🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

372k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
1 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-10: 295 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 682 2026-06: 941 2026-07: 1327 2026-08: 1827 2026-09: 1509 2026-10: 70 9.405 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-192026-10-03
≥90 %538364
≥50 %16031115
≥10 %173
<10 %56400485
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 98.233 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
– OHNE BEWERTUNG
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Google schließt weitere kritische Sicherheitslücke in Chrome

In den neuen Chrome-Versionen 154.0.8037.97/98 für Windows und macOS sowie 154.0.8037.97 für Linux haben die Entwickler 11 teils kritische Sicherheitslücken behoben. Laut Google wird bislang keine der gestopften Lücken für Angriffe ausgenut

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Google schließt weitere kritische Sicherheitslücke in Chrome

In den neuen Chrome-Versionen 154.0.8037.97/98 für Windows und macOS sowie 154.0.8037.97 für Linux haben die Entwickler 11 teils kritische Sicherheitslücken behoben. Laut Google wird bislang keine der gestopften Lücken für Angriffe ausgenut

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-62598 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-62598 | LabRedesCefetRJ WeGIA up to 3.5.0 editar_info_pessoal.php action cross site scripting (GHSA-jmm7-rr7w-f223)

A vulnerability described as problematic has been identified in LabRedesCefetRJ WeGIA up to 3.5.0. This affects an unknown function of the file editar_info_pessoal.php. Executing a manipulation of the argument action can lead to cross site

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-53034 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-53034 | Oracle Financial Services Analytical Applications Infrastructure Oracle Financial Service missing authentication (EUVD-2025-35298)

A vulnerability was found in Oracle Financial Services Analytical Applications Infrastructure 8.0.7.9/8.0.8.7/8.1.2.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Oracle Financial S

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-50075 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-50075 | Oracle Financial Services Revenue Management and Billing up to 7.2.0.0.0 Oracle Financial Service improper authorization

A vulnerability, which was classified as critical, has been found in Oracle Financial Services Revenue Management and Billing up to 7.2.0.0.0. Impacted is an unknown function of the component Oracle Financial Service. Performing a manipulat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 1%
CVE-2025-34255 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-34255 | D-Link Nuclias Connect up to 1.3.1.4 Forgot Password data.exist response discrepancy (EUVD-2025-34832)

A vulnerability marked as problematic has been reported in D-Link Nuclias Connect up to 1.3.1.4. Affected by this issue is some unknown functionality of the component Forgot Password Handler. Performing a manipulation of the argument data.e

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-31342 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-31342 | Galaxy Software Services Vitals ESP up to 1.3 unrestricted upload (EUVD-2025-35042 / CNNVD-202510-2634)

A vulnerability has been found in Galaxy Software Services Vitals ESP up to 1.3 and classified as critical. Affected is an unknown function. Performing a manipulation results in unrestricted upload. This vulnerability is identified as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-11680 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11680 | warmcat libwebsockets up to 4.3.6/4.4.2 PNG File Parser unfilter_scanline width out-of-bounds write (EUVD-2025-35055 / Nessus ID 271663)

A vulnerability was found in warmcat libwebsockets up to 4.3.6/4.4.2. It has been classified as critical. This issue affects the function unfilter_scanline of the component PNG File Parser. This manipulation of the argument width causes out

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-56589 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-56589 | HCL BigFix Service Management cross site scripting (WID-SEC-2026-3707)

A vulnerability identified as problematic has been detected in HCL BigFix Service Management. This vulnerability affects unknown code. Performing a manipulation results in cross site scripting. This vulnerability is identified as CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-31980 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-31980 | HCL BigFix Service Management input validation (WID-SEC-2026-3707)

A vulnerability was found in HCL BigFix Service Management. It has been declared as problematic. The affected element is an unknown function. Executing a manipulation can lead to improper input validation. This vulnerability is handled as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-79625 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-79625 | CODESYS Control RTE Monitoring race condition (WID-SEC-2026-3710)

A vulnerability classified as problematic has been found in CODESYS Control RTE, Control RTE SL, Control Win, Control for BeagleBone SL, Control for emPC-A, Control for IOT2000 SL, Control for Linux ARM SL, Control for Linux SL, Control for

