🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 105 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.868 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-17
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
7.5 HIGH
EPSS 28.6%
CVE-2022-44373 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44373 | TRENDnet Wireless AC Easy-Upgrader TEW-820AP 1.0R stack-based overflow (EUVD-2022-47318)

A vulnerability identified as critical has been detected in TRENDnet Wireless AC Easy-Upgrader TEW-820AP 1.0R. Affected by this vulnerability is an unknown functionality. The manipulation leads to stack-based buffer overflow. This vulnerabi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 32.4%
CVE-2022-44378 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44378 | Automotive Shop Management System 1.0 Master.php?f=delete_mechanic sql injection (EUVD-2022-47323)

A vulnerability was found in Automotive Shop Management System 1.0. It has been classified as critical. This affects an unknown function of the file /asms/classes/Master.php?f=delete_mechanic. This manipulation causes sql injection. This vu

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.6%
CVE-2022-44371 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44371 | hope-boot 1.0.0 deserialization (Issue 83 / EUVD-2022-47316)

A vulnerability identified as critical has been detected in hope-boot 1.0.0. This affects an unknown function. Performing a manipulation results in deserialization. This vulnerability is identified as CVE-2022-44371. The attack can be initi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.7%
CVE-2022-44369 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44369 | NASM 2.16 output/outaout.c null pointer dereference (EUVD-2022-47314)

A vulnerability was found in NASM 2.16. It has been declared as problematic. Affected by this issue is some unknown functionality of the file output/outaout.c. Executing a manipulation can lead to null pointer dereference. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.7%
CVE-2022-44368 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44368 | NASM 2.16 null pointer dereference (EUVD-2022-47313)

A vulnerability marked as problematic has been reported in NASM 2.16. This vulnerability affects unknown code. This manipulation causes null pointer dereference. This vulnerability is tracked as CVE-2022-44368. The attack is only possible w

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2022-44367 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44367 | Tenda i21 1.0.0.14 /goform/setUplinkInfo buffer overflow (EUVD-2022-47312)

A vulnerability identified as critical has been detected in Tenda i21 1.0.0.14. This issue affects some unknown processing of the file /goform/setUplinkInfo. Performing a manipulation results in buffer overflow. This vulnerability was named

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.2%
CVE-2022-44365 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44365 | Tenda i21 1.0.0.14 /goform/setSysPwd stack-based overflow (EUVD-2022-47310)

A vulnerability was found in Tenda i21 1.0.0.14. It has been rated as critical. This affects an unknown part of the file /goform/setSysPwd. This manipulation causes stack-based buffer overflow. This vulnerability is handled as CVE-2022-4436

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.1%
CVE-2022-44363 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44363 | Tenda i21 1.0.0.14 /goform/setSnmpInfo buffer overflow (EUVD-2022-47308)

A vulnerability was found in Tenda i21 1.0.0.14. It has been declared as critical. Affected by this issue is some unknown functionality of the file /goform/setSnmpInfo. The manipulation results in buffer overflow. This vulnerability is know

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.3%
CVE-2022-44362 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44362 | Tenda i21 1.0.0.14 /goform/AddSysLogRule buffer overflow (EUVD-2022-47307)

A vulnerability was found in Tenda i21 1.0.0.14. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/AddSysLogRule. The manipulation leads to buffer overflow. This vulnerability

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.7%
CVE-2022-44361 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44361 | ZZCMS 2022 admin/ad_list.php cross site scripting (EUVD-2022-47306)

A vulnerability labeled as problematic has been found in ZZCMS 2022. This impacts an unknown function of the file admin/ad_list.php. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2022-44361.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.5%
CVE-2022-44355 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44355 | SolarView Compact 7.0 /network_test.php cross site scripting (EUVD-2022-47300)

A vulnerability classified as problematic was found in SolarView Compact 7.0. Affected by this issue is some unknown functionality of the file /network_test.php. The manipulation results in cross site scripting. This vulnerability was named

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.5%
CVE-2026-91102 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91102 | HP HPLIP up to 3.26.5 privileges management (Nessus ID 346884)

A vulnerability identified as critical has been detected in HP HPLIP up to 3.26.5. This vulnerability affects unknown code. The manipulation leads to improper privilege management. This vulnerability is traded as CVE-2026-91102. It is possi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 21.7%
CVE-2026-91098 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91098 | HP HPLIP up to 3.26.5 privilege escalation (Nessus ID 346883)

