Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-17 | 2026-09-30 |
|---|---|---|
| ≥90 % | 0 | 392 |
| ≥50 % | 0 | 1149 |
| ≥10 % | 0 | 2 |
| <10 % | 300 | 424 |
Zimbra Vulnerability Exploited to Gain Root Access and Steal Mailbox Authentication Secrets
An active exploitation of CVE-2026-73570, a high-severity unauthenticated OS command-injection vulnerability in Zimbra Collaboration Suite. Attackers used to obtain root access, establish persistent control, and collect mailbox authenticati
Dockhand CVE-2026-53988 — CVSS 10.0 Unauthenticated Webhook Auth Bypass
An unsigned webhook request is enough to trigger a stack redeployment on Dockhand versions before 1.0.40. CVE-2026-53988 is rated CVSS 10.0. The git webhook endpoints skip authentication entirely when the webhook secret is null — the defaul
CVE-2022-45307 | Chocolatey PHP Package up to 8.1.12 C:\tools\php81 permission (EUVD-2022-48206)
A vulnerability identified as critical has been detected in Chocolatey PHP Package up to 8.1.12. This affects an unknown function of the file C:\tools\php81. The manipulation leads to permission issues. This vulnerability is referenced as C
CVE-2022-45306 | Chocolatey Azure-Pipelines-Agent Package up to 2.211.1 C:\agent permission (EUVD-2022-48205)
A vulnerability described as critical has been identified in Chocolatey Azure-Pipelines-Agent Package up to 2.211.1. This vulnerability affects unknown code of the file C:\agent. Executing a manipulation can lead to permission issues. This
CVE-2022-45305 | Chocolatey Package up to 3.11.0 on Python C:\Python311 permission (EUVD-2022-48204)
A vulnerability classified as critical was found in Chocolatey Package up to 3.11.0 on Python. This affects an unknown part of the file C:\Python311. Executing a manipulation can lead to permission issues. This vulnerability is registered a
NetScaler: Webshell-Mapping nach Command-Injection per CVE-2026-88771
NIEDERLANDE / LONDON (IT BOLTWISE) – Angreifer haben Citrix NetScaler ADC und NetScaler Gateway offenbar über eine Vorauthentifizierungs-Command-Injection kompromittiert. Laut LevelBlue zielen die Aktivitäten auf CVE-2026-88771 mit einer CV
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigati
CVE-2025-5263 | Mozilla Firefox up to 138.0.4 cross-domain policy (Nessus ID 237301 / WID-SEC-2025-1850)
A vulnerability, which was classified as critical, has been found in Mozilla Firefox. This affects an unknown part. The manipulation leads to permissive cross-domain policy with untrusted domains. This vulnerability is uniquely identified a
CVE-2025-4919 | Mozilla Firefox ESR up to 115.23.0 Javascript Object out-of-bounds write (EUVD-2025-15598 / Nessus ID 236893)
A vulnerability described as critical has been identified in Mozilla Firefox ESR up to 115.23.0. This affects an unknown function of the component Javascript Object Handler. Such manipulation leads to out-of-bounds write. This vulnerability
CVE-2025-4918 | Mozilla Firefox ESR up to 115.23.0 JavaScript out-of-bounds write (EUVD-2025-15599 / Nessus ID 236893)
A vulnerability marked as critical has been reported in Mozilla Firefox ESR up to 115.23.0. The impacted element is an unknown function of the component JavaScript Handler. This manipulation causes out-of-bounds write. This vulnerability is
CVE-2025-4093 | Mozilla Thunderbird ESR up to 128.9 memory corruption (Nessus ID 235040 / WID-SEC-2025-1850)
A vulnerability, which was classified as critical, has been found in Mozilla Thunderbird ESR up to 128.9. Impacted is an unknown function. Performing a manipulation results in memory corruption. This vulnerability is identified as CVE-2025-
CVE-2025-4093 | Mozilla Firefox ESR up to 128.9 memory corruption (Nessus ID 235040 / WID-SEC-2025-1850)
A vulnerability classified as critical was found in Mozilla Firefox ESR up to 128.9. This issue affects some unknown processing. Such manipulation leads to memory corruption. This vulnerability is referenced as CVE-2025-4093. It is possible
CVE-2025-4092 | Mozilla Thunderbird up to 137.x memory corruption (WID-SEC-2025-1850)