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
– OHNE BEWERTUNG
EPSS
CVE-2026-76992 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-76992 | CODESYS Development System 3 Gateway size denial of service (WID-SEC-2026-3710)

A vulnerability was found in CODESYS Development System 3, Gateway, Edge Gateway for Windows, HMIOPC DA Server SL, PLCHandler, Runtime Toolkit and Edge Gateway for Linux. It has been declared as critical. This impacts an unknown function of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-12544 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-12544 | Foreman Configuration special elements in template engine (WID-SEC-2026-3712)

A vulnerability was found in Foreman and classified as very critical. This vulnerability affects unknown code of the component Configuration. The manipulation results in improper neutralization of special elements used in a template engine.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2026-12542 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-12542 | Foreman foreman-tail command injection (WID-SEC-2026-3712)

A vulnerability marked as very critical has been reported in Foreman. The impacted element is an unknown function of the component foreman-tail. The manipulation leads to command injection. This vulnerability is documented as CVE-2026-12542

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 1.3%
CVE-2026-12541 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-12541 | Foreman command injection (WID-SEC-2026-3712)

A vulnerability described as problematic has been identified in Foreman. This affects an unknown function. The manipulation results in command injection. This vulnerability is reported as CVE-2026-12541. The attack can be launched remotely.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 1.3%
CVE-2026-12540 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-12540 | Foreman errors:fetch_log request_id command injection (WID-SEC-2026-3712)

A vulnerability identified as critical has been detected in Foreman. Impacted is an unknown function of the component errors:fetch_log. Performing a manipulation of the argument request_id results in command injection. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-96659 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-96659 | Red Hat Satellite Template Preview Endpoint information disclosure (WID-SEC-2026-3712)

A vulnerability has been found in Red Hat Satellite and classified as problematic. The affected element is an unknown function of the component Template Preview Endpoint. Performing a manipulation results in information disclosure. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-12423 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-12423 | Foreman Provisioning information disclosure (WID-SEC-2026-3712)

A vulnerability categorized as problematic has been discovered in Foreman. This issue affects some unknown processing of the component Provisioning. Such manipulation leads to information disclosure. This vulnerability is listed as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.7%
CVE-2026-96658 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-96658 | Red Hat Satellite Templating Engine privileges management (WID-SEC-2026-3712)

A vulnerability, which was classified as very critical, was found in Red Hat Satellite. Impacted is an unknown function of the component Templating Engine. Such manipulation leads to improper privilege management. This vulnerability is docu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2022-4318 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-4318 | cri-o 1.9 /etc/passwd privilege escalation (Nessus ID 342241 / WID-SEC-2023-0600)

A vulnerability, which was classified as problematic, has been found in cri-o 1.9. The impacted element is an unknown function of the file /etc/passwd. This manipulation causes privilege escalation. This vulnerability is registered as CVE-2

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2026-19672 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19672 | Python tarfile up to 3.15.x path traversal (EUVD-2026-62536 / WID-SEC-2026-3016)

A vulnerability was found in Python tarfile up to 3.15.x and classified as problematic. The impacted element is an unknown function. The manipulation results in path traversal. This vulnerability is known as CVE-2026-19672. Attacking locall

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Citrix NetScaler Appliances Reboot Repeatedly After 0-Day Security Update

Citrix NetScaler administrators report repeated appliance crashes and forced reboots after deploying emergency updates for recently disclosed zero-day vulnerabilities, with the disruption now linked to a newly observed issue affecting SAML

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-62583 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-62583 | NAVER Whale Browser up to 4.32.315.22 iFrame Sandbox security check

A vulnerability, which was classified as problematic, was found in NAVER Whale Browser up to 4.32.315.22. The impacted element is an unknown function of the component iFrame Sandbox Handler. The manipulation results in security check for st

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-62371 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-62371 | opensearch-project data-prepper up to 2.12.1 certificate validation

A vulnerability was found in opensearch-project data-prepper up to 2.12.1. It has been classified as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in improper certificate validation. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-58426 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-58426 | NEOJAPAN desknets NEO up to 9.0R2.0 hard-coded key