A vulnerability described as critical has been identified in HP HPLIP up to 3.26.5. This vulnerability affects unknown code. The manipulation results in privilege escalation. This vulnerability was named CVE-2026-91098. The attack may be pe

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2026-91105 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91105 | HP HPLIP up to 3.26.5 privileges management (Nessus ID 346885)

A vulnerability was found in HP HPLIP up to 3.26.5. It has been classified as critical. Affected is an unknown function. This manipulation causes improper privilege management. This vulnerability is registered as CVE-2026-91105. Remote expl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.2%
CVE-2022-44351 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44351 | Zorlan Skycaiji 2.5.1 Mystore.php deserialization (Issue 46 / EUVD-2022-47296)

A vulnerability, which was classified as problematic, was found in Zorlan Skycaiji 2.5.1. This issue affects some unknown processing of the file /SkycaijiApp/admin/controller/Mystore.php. Executing a manipulation can lead to deserialization

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.7%
CVE-2022-44354 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44354 | SolarView Compact 4.0/5.0 unrestricted upload (EUVD-2022-47299)

A vulnerability was found in SolarView Compact 4.0/5.0. It has been rated as problematic. This affects an unknown part. Performing a manipulation results in unrestricted upload. This vulnerability is reported as CVE-2022-44354. The attacker

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2022-44349 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44349 | NAVBLUE S.A.S N-Ops &amp; Crew 22.5-rc.50 cross site scripting (EUVD-2022-47294)

A vulnerability has been found in NAVBLUE S.A.S N-Ops &amp;amp; Crew 22.5-rc.50 and classified as problematic. The affected element is an unknown function. Performing a manipulation results in cross site scripting. This vulnerability was na

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 29.9%
CVE-2022-44348 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44348 | Sanitization Management System 1.0 update_status.php ID sql injection (EUVD-2022-47293)

A vulnerability was found in Sanitization Management System 1.0. It has been classified as critical. Impacted is an unknown function of the file /php-sms/admin/orders/update_status.php. This manipulation of the argument ID causes sql inject

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 20.4%
CVE-2022-44347 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44347 | Sanitization Management System 1.0 view_inquiry ID sql injection (EUVD-2022-47292)

A vulnerability was found in Sanitization Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php-sms/admin/?page=inquiries/view_inquiry. The manipulation of the argument ID results in s

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.4%
CVE-2026-20707 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-20707 | Intel Xeon Scalable Processors race condition (Nessus ID 346889)

A vulnerability described as critical has been identified in Intel Xeon Scalable Processors. The affected element is an unknown function. The manipulation results in race condition. This vulnerability was named CVE-2026-20707. The attack ne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.1%
CVE-2026-20901 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-20901 | Intel Xeon Processors Firmware input validation (Nessus ID 346889)

A vulnerability categorized as problematic has been discovered in Intel Xeon Processors. Affected is an unknown function of the component Firmware. Executing a manipulation can lead to improper input validation. The identification of this v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27%
CVE-2026-91097 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-91097 | HP Linux Imaging and Printing Software up to 3.26.5 privileges management (Nessus ID 346887)

A vulnerability marked as critical has been reported in HP Linux Imaging and Printing Software up to 3.26.5. This affects an unknown part. The manipulation leads to improper privilege management. This vulnerability is uniquely identified as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.9%
CVE-2026-20760 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-20760 | Intel Processors Microcode privileges management (Nessus ID 346889)

A vulnerability categorized as very critical has been discovered in Intel Processors. The impacted element is an unknown function of the component Microcode. Executing a manipulation can lead to improper privilege management. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27%
CVE-2026-20713 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-20713 | Intel Xeon processors control flow (Nessus ID 346889)

A vulnerability classified as problematic has been found in Intel Xeon processors. The impacted element is an unknown function. This manipulation causes incorrect control flow. The identification of this vulnerability is CVE-2026-20713. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.3%
CVE-2026-20716 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-20716 | Intel Processors access control (Nessus ID 346889)

A vulnerability classified as problematic was found in Intel Processors. This affects an unknown function. Such manipulation leads to improper access controls. This vulnerability is referenced as CVE-2026-20716. The attack can only be perfo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 29%
CVE-2022-44345 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44345 | Sanitization Management System 1.0 view_quote ID sql injection (EUVD-2022-47290)