A vulnerability classified as critical has been found in Mozilla Thunderbird up to 137.x. This vulnerability affects unknown code. This manipulation causes memory corruption. The identification of this vulnerability is CVE-2025-4092. It is
CVE-2025-4092 | Mozilla Firefox up to 137.x memory corruption (WID-SEC-2025-1850)
A vulnerability described as critical has been identified in Mozilla Firefox up to 137.x. This affects an unknown part. The manipulation results in memory corruption. This vulnerability was named CVE-2025-4092. The attack may be performed f
CVE-2025-4091 | Mozilla Thunderbird up to 137.x memory corruption (Nessus ID 234929 / WID-SEC-2025-1850)
A vulnerability marked as critical has been reported in Mozilla Thunderbird up to 137.x. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption. This vulnerability is uniquely identified as CVE-202
CVE-2025-4091 | Mozilla Firefox up to 137.x memory corruption (Nessus ID 234929 / WID-SEC-2025-1850)
A vulnerability labeled as critical has been found in Mozilla Firefox up to 137.x. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to memory corruption. This vulnerability is handled as CVE-2025
CVE-2025-4090 | Mozilla Thunderbird up to 137.x on Android Logcat information disclosure (Nessus ID 297161 / WID-SEC-2025-1850)
A vulnerability has been found in Mozilla Thunderbird up to 137.x on Android and classified as problematic. Affected is an unknown function of the component Logcat. This manipulation causes information disclosure. This vulnerability is trac
CVE-2025-4090 | Mozilla Firefox up to 137.x on Android Logcat information disclosure (Nessus ID 297161 / WID-SEC-2025-1850)
A vulnerability, which was classified as problematic, was found in Mozilla Firefox up to 137.x on Android. This impacts an unknown function of the component Logcat. The manipulation results in information disclosure. This vulnerability is i
Hackers Exploit Zimbra CVE-2026-73570 With Crafted Emails to Execute Commands Without Authentication
Threat Intelligence has identified active exploitation of CVE-2026-73570, a serious unauthenticated command-injection vulnerability in Zimbra Collaboration Suite. The flaw allows attackers to execute operating-system commands on exposed mai
CVE-2023-32393 | Apple tvOS Web Content memory corruption (Nessus ID 352169)
A vulnerability categorized as critical has been discovered in Apple tvOS. Affected by this issue is some unknown functionality of the component Web Content Handler. Such manipulation leads to memory corruption. This vulnerability is traded
CVE-2023-32393 | Apple watchOS Web Content memory corruption (Nessus ID 352169)
A vulnerability was found in Apple watchOS. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component Web Content Handler. This manipulation causes memory corruption. This vulnerability appea
CVE-2023-32393 | Apple iOS/iPadOS Web Content memory corruption (Nessus ID 352169)
A vulnerability was found in Apple iOS and iPadOS. It has been declared as critical. Affected is an unknown function of the component Web Content Handler. The manipulation results in memory corruption. This vulnerability is reported as CVE-
CVE-2023-32393 | Apple macOS WebKit memory corruption (HT213605 / Nessus ID 352169)
A vulnerability identified as critical has been detected in Apple macOS. The impacted element is an unknown function of the component WebKit. The manipulation leads to memory corruption. This vulnerability is referenced as CVE-2023-32393. R
CVE-2023-32359 | Apple iOS/iPadOS up to 16.7.1 VoiceOver information disclosure (Nessus ID 352169 / WID-SEC-2024-1213)
A vulnerability identified as problematic has been detected in Apple iOS and iPadOS up to 16.7.1. Affected by this issue is some unknown functionality of the component VoiceOver. The manipulation leads to information disclosure. This vulner
CVE-2026-19534 | undici up to 6.28.0/7.29.0/8.10.1 WebSocket Client null pointer dereference (Nessus ID 352183)
A vulnerability classified as problematic has been found in undici up to 6.28.0/7.29.0/8.10.1. This impacts an unknown function of the component WebSocket Client. Performing a manipulation results in null pointer dereference. This vulnerabi
