🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

372k+ 🇪🇺 EUVD-Datenbank
1 🔴 Critical im Radar
1 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 682 2026-06: 941 2026-07: 1327 2026-08: 1827 2026-09: 1478 9.326 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-172026-09-30
≥90 %0392
≥50 %01149
≥10 %02
<10 %300424
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 98.070 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
EPSS 11.7%
CVE-2026-73570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Zimbra Vulnerability Exploited to Gain Root Access and Steal Mailbox Authentication Secrets

An active exploitation of CVE-2026-73570, a high-severity unauthenticated OS command-injection vulnerability in Zimbra Collaboration Suite. Attackers used to obtain root access, establish persistent control, and collect mailbox authenticati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2026-53988 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Dockhand CVE-2026-53988 — CVSS 10.0 Unauthenticated Webhook Auth Bypass

An unsigned webhook request is enough to trigger a stack redeployment on Dockhand versions before 1.0.40. CVE-2026-53988 is rated CVSS 10.0. The git webhook endpoints skip authentication entirely when the webhook secret is null — the defaul

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2022-45307 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45307 | Chocolatey PHP Package up to 8.1.12 C:\tools\php81 permission (EUVD-2022-48206)

A vulnerability identified as critical has been detected in Chocolatey PHP Package up to 8.1.12. This affects an unknown function of the file C:\tools\php81. The manipulation leads to permission issues. This vulnerability is referenced as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2022-45306 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2022-45306 | Chocolatey Azure-Pipelines-Agent Package up to 2.211.1 C:\agent permission (EUVD-2022-48205)

A vulnerability described as critical has been identified in Chocolatey Azure-Pipelines-Agent Package up to 2.211.1. This vulnerability affects unknown code of the file C:\agent. Executing a manipulation can lead to permission issues. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 0.4%
CVE-2022-45305 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45305 | Chocolatey Package up to 3.11.0 on Python C:\Python311 permission (EUVD-2022-48204)

A vulnerability classified as critical was found in Chocolatey Package up to 3.11.0 on Python. This affects an unknown part of the file C:\Python311. Executing a manipulation can lead to permission issues. This vulnerability is registered a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1.1%
CVE-2026-88771 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

NetScaler: Webshell-Mapping nach Command-Injection per CVE-2026-88771

NIEDERLANDE / LONDON (IT BOLTWISE) – Angreifer haben Citrix NetScaler ADC und NetScaler Gateway offenbar über eine Vorauthentifizierungs-Command-Injection kompromittiert. Laut LevelBlue zielen die Aktivitäten auf CVE-2026-88771 mit einer CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. &quot;Their investigati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 0.2%
CVE-2025-5263 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-5263 | Mozilla Firefox up to 138.0.4 cross-domain policy (Nessus ID 237301 / WID-SEC-2025-1850)

A vulnerability, which was classified as critical, has been found in Mozilla Firefox. This affects an unknown part. The manipulation leads to permissive cross-domain policy with untrusted domains. This vulnerability is uniquely identified a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 8.6%
CVE-2025-4919 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4919 | Mozilla Firefox ESR up to 115.23.0 Javascript Object out-of-bounds write (EUVD-2025-15598 / Nessus ID 236893)

A vulnerability described as critical has been identified in Mozilla Firefox ESR up to 115.23.0. This affects an unknown function of the component Javascript Object Handler. Such manipulation leads to out-of-bounds write. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 9.4%
CVE-2025-4918 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4918 | Mozilla Firefox ESR up to 115.23.0 JavaScript out-of-bounds write (EUVD-2025-15599 / Nessus ID 236893)

A vulnerability marked as critical has been reported in Mozilla Firefox ESR up to 115.23.0. The impacted element is an unknown function of the component JavaScript Handler. This manipulation causes out-of-bounds write. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2025-4093 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4093 | Mozilla Thunderbird ESR up to 128.9 memory corruption (Nessus ID 235040 / WID-SEC-2025-1850)

A vulnerability, which was classified as critical, has been found in Mozilla Thunderbird ESR up to 128.9. Impacted is an unknown function. Performing a manipulation results in memory corruption. This vulnerability is identified as CVE-2025-