A vulnerability has been found in Sanitization Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-sms/admin/?page=quotes/view_quote. The manipulation of the argument ID leads to sql in

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.7%
CVE-2022-44343 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44343 | ZhongBangKeJi CRMEB 4.4.4 information disclosure (EUVD-2022-47288)

A vulnerability was found in ZhongBangKeJi CRMEB 4.4.4. It has been declared as problematic. The affected element is an unknown function. Such manipulation leads to information disclosure. This vulnerability is documented as CVE-2022-44343.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.9%
CVE-2022-44321 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44321 | PicoC 3.2.2 lex.c LexSkipComment heap-based overflow (Issue 37 / EUVD-2022-47266)

A vulnerability was found in PicoC 3.2.2. It has been classified as critical. Affected is the function LexSkipComment of the file lex.c. The manipulation leads to heap-based buffer overflow. This vulnerability is listed as CVE-2022-44321. T

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.5%
CVE-2022-44320 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44320 | PicoC 3.2.2 expression.c ExpressionCoerceFP heap-based overflow (Issue 37 / EUVD-2022-47265)

A vulnerability marked as critical has been reported in PicoC 3.2.2. This affects the function ExpressionCoerceFP of the file expression.c. Performing a manipulation results in heap-based buffer overflow. This vulnerability is known as CVE-

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2025-35973 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2025-35973 | Intel Processors Kernel/Hypervisor privileges management (Nessus ID 346889)

A vulnerability was found in Intel Processors. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Kernel/Hypervisor. This manipulation causes improper privilege management. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 2.3%
CVE-2026-20917 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-20917 | Intel Processors Hypervisor/Kernel information disclosure (Nessus ID 346889)

A vulnerability was found in Intel Processors. It has been classified as problematic. This affects an unknown part of the component Hypervisor/Kernel. The manipulation leads to information disclosure. This vulnerability is traded as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.1%
CVE-2025-31936 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-31936 | Intel Xeon 6 processors SMM/TDX privileges management (Nessus ID 346889 / WID-SEC-2026-2772)

A vulnerability marked as problematic has been reported in Intel Xeon 6 processors. Impacted is an unknown function of the component SMM/TDX. The manipulation leads to improper privilege management. This vulnerability is uniquely identified

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21%
CVE-2025-31938 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-31938 | Intel Xeon 6 Scalable processors TDX access control (Nessus ID 346889)

A vulnerability was found in Intel Xeon 6 Scalable processors. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component TDX. The manipulation results in improper access controls. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.6%
CVE-2026-70351 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-70351 | Microsoft WebP Image Extension prior 1.2.31.0 integer overflow (Nessus ID 346896)

A vulnerability marked as critical has been reported in Microsoft WebP Image Extension. Affected by this vulnerability is an unknown functionality. This manipulation causes integer overflow. This vulnerability appears as CVE-2026-70351. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 25%
CVE-2026-15913 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-15913 | Fortra GoAnywhere MFT up to 7.10.1 path traversal (EUVD-2026-75175 / Nessus ID 346899)

A vulnerability classified as problematic was found in Fortra GoAnywhere MFT up to 7.10.1. This affects an unknown part. The manipulation results in path traversal. This vulnerability was named CVE-2026-15913. The attack may be performed fr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.6%
CVE-2026-84386 💻 Lokal 🔓 Keine Authentifizierung nötig
Fortinet

CVE-2026-84386 | Fortinet FortiClientWindows up to 7.2.15/7.4.7 access control (Nessus ID 346901)

A vulnerability marked as problematic has been reported in Fortinet FortiClientWindows up to 7.2.15/7.4.7. This affects an unknown function. The manipulation leads to improper access controls. This vulnerability is referenced as CVE-2026-84

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2022-44319 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44319 | PicoC 3.2.2 cstdlib/string.c StdioBasePrintf heap-based overflow (Issue 37 / EUVD-2022-47264)

A vulnerability was found in PicoC 3.2.2 and classified as critical. This impacts the function StdioBasePrintf in the library cstdlib/string.c. Executing a manipulation can lead to heap-based buffer overflow. This vulnerability is tracked a

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.2%
CVE-2022-44318 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44318 | PicoC 3.2.2 cstdlib/string.c StringStrcat heap-based overflow (Issue 37 / EUVD-2022-47263)