Angriffe aus dem lokalen Netzwerk auf Zyxel-Switches
Eine gefährliche Schwachstelle in mehreren Zyxel-Switches der GS1900-Serie wird für Angriffe genutzt. Nicht angemeldete Angreifer im lokalen Netzwerk können über eine präparierte HTTP-Anfrage potenziell Betriebssystembefehle ausführen. (Bil
CVE-2026-54873 | OpenSSL up to 3.4.7/3.5.8/3.6.4/4.0.2 QUIC allocation of resources (Nessus ID 352191)
A vulnerability classified as problematic was found in OpenSSL up to 3.4.7/3.5.8/3.6.4/4.0.2. Affected is an unknown function of the component QUIC. The manipulation results in allocation of resources. This vulnerability is reported as CVE-
CVE-2026-77696 | OpenSSL up to 4.0.2 SM2 Signature Generation timing discrepancy (Nessus ID 352192)
A vulnerability labeled as problematic has been found in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. The affected element is an unknown function of the component SM2 Signature Generation. Such manipulation leads to observable timing discr
CVE-2026-75806 | OpenSSL up to 4.0.2 Record Layer improper validation of specified quantity in input (Nessus ID 352193)
A vulnerability categorized as problematic has been discovered in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. The impacted element is an unknown function of the component Record Layer. Such manipulation leads to improper validation of spe
CVE-2026-75805 | OpenSSL up to 4.0.2 CMP Client OSSL_CMP_exec_RR_ses null pointer dereference (Nessus ID 352193)
A vulnerability was found in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. It has been classified as problematic. This issue affects the function OSSL_CMP_exec_RR_ses of the component CMP Client. The manipulation leads to null pointer deref
CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Gain Root Access
A Docker flaw, CVE-2026-17106 (dubbed CopyEscape), lets malicious containers write files outside the docker cp destination, potentially enabling code execution and root-level compromise. The issue affects Docker’s archive extraction handlin
Donnerstag: Sicherheitslücke bei Wiener Behörde, Tech-Prominenz hilft Pentagon
Cybereinbruch in Wien + Musk &amp; Luckey als Hegseth-Berater + Google-KI für IT-Sicherheit + US-Untersuchung von KI-Vorfällen + KI-Einsatz in der Reha + #heiseshow Weiterlesen
CVE-2026-42772 | OpenSSL up to 3.4.7/3.5.8/3.6.4/4.0.2 Stream Reassembly algorithmic complexity (Nessus ID 352194)
A vulnerability categorized as problematic has been discovered in OpenSSL up to 3.4.7/3.5.8/3.6.4/4.0.2. This issue affects some unknown processing of the component Stream Reassembly. The manipulation results in inefficient algorithmic comp
CVE-2026-35191 | OpenSSL up to 3.5.8/3.6.4/4.0.2 QUIC expected behavior violation (Nessus ID 352194)
A vulnerability was found in OpenSSL up to 3.5.8/3.6.4/4.0.2. It has been declared as problematic. This affects an unknown part of the component QUIC. Executing a manipulation can lead to expected behavior violation. The identification of t
CVE-2025-4089 | Mozilla Thunderbird up to 137.x Copy as cURL command injection (WID-SEC-2025-1850)
A vulnerability marked as problematic has been reported in Mozilla Thunderbird up to 137.x. This issue affects some unknown processing of the component Copy as cURL Handler. This manipulation causes command injection. This vulnerability is
CVE-2025-4089 | Mozilla Firefox up to 137.x Copy as cURL command injection (WID-SEC-2025-1850)
A vulnerability labeled as problematic has been found in Mozilla Firefox up to 137.x. This vulnerability affects unknown code of the component Copy as cURL Handler. The manipulation results in command injection. This vulnerability is known
CVE-2025-4088 | Mozilla Thunderbird up to 137.x Storage Access API access control (WID-SEC-2025-1850)
A vulnerability, which was classified as critical, has been found in Mozilla Thunderbird up to 137.x. This affects an unknown function of the component Storage Access API. The manipulation leads to improper access controls. This vulnerabili