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2025-4093 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4093 | Mozilla Firefox ESR up to 128.9 memory corruption (Nessus ID 235040 / WID-SEC-2025-1850)

A vulnerability classified as critical was found in Mozilla Firefox ESR up to 128.9. This issue affects some unknown processing. Such manipulation leads to memory corruption. This vulnerability is referenced as CVE-2025-4093. It is possible

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-4092 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4092 | Mozilla Thunderbird up to 137.x memory corruption (WID-SEC-2025-1850)

A vulnerability classified as critical has been found in Mozilla Thunderbird up to 137.x. This vulnerability affects unknown code. This manipulation causes memory corruption. The identification of this vulnerability is CVE-2025-4092. It is

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-4092 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4092 | Mozilla Firefox up to 137.x memory corruption (WID-SEC-2025-1850)

A vulnerability described as critical has been identified in Mozilla Firefox up to 137.x. This affects an unknown part. The manipulation results in memory corruption. This vulnerability was named CVE-2025-4092. The attack may be performed f

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2025-4091 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4091 | Mozilla Thunderbird up to 137.x memory corruption (Nessus ID 234929 / WID-SEC-2025-1850)

A vulnerability marked as critical has been reported in Mozilla Thunderbird up to 137.x. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption. This vulnerability is uniquely identified as CVE-202

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2025-4091 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4091 | Mozilla Firefox up to 137.x memory corruption (Nessus ID 234929 / WID-SEC-2025-1850)

A vulnerability labeled as critical has been found in Mozilla Firefox up to 137.x. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to memory corruption. This vulnerability is handled as CVE-2025

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-4090 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2025-4090 | Mozilla Thunderbird up to 137.x on Android Logcat information disclosure (Nessus ID 297161 / WID-SEC-2025-1850)

A vulnerability has been found in Mozilla Thunderbird up to 137.x on Android and classified as problematic. Affected is an unknown function of the component Logcat. This manipulation causes information disclosure. This vulnerability is trac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-4090 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2025-4090 | Mozilla Firefox up to 137.x on Android Logcat information disclosure (Nessus ID 297161 / WID-SEC-2025-1850)

A vulnerability, which was classified as problematic, was found in Mozilla Firefox up to 137.x on Android. This impacts an unknown function of the component Logcat. The manipulation results in information disclosure. This vulnerability is i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 11.7%
CVE-2026-73570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Hackers Exploit Zimbra CVE-2026-73570 With Crafted Emails to Execute Commands Without Authentication

Threat Intelligence has identified active exploitation of CVE-2026-73570, a serious unauthenticated command-injection vulnerability in Zimbra Collaboration Suite. The flaw allows attackers to execute operating-system commands on exposed mai

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1%
CVE-2023-32393 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2023-32393 | Apple tvOS Web Content memory corruption (Nessus ID 352169)

A vulnerability categorized as critical has been discovered in Apple tvOS. Affected by this issue is some unknown functionality of the component Web Content Handler. Such manipulation leads to memory corruption. This vulnerability is traded

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1%
CVE-2023-32393 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2023-32393 | Apple watchOS Web Content memory corruption (Nessus ID 352169)

A vulnerability was found in Apple watchOS. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component Web Content Handler. This manipulation causes memory corruption. This vulnerability appea

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1%
CVE-2023-32393 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2023-32393 | Apple iOS/iPadOS Web Content memory corruption (Nessus ID 352169)

A vulnerability was found in Apple iOS and iPadOS. It has been declared as critical. Affected is an unknown function of the component Web Content Handler. The manipulation results in memory corruption. This vulnerability is reported as CVE-

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1%
CVE-2023-32393 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2023-32393 | Apple macOS WebKit memory corruption (HT213605 / Nessus ID 352169)

A vulnerability identified as critical has been detected in Apple macOS. The impacted element is an unknown function of the component WebKit. The manipulation leads to memory corruption. This vulnerability is referenced as CVE-2023-32393. R

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1.2%
CVE-2023-32359 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2023-32359 | Apple iOS/iPadOS up to 16.7.1 VoiceOver information disclosure (Nessus ID 352169 / WID-SEC-2024-1213)