A vulnerability has been found in PicoC 3.2.2 and classified as critical. This affects the function StringStrcat in the library cstdlib/string.c. Performing a manipulation results in heap-based buffer overflow. This vulnerability is identif

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.7%
CVE-2022-44316 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44316 | PicoC 3.2.2 lex.c LexGetStringConstant heap-based overflow (Issue 37 / EUVD-2022-47261)

A vulnerability, which was classified as critical, has been found in PicoC 3.2.2. The affected element is the function LexGetStringConstant of the file lex.c. This manipulation causes heap-based buffer overflow. The identification of this v

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.9%
CVE-2022-44317 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44317 | PicoC 3.2.2 cstdlib/stdio.c StdioOutPutc heap-based overflow (Issue 37 / EUVD-2022-47262)

A vulnerability, which was classified as critical, was found in PicoC 3.2.2. The impacted element is the function StdioOutPutc in the library cstdlib/stdio.c. Such manipulation leads to heap-based buffer overflow. This vulnerability is refe

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.4%
CVE-2026-89813 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89813 | Linux Kernel up to 7.2.4 KIQ ring drm/amdgpu amdgpu_device_pre_asic_reset race condition (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 7.2.4 and classified as critical. Affected by this issue is the function amdgpu_device_pre_asic_reset of the file drm/amdgpu of the component KIQ ring. Such manipulation leads to race conditio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 29.2%
CVE-2026-89812 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89812 | Linux Kernel MES ring amdgpu_device_pre_asic_reset infinite loop (WID-SEC-2026-3438)

A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function amdgpu_device_pre_asic_reset of the component MES ring. This manipulation causes infinite loop. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 27.8%
CVE-2026-89811 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89811 | Linux Kernel up to 6.18.50/7.2.4/7.3-rc1 amdkfd/MES Queue Management amdkfd evict_process_queues_cpsch/suspend_queues race condition (WID-SEC-2026-3438)

A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.18.50/7.2.4/7.3-rc1. This impacts the function evict_process_queues_cpsch/suspend_queues of the file drivers/gpu/drm/amd/amdkfd of the component

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.8%
CVE-2026-89810 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89810 | Linux Kernel up to 6.18.50/7.2.4 amdkfd drm/amdkfd svm_migrate_copy_to_ram allocation of resources (WID-SEC-2026-3438)

A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.18.50/7.2.4. Impacted is the function svm_migrate_copy_to_ram of the file drm/amdkfd of the component amdkfd. The manipulation results in allocation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.7%
CVE-2026-89808 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89808 | Linux Kernel up to 6.18.50/7.2.4 amdkfd svm_migrate_copy_memory_gart uninitialized variable (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4. It has been rated as very critical. This issue affects the function svm_migrate_copy_memory_gart of the file drivers/gpu/drm/amd/amdkfd of the component amdkfd. The manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.5%
CVE-2026-89809 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89809 | Linux Kernel up to 7.2.4/7.3-rc1 amdkfd mqds pqm_debugfs_mqds pqn null pointer dereference (WID-SEC-2026-3438)

A vulnerability, which was classified as problematic, was found in Linux Kernel up to 7.2.4/7.3-rc1. Affected is the function pqm_debugfs_mqds of the file /sys/kernel/debug/kfd/mqds of the component amdkfd. The manipulation of the argument

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 29.2%
CVE-2026-89807 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89807 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 amdkfd amdkfd.c create_queue_cpsch/create_queue_nocpsch null pointer dereference (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 6.12.109/6.18.50/7.2.4. It has been declared as problematic. This vulnerability affects the function create_queue_cpsch/create_queue_nocpsch of the file drivers/gpu/drm/amd/amdkfd/amdkfd.c of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.8%
CVE-2026-89806 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89806 | Linux Kernel up to 6.18.50/7.2.4/7.3-rc1 Sysfb drm/sysfb integer overflow (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4/7.3-rc1. It has been classified as very critical. This affects an unknown part of the file drm/sysfb of the component Sysfb. Performing a manipulation results in integer overflow

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.9%
CVE-2022-44315 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44315 | PicoC 3.2.2 expression.c ExpressionAssign heap-based overflow (Issue 37 / EUVD-2022-47260)