A vulnerability, which was classified as problematic, has been found in NEOJAPAN desknets NEO up to 9.0R2.0. Affected by this issue is some unknown functionality. Performing a manipulation results in use of hard-coded cryptographic key . Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-34253 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-34253 | D-Link Nuclias Connect up to 1.3.1.4 Network cross site scripting (EUVD-2025-34830)

A vulnerability identified as problematic has been detected in D-Link Nuclias Connect up to 1.3.1.4. Impacted is an unknown function. The manipulation of the argument Network leads to cross site scripting. This vulnerability is listed as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.6%
CVE-2025-62672 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-62672 | boyns rplay up to 3.3.2 librplay/rplay.c RPLAY_DATA allocation of resources (EUVD-2025-35001 / Nessus ID 271680)

A vulnerability categorized as problematic has been discovered in boyns rplay up to 3.3.2. Affected by this issue is the function RPLAY_DATA of the file librplay/rplay.c. The manipulation results in allocation of resources. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-59557 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-59557 | ThemeMove Learts Addons Plugin up to 1.7.5 on WordPress sql injection

A vulnerability classified as critical has been found in ThemeMove Learts Addons Plugin up to 1.7.5 on WordPress. Affected by this vulnerability is an unknown functionality. This manipulation causes sql injection. This vulnerability is hand

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-59006 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-59006 | themebon Easy Woocommerce Customizer Plugin up to 1.0.2 on WordPress cross site scripting

A vulnerability has been found in themebon Easy Woocommerce Customizer Plugin up to 1.0.2 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.6%
CVE-2025-53067 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-53067 | Oracle MySQL Server up to 9.4.0 Optimizer denial of service (Nessus ID 276863 / WID-SEC-2025-2363)

A vulnerability classified as problematic has been found in Oracle MySQL Server up to 9.4.0. The affected element is an unknown function of the component Optimizer. Performing a manipulation results in denial of service. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-49940 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-49940 | ThemeFusion Fusion Builder Plugin up to 3.13.2 on WordPress cross site scripting

A vulnerability, which was classified as problematic, was found in ThemeFusion Fusion Builder Plugin up to 3.13.2 on WordPress. This issue affects some unknown processing. The manipulation results in cross site scripting. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 19.1%
CVE-2024-58274 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-58274 | Hikvision CSMP iSecure Center up to 2024-08-01 detection os command injection (EUVD-2024-55040 / CNNVD-202510-3181)

A vulnerability categorized as critical has been discovered in Hikvision CSMP iSecure Center up to 2024-08-01. This vulnerability affects unknown code of the file /center/api/installation/detection. Such manipulation leads to os command inj

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2024-42192 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2024-42192 | HCL Traveler for Microsoft Outlook 3.0.14 insufficiently protected credentials (KB0124066)

A vulnerability classified as problematic has been found in HCL Traveler for Microsoft Outlook 3.0.14. This impacts an unknown function. Performing a manipulation results in insufficiently protected credentials. This vulnerability is report

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2024-31573 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-31573 | xmlunit-core prior 2.10.0 XSLT Stylesheet Parser resource transfer (EUVD-2024-1578 / Nessus ID 271645)

A vulnerability categorized as problematic has been discovered in xmlunit-core. This impacts an unknown function of the component XSLT Stylesheet Parser. The manipulation results in incorrect resource transfer. This vulnerability was named

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-59497 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2025-59497 | Microsoft Defender for Endpoint on Linux toctou (EUVD-2025-34266)

A vulnerability classified as critical was found in Microsoft Defender for Endpoint on Linux. Affected by this vulnerability is an unknown functionality. The manipulation results in time-of-check time-of-use. This vulnerability is reported

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-42939 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-42939 | SAP S4HANA 4CORE 104 up to 108 Manage Processing Rules authorization (EUVD-2025-34118 / CNNVD-202510-2076)

A vulnerability marked as critical has been reported in SAP S4HANA 4CORE 104 up to 108. Impacted is an unknown function of the component Manage Processing Rules. The manipulation leads to incorrect authorization. This vulnerability is uniqu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-40755 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-40755 | Siemens SINEC NMS up to 4.0 Endpoint getTotalAndFilterCounts sql injection (ssa-318832)

A vulnerability, which was classified as critical, has been found in Siemens SINEC NMS up to 4.0. The impacted element is the function getTotalAndFilterCounts of the component Endpoint. Performing a manipulation results in sql injection. Th

