security vulnerabilities including a critical sandbox escape (CVE-2026-34078). This guide walks you through checking your Flatpak version, updating on Ubuntu, Fedora, and Arch Linux, auditing app permissions with F
CVE-2026-93386 | Google Chrome up to 153.0.8010.47 WebAppInstalls information disclosure (EUVD-2026-82490)
A vulnerability was found in Google Chrome. It has been rated as problematic. This impacts an unknown function of the component WebAppInstalls. The manipulation leads to information disclosure. This vulnerability is documented as CVE-2026-9
CVE-2026-93426 | SigNoz up to 0.141.x Query Range API sql injection (EUVD-2026-82493)
A vulnerability was found in SigNoz up to 0.141.x and classified as critical. This issue affects some unknown processing of the component Query Range API. Such manipulation leads to sql injection. This vulnerability is referenced as CVE-202
CVE-2026-73638 | Imager up to 1.034 tiff_load_ifd out-of-bounds (EUVD-2026-82491)
A vulnerability, which was classified as problematic, was found in Imager up to 1.034. This affects the function tiff_load_ifd. The manipulation results in out-of-bounds read. This vulnerability was named CVE-2026-73638. The attack may be p
CVE-2026-73639 | Imager 1.003 PNG read_direct8 buffer overflow (EUVD-2026-82492)
A vulnerability, which was classified as problematic, has been found in Imager 1.003. Affected by this issue is the function read_direct8 of the component PNG. The manipulation leads to buffer overflow. This vulnerability is uniquely identi
CVE-2026-16750 | Stylemix Motors Plugin up to 1.4.120 on WordPress mvl_ajax_dealer_load_cars improper authorization (EUVD-2026-82494)
A vulnerability classified as problematic was found in Stylemix Motors Plugin up to 1.4.120 on WordPress. This impacts the function mvl_ajax_dealer_load_cars. Executing a manipulation can lead to improper authorization. This vulnerability a
CVE-2026-16582 | melograno Booking for Appointments and Events Calendar Plugin improper authorization (EUVD-2026-82495)
A vulnerability described as problematic has been identified in melograno Booking for Appointments and Events Calendar Plugin up to 2.4.5 on WordPress. The impacted element is an unknown function. Such manipulation of the argument package-r
CVE-2026-14311 | melograno Booking for Appointments and Events Calendar Plugin /users/customers/ improper authorization (EUVD-2026-82496)
A vulnerability classified as critical has been found in melograno Booking for Appointments and Events Calendar Plugin up to 2.4.4 on WordPress. This affects an unknown function of the file /users/customers/. Performing a manipulation resul
CVE-2023-4751 | vim up to 9.0.1247 heap-based overflow
A vulnerability was found in vim and classified as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to heap-based buffer overflow. This vulnerability is registered as CVE-2023-4751. The attac
CVE-2021-20327 | mongodb-client-encryption 1.2.0 on Node.js certificate validation
A vulnerability was found in mongodb-client-encryption 1.2.0 on Node.js and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to improper certificate validation. This vulnerability is reg
CVE-2017-7200 | OpenStack Glance Image Service API v1 Portscan server-side request forgery (BID-96988)
A vulnerability classified as problematic has been found in OpenStack Glance. The affected element is an unknown function of the component Image Service API v1. This manipulation causes server-side request forgery (Portscan). This vulnerabi
CVE-2012-5825 | Horde Kronolith 3.0.17 Portal Blocks input validation (ID 349780 / XFDB-80084)
A vulnerability described as problematic has been identified in Horde Kronolith 3.0.17. This issue affects some unknown processing of the component Portal Blocks. Such manipulation leads to improper input validation. This vulnerability is d
CVE-2012-5825 | Horde Groupware/Groupware Webmail Edition 4.0.8 Portal Blocks input validation (ID 349780 / XFDB-80084)
A vulnerability marked as problematic has been reported in Horde Groupware and Groupware Webmail Edition 4.0.8. This vulnerability affects unknown code of the component Portal Blocks. This manipulation causes improper input validation. This
CVE-2023-5535 | vim up to 9.0.1969 use after free
A vulnerability described as critical has been identified in vim. This affects an unknown part. Executing a manipulation can lead to use after free. This vulnerability is tracked as CVE-2023-5535. The attack can be launched remotely. No exp
USN-8779-2: Bubblewrap regression
USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for CVE-2026-87766 introduced a regression in symlink resolution, preventing certain Flatpak applications from launching. This update reverts that fix until a complete f
Finding the Agent Infrastructure: What Internet Measurement Can and Cannot Say About AI Coding Tool Exposure
Finding the Agent Infrastructure: What Internet Measurement Can and Cannot Say About AI Coding Tool Exposure In September 2026, researchers disclosed a class of configuration injection flaws affecting several AI coding agents, including Cla
Cisco patches max-severity ISE flaw, the second critical zero-day this week
Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network control and policy enforcement. This is the second zero-day flaw
Cisco alerts customers to second actively exploited zero-day in as many days
Cisco disclosed its second actively exploited zero-day vulnerability in as many days, presenting its customers with back-to-back threats to address in unrelated products. The latest zero-day — CVE-2026-76460 — has a maximum-severity rating
Check Point: Authentifizierungs-Bypass ermöglicht Root-Codeausführung per CVE-2026-91843
LONDON (IT BOLTWISE) – Eine kritische Schwachstelle in den Security Management und Log Servern von Check Point (CVE-2026-91843) kann es Angreifern ohne Login ermöglichen, Root-Code über das Netzwerk auszuführen. Check Point hat dafür einen
<b>Windows</b> Defender: Falsche Warnung täuscht Sicherheitslücke vor - ad-hoc-news.de
Eine fehlerhafte Defender-Meldung betrifft Windows- und Server-Systeme. Microsoft bestätigt den Anzeigefehler und stellt eine Korrektur in ... Weiterlesen
Hunting the Cisco ISE Authentication Bypass: Detection and Response for CVE-2026-76423
Hunting the Cisco ISE Authentication Bypass: Detection and Response for CVE-2026-76423 Vulnerability overview CVE-2026-76423 is an authentication bypass in the Cisco Identity Services Engine REST API, disclosed on 16 September 2026 with a C
USN-8780-1: libsoup vulnerabilities
It was discovered that libsoup incorrectly handled certain URLs when using an HTTP proxy. A remote attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-1467) It was discovered that libsoup did not remove proxy
USN-8779-1: Bubblewrap vulnerabilities
It was discovered that Bubblewrap incorrectly handled certain temporary directories. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2019
CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes — e.g. flip `is_admin
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restor
CVE-2026-61592 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the vict
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user
CVE-2026-61597 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which n
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-s
CVE-2026-92599 | joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the input is unanchored, so a valid ISO date followed by a long run of fractional-second digits causes the regex engine to restart its search from every position in the string, yielding time proportional to the square of the in
joi (npm package `joi`, hapi.js) versions >=17.2.0 =18.0.0