A vulnerability identified as problematic has been detected in Apple iOS and iPadOS up to 16.7.1. Affected by this issue is some unknown functionality of the component VoiceOver. The manipulation leads to information disclosure. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2026-19534 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19534 | undici up to 6.28.0/7.29.0/8.10.1 WebSocket Client null pointer dereference (Nessus ID 352183)

A vulnerability classified as problematic has been found in undici up to 6.28.0/7.29.0/8.10.1. This impacts an unknown function of the component WebSocket Client. Performing a manipulation results in null pointer dereference. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.5%
CVE-2026-7273 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Angriffe aus dem lokalen Netzwerk auf Zyxel-Switches

Eine gefährliche Schwachstelle in mehreren Zyxel-Switches der GS1900-Serie wird für Angriffe genutzt. Nicht angemeldete Angreifer im lokalen Netzwerk können über eine präparierte HTTP-Anfrage potenziell Betriebssystembefehle ausführen. (Bil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-54873 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-54873 | OpenSSL up to 3.4.7/3.5.8/3.6.4/4.0.2 QUIC allocation of resources (Nessus ID 352191)

A vulnerability classified as problematic was found in OpenSSL up to 3.4.7/3.5.8/3.6.4/4.0.2. Affected is an unknown function of the component QUIC. The manipulation results in allocation of resources. This vulnerability is reported as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-77696 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77696 | OpenSSL up to 4.0.2 SM2 Signature Generation timing discrepancy (Nessus ID 352192)

A vulnerability labeled as problematic has been found in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. The affected element is an unknown function of the component SM2 Signature Generation. Such manipulation leads to observable timing discr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2026-75806 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75806 | OpenSSL up to 4.0.2 Record Layer improper validation of specified quantity in input (Nessus ID 352193)

A vulnerability categorized as problematic has been discovered in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. The impacted element is an unknown function of the component Record Layer. Such manipulation leads to improper validation of spe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-75805 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75805 | OpenSSL up to 4.0.2 CMP Client OSSL_CMP_exec_RR_ses null pointer dereference (Nessus ID 352193)

A vulnerability was found in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. It has been classified as problematic. This issue affects the function OSSL_CMP_exec_RR_ses of the component CMP Client. The manipulation leads to null pointer deref

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2026-17106 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Gain Root Access

A Docker flaw, CVE-2026-17106 (dubbed CopyEscape), lets malicious containers write files outside the docker cp destination, potentially enabling code execution and root-level compromise. The issue affects Docker’s archive extraction handlin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Donnerstag: Sicherheitslücke bei Wiener Behörde, Tech-Prominenz hilft Pentagon

Cybereinbruch in Wien + Musk &amp;amp; Luckey als Hegseth-Berater + Google-KI für IT-Sicherheit + US-Untersuchung von KI-Vorfällen + KI-Einsatz in der Reha + #heiseshow Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-42772 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-42772 | OpenSSL up to 3.4.7/3.5.8/3.6.4/4.0.2 Stream Reassembly algorithmic complexity (Nessus ID 352194)

A vulnerability categorized as problematic has been discovered in OpenSSL up to 3.4.7/3.5.8/3.6.4/4.0.2. This issue affects some unknown processing of the component Stream Reassembly. The manipulation results in inefficient algorithmic comp

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-35191 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-35191 | OpenSSL up to 3.5.8/3.6.4/4.0.2 QUIC expected behavior violation (Nessus ID 352194)

A vulnerability was found in OpenSSL up to 3.5.8/3.6.4/4.0.2. It has been declared as problematic. This affects an unknown part of the component QUIC. Executing a manipulation can lead to expected behavior violation. The identification of t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2025-4089 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4089 | Mozilla Thunderbird up to 137.x Copy as cURL command injection (WID-SEC-2025-1850)

A vulnerability marked as problematic has been reported in Mozilla Thunderbird up to 137.x. This issue affects some unknown processing of the component Copy as cURL Handler. This manipulation causes command injection. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2025-4089 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4089 | Mozilla Firefox up to 137.x Copy as cURL command injection (WID-SEC-2025-1850)

A vulnerability labeled as problematic has been found in Mozilla Firefox up to 137.x. This vulnerability affects unknown code of the component Copy as cURL Handler. The manipulation results in command injection. This vulnerability is known

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2025-4088 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4088 | Mozilla Thunderbird up to 137.x Storage Access API access control (WID-SEC-2025-1850)