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-37147 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-37147 | HPE ArubaOS up to 10.7.1.1 Secure Boot authentication spoofing

A vulnerability identified as critical has been detected in HPE ArubaOS up to 8.10.0.18/8.12.0.5/8.13.0.1/10.4.1.8/10.7.1.1. This impacts an unknown function of the component Secure Boot. Performing a manipulation results in authentication

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.7%
CVE-2025-37138 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-37138 | HPE ArubaOS up to 10.7.1.1 Command Line Interface command injection

A vulnerability identified as critical has been detected in HPE ArubaOS up to 8.10.0.18/8.12.0.5/8.13.0.1/10.4.1.8/10.7.1.1. Affected by this issue is some unknown functionality of the component Command Line Interface. The manipulation lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-20717 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-20717 | MediaTek MT7986 WLAN AP Driver stack-based overflow

A vulnerability marked as critical has been reported in MediaTek MT6890, MT7615, MT7622, MT7663, MT7915, MT7916, MT7981 and MT7986. The affected element is an unknown function of the component WLAN AP Driver. This manipulation causes stack-

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11720 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-11720 | Mozilla Firefox up to 143 on Android Focus UI ui layer (WID-SEC-2025-2275)

A vulnerability classified as problematic has been found in Mozilla Firefox up to 143 on Android. This vulnerability affects unknown code of the component Focus UI. This manipulation causes improper restriction of rendered ui layers. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-11718 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-11718 | Mozilla Firefox up to 143 on Android Address Bar clickjacking (WID-SEC-2025-2275)

A vulnerability, which was classified as problematic, was found in Mozilla Firefox up to 143 on Android. The affected element is an unknown function of the component Address Bar. Executing a manipulation can lead to clickjacking. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11717 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-11717 | Mozilla Firefox up to 143 on Android denial of service (WID-SEC-2025-2275)

A vulnerability, which was classified as problematic, has been found in Mozilla Firefox up to 143 on Android. Impacted is an unknown function. Performing a manipulation results in denial of service. This vulnerability is known as CVE-2025-1

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 20.4%
CVE-2025-10242 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10242 | Ivanti Endpoint Manager Mobile prior 12.4.0.4/12.5.0.4/12.6.0.2 os command injection (EUVD-2025-34213 / Nessus ID 270691)

A vulnerability categorized as critical has been discovered in Ivanti Endpoint Manager Mobile. This issue affects some unknown processing. The manipulation results in os command injection. This vulnerability is identified as CVE-2025-10242.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 15.3%
CVE-2025-9713 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-9713 | Ivanti Endpoint Manager path traversal (EUVD-2025-34088 / Nessus ID 275450)

A vulnerability, which was classified as critical, was found in Ivanti Endpoint Manager. Affected is an unknown function. Executing a manipulation can lead to path traversal. This vulnerability is tracked as CVE-2025-9713. The attack can be

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-9626 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9626 | Page Blocks Plugin up to 1.1.0 on WordPress admin_process_widget_page_change cross-site request forgery (EUVD-2025-33848)

A vulnerability classified as problematic was found in Page Blocks Plugin up to 1.1.0 on WordPress. Affected by this vulnerability is the function admin_process_widget_page_change. The manipulation results in cross-site request forgery. Thi

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-8593 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-8593 | GSheetConnector for Gravity Forms Plugin up to 1.3.27 on WordPress Plugin Installation install_plugin authorization (EUVD-2025-33844)

A vulnerability classified as critical has been found in GSheetConnector for Gravity Forms Plugin up to 1.3.27 on WordPress. The impacted element is the function install_plugin of the component Plugin Installation Handler. Performing a mani

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.7%
CVE-2025-37729 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-37729 | Elastic Cloud Enterprise up to 3.8.1/4.0.1 Template Engine special elements in template engine (EUVD-2025-34069)

A vulnerability has been found in Elastic Cloud Enterprise up to 3.8.1/4.0.1 and classified as problematic. This affects an unknown part of the component Template Engine. The manipulation leads to improper neutralization of special elements

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-31995 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-31995 | HCL MaxAI Workbench input validation (KB0124425)