CVE-2025-4088 | Mozilla Firefox up to 137.x Storage Access API access control (WID-SEC-2025-1850)
A vulnerability classified as critical was found in Mozilla Firefox up to 137.x. The impacted element is an unknown function of the component Storage Access API. Executing a manipulation can lead to improper access controls. The identificat
CVE-2025-4087 | Mozilla Thunderbird up to 137.x XPath Parser out-of-bounds (Nessus ID 235040 / WID-SEC-2025-1850)
A vulnerability was found in Mozilla Thunderbird up to 137.x. It has been classified as critical. Affected by this issue is some unknown functionality of the component XPath Parser. Performing a manipulation results in out-of-bounds read. T
CVE-2025-4087 | Mozilla Firefox up to 137.x XPath Parser out-of-bounds (Nessus ID 235040 / WID-SEC-2025-1850)
A vulnerability was found in Mozilla Firefox up to 137.x and classified as critical. Affected by this vulnerability is an unknown functionality of the component XPath Parser. Such manipulation leads to out-of-bounds read. This vulnerability
CVE-2025-4086 | Mozilla Thunderbird up to 137 on Android Filename ui layer (Nessus ID 297163 / WID-SEC-2025-1850)
A vulnerability classified as problematic has been found in Mozilla Thunderbird up to 137 on Android. The affected element is an unknown function of the component Filename Handler. Performing a manipulation results in improper restriction o
CVE-2025-4086 | Mozilla Firefox up to 137 on Android Filename ui layer (Nessus ID 297163 / WID-SEC-2025-1850)
A vulnerability described as problematic has been identified in Mozilla Firefox up to 137 on Android. Impacted is an unknown function of the component Filename Handler. Such manipulation leads to improper restriction of rendered ui layers.
CVE-2025-4085 | Mozilla Thunderbird up to 137.x UITour privileges management (Nessus ID 234927 / WID-SEC-2025-1850)
A vulnerability was found in Mozilla Thunderbird up to 137.x. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component UITour. Performing a manipulation results in improper privilege managem
CVE-2025-4085 | Mozilla Firefox up to 137.x UITour privileges management (Nessus ID 234927 / WID-SEC-2025-1850)
A vulnerability was found in Mozilla Firefox up to 137.x. It has been declared as critical. Affected is an unknown function of the component UITour. Such manipulation leads to improper privilege management. This vulnerability is documented
CVE-2025-4084 | Mozilla Thunderbird ESR up to 115.22/128.9 on Windows Copy as cURL escape output (Nessus ID 234931 / WID-SEC-2025-1850)
A vulnerability identified as problematic has been detected in Mozilla Thunderbird ESR up to 115.22/128.9 on Windows. This affects an unknown part of the component Copy as cURL Handler. The manipulation leads to escaping of output. This vul
CVE-2025-4084 | Mozilla Firefox ESR up to 115.22/128.9 on Windows Copy as cURL escape output (Nessus ID 234931 / WID-SEC-2025-1850)
A vulnerability categorized as problematic has been discovered in Mozilla Firefox ESR up to 115.22/128.9 on Windows. Affected by this issue is some unknown functionality of the component Copy as cURL Handler. Executing a manipulation can le
CVE-2026-10031 | drakkan SFTPGo up to 2.7.3 Symbolic Link access control (EUVD-2026-51360)
A vulnerability classified as critical was found in drakkan SFTPGo up to 2.7.3. Impacted is an unknown function of the component Symbolic Link Handler. The manipulation results in improper access controls. This vulnerability is reported as
CVE-2026-96362 and the Limits of Version-Based Drupal Scanning
CVE-2026-96362 and the Limits of Version-Based Drupal Scanning Vulnerability overview CERT-BUND advisory WID-SEC-2026-3554 covers a batch of vulnerabilities in contributed Drupal projects, published 23 September 2026 and rated high risk. Th
CVE-2022-45304 | Chocolatey Cmder Package up to 1.3.20 C:\tools\Cmder permission (EUVD-2022-48203)
A vulnerability marked as critical has been reported in Chocolatey Cmder Package up to 1.3.20. This affects an unknown part of the file C:\tools\Cmder. Performing a manipulation results in permission issues. This vulnerability is identified