A vulnerability, which was classified as critical, has been found in Mozilla Thunderbird up to 137.x. This affects an unknown function of the component Storage Access API. The manipulation leads to improper access controls. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2025-4088 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4088 | Mozilla Firefox up to 137.x Storage Access API access control (WID-SEC-2025-1850)

A vulnerability classified as critical was found in Mozilla Firefox up to 137.x. The impacted element is an unknown function of the component Storage Access API. Executing a manipulation can lead to improper access controls. The identificat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-4087 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4087 | Mozilla Thunderbird up to 137.x XPath Parser out-of-bounds (Nessus ID 235040 / WID-SEC-2025-1850)

A vulnerability was found in Mozilla Thunderbird up to 137.x. It has been classified as critical. Affected by this issue is some unknown functionality of the component XPath Parser. Performing a manipulation results in out-of-bounds read. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-4087 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4087 | Mozilla Firefox up to 137.x XPath Parser out-of-bounds (Nessus ID 235040 / WID-SEC-2025-1850)

A vulnerability was found in Mozilla Firefox up to 137.x and classified as critical. Affected by this vulnerability is an unknown functionality of the component XPath Parser. Such manipulation leads to out-of-bounds read. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-4086 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-4086 | Mozilla Thunderbird up to 137 on Android Filename ui layer (Nessus ID 297163 / WID-SEC-2025-1850)

A vulnerability classified as problematic has been found in Mozilla Thunderbird up to 137 on Android. The affected element is an unknown function of the component Filename Handler. Performing a manipulation results in improper restriction o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-4086 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-4086 | Mozilla Firefox up to 137 on Android Filename ui layer (Nessus ID 297163 / WID-SEC-2025-1850)

A vulnerability described as problematic has been identified in Mozilla Firefox up to 137 on Android. Impacted is an unknown function of the component Filename Handler. Such manipulation leads to improper restriction of rendered ui layers.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-4085 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4085 | Mozilla Thunderbird up to 137.x UITour privileges management (Nessus ID 234927 / WID-SEC-2025-1850)

A vulnerability was found in Mozilla Thunderbird up to 137.x. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component UITour. Performing a manipulation results in improper privilege managem

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-4085 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4085 | Mozilla Firefox up to 137.x UITour privileges management (Nessus ID 234927 / WID-SEC-2025-1850)

A vulnerability was found in Mozilla Firefox up to 137.x. It has been declared as critical. Affected is an unknown function of the component UITour. Such manipulation leads to improper privilege management. This vulnerability is documented

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2025-4084 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2025-4084 | Mozilla Thunderbird ESR up to 115.22/128.9 on Windows Copy as cURL escape output (Nessus ID 234931 / WID-SEC-2025-1850)

A vulnerability identified as problematic has been detected in Mozilla Thunderbird ESR up to 115.22/128.9 on Windows. This affects an unknown part of the component Copy as cURL Handler. The manipulation leads to escaping of output. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 0.4%
CVE-2025-4084 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2025-4084 | Mozilla Firefox ESR up to 115.22/128.9 on Windows Copy as cURL escape output (Nessus ID 234931 / WID-SEC-2025-1850)

A vulnerability categorized as problematic has been discovered in Mozilla Firefox ESR up to 115.22/128.9 on Windows. Affected by this issue is some unknown functionality of the component Copy as cURL Handler. Executing a manipulation can le

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 0.3%
CVE-2026-10031 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-10031 | drakkan SFTPGo up to 2.7.3 Symbolic Link access control (EUVD-2026-51360)

A vulnerability classified as critical was found in drakkan SFTPGo up to 2.7.3. Impacted is an unknown function of the component Symbolic Link Handler. The manipulation results in improper access controls. This vulnerability is reported as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-96355 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-96362 and the Limits of Version-Based Drupal Scanning

CVE-2026-96362 and the Limits of Version-Based Drupal Scanning Vulnerability overview CERT-BUND advisory WID-SEC-2026-3554 covers a batch of vulnerabilities in contributed Drupal projects, published 23 September 2026 and rated high risk. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2022-45304 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45304 | Chocolatey Cmder Package up to 1.3.20 C:\tools\Cmder permission (EUVD-2022-48203)