A vulnerability was found in HCL MaxAI Workbench and classified as critical. This affects an unknown function. Such manipulation leads to improper input validation. This vulnerability is traded as CVE-2025-31995. The attack may be launched

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-11629 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11629 | RainyGao DocSys up to 2.02.36 /Manage/getUserList.do getUserList sql injection (EUVD-2025-33886)

A vulnerability was found in RainyGao DocSys up to 2.02.36. It has been declared as critical. This impacts the function getUserList of the file /Manage/getUserList.do. Such manipulation leads to sql injection. This vulnerability is referenc

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11611 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11611 | SourceCodester Simple Inventory System 1.0 /user.php uemail sql injection (EUVD-2025-33873)

A vulnerability, which was classified as critical, has been found in SourceCodester Simple Inventory System 1.0. Impacted is an unknown function of the file /user.php. This manipulation of the argument uemail causes sql injection. This vuln

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-11597 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11597 | code-projects E-Commerce Website 1.0 product_add_qty.php prod_id sql injection (EUVD-2025-33860)

A vulnerability identified as critical has been detected in code-projects E-Commerce Website 1.0. The impacted element is an unknown function of the file /pages/product_add_qty.php. The manipulation of the argument prod_id leads to sql inje

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-10375 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-10375 | accessiBe Plugin up to 2.10 on WordPress Setting cross-site request forgery (EUVD-2025-33840)

A vulnerability, which was classified as problematic, has been found in accessiBe Plugin up to 2.10 on WordPress. This impacts the function accessibe_signup/accessibe_login/accessibe_license_trial/accessibe_modify_config/accessibe_add_verif

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-105080 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-105080 | C4illin ConvertX up to 0.18.x privileges management (EUVD-2026-91868)

A vulnerability has been found in C4illin ConvertX up to 0.18.x and classified as critical. The impacted element is an unknown function. The manipulation leads to improper privilege management. This vulnerability is referenced as CVE-2026-1

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-79113 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79113 | aswf OpenAPV prior 1.1.1.0 privilege escalation (EUVD-2026-91869)

A vulnerability was found in aswf OpenAPV and classified as critical. This affects an unknown function. The manipulation results in privilege escalation. This vulnerability is identified as CVE-2026-79113. The attack can be executed remotel

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-105083 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-105083 | ImageMagick up to 6.9.13-56/7.1.2-31 Policy Cache policy.xml LoadPolicyCache access control (EUVD-2026-91870)

A vulnerability was found in ImageMagick up to 6.9.13-56/7.1.2-31. It has been classified as problematic. This impacts the function LoadPolicyCache of the file policy.xml of the component Policy Cache. This manipulation causes improper acce

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-95865 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-95865 | Beaver Builder Page Builder Plugin up to 2.11.0.5 on WordPress AJAX Endpoint fields[][value] sql injection (EUVD-2026-91875)

A vulnerability was found in Beaver Builder Page Builder Plugin up to 2.11.0.5 on WordPress. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component AJAX Endpoint. Performing a manipulation

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-105090 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-105090 | Formbricks up to 5.4.3/6.0.0 Survey-level Custom Head Scripts feature cross site scripting (EUVD-2026-91874)

A vulnerability was found in Formbricks up to 5.4.3/6.0.0. It has been declared as problematic. Affected is an unknown function of the component Survey-level Custom Head Scripts feature. Such manipulation leads to cross site scripting. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-96270 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
WordPress

CVE-2026-96270 | Ultimate Member Plugin up to 2.13.1 on WordPress Admin UI jQuery.html form_id cross site scripting (EUVD-2026-91876)

A vulnerability marked as problematic has been reported in Ultimate Member Plugin up to 2.13.1 on WordPress. This issue affects the function jQuery.html of the component Admin UI. This manipulation of the argument form_id causes cross site

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-94378 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-94378 | psmplugins SupportCandy Plugin up to 3.5.3 on WordPress name cross site scripting (EUVD-2026-91878)

A vulnerability classified as problematic has been found in psmplugins SupportCandy Plugin up to 3.5.3 on WordPress. The affected element is an unknown function. Performing a manipulation of the argument Name results in cross site scripting

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
60 von ~0 Einträgen geladen Ende der Trefferliste — 60 Einträge geladen. Tipp: Filter leichtern für tieferes Blättern.