A vulnerability classified as critical was found in PicoC 3.2.2. Impacted is the function ExpressionAssign of the file expression.c. The manipulation results in heap-based buffer overflow. This vulnerability was named CVE-2022-44315. The at

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.1%
CVE-2022-44314 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44314 | PicoC 3.2.2 cstdlib/string.c StringStrncpy heap-based overflow (Issue 37 / EUVD-2022-47259)

A vulnerability classified as critical has been found in PicoC 3.2.2. This issue affects the function StringStrncpy in the library cstdlib/string.c. The manipulation leads to heap-based buffer overflow. This vulnerability is uniquely identi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.2%
CVE-2022-44313 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44313 | PicoC 3.2.2 expression.c ExpressionCoerceUnsignedInteger heap-based overflow (Issue 37 / EUVD-2022-47258)

A vulnerability labeled as critical has been found in PicoC 3.2.2. Affected by this issue is the function ExpressionCoerceUnsignedInteger of the file expression.c. Such manipulation leads to heap-based buffer overflow. This vulnerability is

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.6%
CVE-2022-44312 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44312 | PicoC 3.2.2 expression.c ExpressionCoerceInteger heap-based overflow (Issue 37 / EUVD-2022-47257)

A vulnerability identified as critical has been detected in PicoC 3.2.2. Affected by this vulnerability is the function ExpressionCoerceInteger of the file expression.c. This manipulation causes heap-based buffer overflow. This vulnerabilit

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26%
CVE-2022-44311 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44311 | html2xhtml 1.3 HTML File procesador.c elm_close out-of-bounds (Issue 19 / EUVD-2022-47256)

A vulnerability categorized as problematic has been discovered in html2xhtml 1.3. Affected is the function elm_close of the file procesador.c of the component HTML File Handler. The manipulation results in out-of-bounds read. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.7%
CVE-2022-44299 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44299 | SiteServerCMS 7.1.3 information disclosure (Issue 3491 / EUVD-2022-47246)

A vulnerability was found in SiteServerCMS 7.1.3 and classified as problematic. This affects an unknown part. Executing a manipulation can lead to information disclosure. The identification of this vulnerability is CVE-2022-44299. The attac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 20.3%
CVE-2022-44298 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44298 | SiteServer CMS 7.1.3 sql injection (Issue 3492 / EUVD-2022-47245)

A vulnerability labeled as critical has been found in SiteServer CMS 7.1.3. Impacted is an unknown function. The manipulation results in sql injection. This vulnerability is reported as CVE-2022-44298. The attacker must have access to the l

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 29%
CVE-2022-44297 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44297 | SiteServer CMS 7.1.3 sql injection (Issue 3490 / EUVD-2022-47244)

A vulnerability was found in SiteServer CMS 7.1.3. It has been classified as critical. The impacted element is an unknown function. Performing a manipulation results in sql injection. This vulnerability is reported as CVE-2022-44297. The at

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 24.2%
CVE-2022-44296 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44296 | oretnom23 Sanitization Management System 1.0 manage_remark.php ID sql injection (EUVD-2022-47243)

A vulnerability classified as critical has been found in oretnom23 Sanitization Management System 1.0. The affected element is an unknown function of the file /php-sms/admin/quotes/manage_remark.php. Performing a manipulation of the argumen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 23.4%
CVE-2022-44295 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44295 | oretnom23 Sanitization Management System 1.0 assign_team.php ID sql injection (EUVD-2022-47242)

A vulnerability described as critical has been identified in oretnom23 Sanitization Management System 1.0. Impacted is an unknown function of the file /php-sms/admin/orders/assign_team.php. Such manipulation of the argument ID leads to sql

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.4%
CVE-2026-34078 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

How to Protect Your Linux System from Flatpak Security Issues (2026)

Flatpak 1.18.1 patched 10 security vulnerabilities including a critical sandbox escape (CVE-2026-34078). This guide walks you through checking your Flatpak version, updating on Ubuntu, Fedora, and Arch Linux, auditing app permissions with F

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 5.7%
CVE-2026-93386 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-93386 | Google Chrome up to 153.0.8010.47 WebAppInstalls information disclosure (EUVD-2026-82490)

A vulnerability was found in Google Chrome. It has been rated as problematic. This impacts an unknown function of the component WebAppInstalls. The manipulation leads to information disclosure. This vulnerability is documented as CVE-2026-9

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.