A vulnerability marked as critical has been reported in Chocolatey Cmder Package up to 1.3.20. This affects an unknown part of the file C:\tools\Cmder. Performing a manipulation results in permission issues. This vulnerability is identified

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2022-45301 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45301 | Chocolatey Gem up to 3.1.2.1 on Ruby C:\tools\ruby31 permission (EUVD-2022-48200)

A vulnerability classified as critical has been found in Chocolatey Gem up to 3.1.2.1 on Ruby. Affected by this issue is some unknown functionality of the file C:\tools\ruby31. Performing a manipulation results in permission issues. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.8%
CVE-2022-45297 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45297 | tlfyyds EQ up to 2.2.0 UserPwd sql injection (EUVD-2022-48197 / EDB-51154)

A vulnerability has been found in tlfyyds EQ up to 2.2.0 and classified as critical. Impacted is an unknown function. Performing a manipulation of the argument UserPwd results in sql injection. This vulnerability was named CVE-2022-45297. T

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2022-45292 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45292 | Funkwhale 1.2.8 User Invite access control (Issue 1952 / EUVD-2022-48192)

A vulnerability identified as critical has been detected in Funkwhale 1.2.8. Impacted is an unknown function of the component User Invite Handler. The manipulation leads to improper access controls. This vulnerability is documented as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1.3%
CVE-2022-45291 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45291 | PWS Personal Weather Station Dashboard settings.php code injection (EUVD-2022-48191)

A vulnerability, which was classified as critical, was found in PWS Personal Weather Station Dashboard. Affected by this issue is some unknown functionality of the file settings.php. Executing a manipulation can lead to code injection. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-88774 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Policy Drift on Application Delivery Controllers: The Setting Behind CVE-2026-88774

Policy Drift on Application Delivery Controllers: The Setting Behind CVE-2026-88774 Application delivery controllers accumulate configuration the way coastlines accumulate sediment. A rule is added for a migration, a redirect for a campaign

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-9987 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9987 | broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress get_sponsored_meta information disclosure (EUVD-2025-209818)

A vulnerability, which was classified as problematic, was found in broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress. This affects the function get_sponsored_meta. Such manipulation leads to information disclosure. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.2%
CVE-2025-14755 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-14755 | stylemix Cost Calculator Builder Plugin up to 4.0.1 on WordPress renderWooCommercePayment authorization (EUVD-2025-209816)

A vulnerability classified as critical was found in stylemix Cost Calculator Builder Plugin up to 4.0.1 on WordPress. The affected element is the function renderWooCommercePayment. The manipulation results in missing authorization. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.2%
CVE-2025-9989 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9989 | broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress Setting cross site scripting (EUVD-2025-209820)

A vulnerability labeled as problematic has been found in broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress. Impacted is an unknown function of the component Setting Handler. Executing a manipulation can lead to cross site scriptin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.2%
CVE-2025-9988 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9988 | broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress AJAX Action create_advertiser improper authorization (EUVD-2025-209819)

A vulnerability has been found in broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress and classified as critical. This impacts the function create_advertiser of the component AJAX Action Handler. Performing a manipulation results in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.3%
CVE-2025-14033 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-14033 | ghera74 ilGhera Support System for WooCommerce Plugin up to 1.3.0 on WordPress get_ticket_content_callback authorization (EUVD-2025-209822)

A vulnerability, which was classified as problematic, was found in ghera74 ilGhera Support System for WooCommerce Plugin up to 1.3.0 on WordPress. Affected by this vulnerability is the function get_ticket_content_callback. Executing a manip

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.2%
CVE-2025-14767 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-14767 | wpclever WPC Badge Management for WooCommerce Plugin up to 3.1.6 on WordPress Shortcode wpcbm_best_seller text cross site scripting (EUVD-2025-209823)

A vulnerability was found in wpclever WPC Badge Management for WooCommerce Plugin up to 3.1.6 on WordPress. It has been classified as problematic. The affected element is the function wpcbm_best_seller of the component Shortcode Handler. Pe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
60 von ~0 Einträgen geladen Ende der Trefferliste — 60 Einträge geladen. Tipp: Filter leichtern für tieferes Blättern.