CVE-2022-45301 | Chocolatey Gem up to 3.1.2.1 on Ruby C:\tools\ruby31 permission (EUVD-2022-48200)
A vulnerability classified as critical has been found in Chocolatey Gem up to 3.1.2.1 on Ruby. Affected by this issue is some unknown functionality of the file C:\tools\ruby31. Performing a manipulation results in permission issues. This vu
CVE-2022-45297 | tlfyyds EQ up to 2.2.0 UserPwd sql injection (EUVD-2022-48197 / EDB-51154)
A vulnerability has been found in tlfyyds EQ up to 2.2.0 and classified as critical. Impacted is an unknown function. Performing a manipulation of the argument UserPwd results in sql injection. This vulnerability was named CVE-2022-45297. T
CVE-2022-45292 | Funkwhale 1.2.8 User Invite access control (Issue 1952 / EUVD-2022-48192)
A vulnerability identified as critical has been detected in Funkwhale 1.2.8. Impacted is an unknown function of the component User Invite Handler. The manipulation leads to improper access controls. This vulnerability is documented as CVE-2
CVE-2022-45291 | PWS Personal Weather Station Dashboard settings.php code injection (EUVD-2022-48191)
A vulnerability, which was classified as critical, was found in PWS Personal Weather Station Dashboard. Affected by this issue is some unknown functionality of the file settings.php. Executing a manipulation can lead to code injection. The
Policy Drift on Application Delivery Controllers: The Setting Behind CVE-2026-88774
Policy Drift on Application Delivery Controllers: The Setting Behind CVE-2026-88774 Application delivery controllers accumulate configuration the way coastlines accumulate sediment. A rule is added for a migration, a redirect for a campaign
CVE-2025-9987 | broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress get_sponsored_meta information disclosure (EUVD-2025-209818)
A vulnerability, which was classified as problematic, was found in broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress. This affects the function get_sponsored_meta. Such manipulation leads to information disclosure. This vulnerabil
CVE-2025-14755 | stylemix Cost Calculator Builder Plugin up to 4.0.1 on WordPress renderWooCommercePayment authorization (EUVD-2025-209816)
A vulnerability classified as critical was found in stylemix Cost Calculator Builder Plugin up to 4.0.1 on WordPress. The affected element is the function renderWooCommercePayment. The manipulation results in missing authorization. This vul
CVE-2025-9989 | broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress Setting cross site scripting (EUVD-2025-209820)
A vulnerability labeled as problematic has been found in broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress. Impacted is an unknown function of the component Setting Handler. Executing a manipulation can lead to cross site scriptin
CVE-2025-9988 | broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress AJAX Action create_advertiser improper authorization (EUVD-2025-209819)
A vulnerability has been found in broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress and classified as critical. This impacts the function create_advertiser of the component AJAX Action Handler. Performing a manipulation results in
CVE-2025-14033 | ghera74 ilGhera Support System for WooCommerce Plugin up to 1.3.0 on WordPress get_ticket_content_callback authorization (EUVD-2025-209822)
A vulnerability, which was classified as problematic, was found in ghera74 ilGhera Support System for WooCommerce Plugin up to 1.3.0 on WordPress. Affected by this vulnerability is the function get_ticket_content_callback. Executing a manip
CVE-2025-14767 | wpclever WPC Badge Management for WooCommerce Plugin up to 3.1.6 on WordPress Shortcode wpcbm_best_seller text cross site scripting (EUVD-2025-209823)
A vulnerability was found in wpclever WPC Badge Management for WooCommerce Plugin up to 3.1.6 on WordPress. It has been classified as problematic. The affected element is the function wpcbm_best_seller of the component Shortcode Handler. Pe