🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

371k+ 🇪🇺 EUVD-Datenbank
3 🔴 Critical im Radar
2 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
17 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 682 2026-06: 941 2026-07: 1327 2026-08: 1827 2026-09: 1478 9.326 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-172026-09-30
≥90 %0392
≥50 %01149
≥10 %02
<10 %300424
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 98.068 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
EPSS 0.3%
CVE-2025-9987 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9987 | broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress get_sponsored_meta information disclosure (EUVD-2025-209818)

A vulnerability, which was classified as problematic, was found in broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress. This affects the function get_sponsored_meta. Such manipulation leads to information disclosure. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.2%
CVE-2025-14755 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-14755 | stylemix Cost Calculator Builder Plugin up to 4.0.1 on WordPress renderWooCommercePayment authorization (EUVD-2025-209816)

A vulnerability classified as critical was found in stylemix Cost Calculator Builder Plugin up to 4.0.1 on WordPress. The affected element is the function renderWooCommercePayment. The manipulation results in missing authorization. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.2%
CVE-2025-9989 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9989 | broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress Setting cross site scripting (EUVD-2025-209820)

A vulnerability labeled as problematic has been found in broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress. Impacted is an unknown function of the component Setting Handler. Executing a manipulation can lead to cross site scriptin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.2%
CVE-2025-9988 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9988 | broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress AJAX Action create_advertiser improper authorization (EUVD-2025-209819)

A vulnerability has been found in broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress and classified as critical. This impacts the function create_advertiser of the component AJAX Action Handler. Performing a manipulation results in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.3%
CVE-2025-14033 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-14033 | ghera74 ilGhera Support System for WooCommerce Plugin up to 1.3.0 on WordPress get_ticket_content_callback authorization (EUVD-2025-209822)

A vulnerability, which was classified as problematic, was found in ghera74 ilGhera Support System for WooCommerce Plugin up to 1.3.0 on WordPress. Affected by this vulnerability is the function get_ticket_content_callback. Executing a manip

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.2%
CVE-2025-14767 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-14767 | wpclever WPC Badge Management for WooCommerce Plugin up to 3.1.6 on WordPress Shortcode wpcbm_best_seller text cross site scripting (EUVD-2025-209823)

A vulnerability was found in wpclever WPC Badge Management for WooCommerce Plugin up to 3.1.6 on WordPress. It has been classified as problematic. The affected element is the function wpcbm_best_seller of the component Shortcode Handler. Pe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS
CVE-2026-103531 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-103531 | OpenSC up to 0.27.1 card-setcos.c setcos_construct_fci_44 type_attr stack-based overflow (ID 3812 / EUVD-2026-90449)

A vulnerability classified as problematic was found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.6%
CVE-2026-19667 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19667 | ISC BIND 9 up to 9.20.27-S1 named input validation (Nessus ID 352233)

A vulnerability described as critical has been identified in ISC BIND 9 up to 9.18.50/9.20.27/9.21.25/9.18.50-S1/9.20.27-S1. This impacts an unknown function of the component named. The manipulation results in improper input validation. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1.6%
CVE-2022-36440 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-36440 | Frrouting frr-bgpd 8.3.0 BGP Open Packet peek_for_as4_capability assertion (Nessus ID 352219)

A vulnerability classified as problematic was found in Frrouting frr-bgpd 8.3.0. Impacted is the function peek_for_as4_capability of the component BGP Open Packet Handler. Executing a manipulation can lead to reachable assertion. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.6%
CVE-2026-19666 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19666 | ISC BIND 9 up to 9.20.27-S1 dns64 input validation (Nessus ID 352233)

A vulnerability classified as critical was found in ISC BIND 9 up to 9.18.50/9.20.27/9.21.25/9.18.50-S1/9.20.27-S1. This vulnerability affects unknown code of the component dns64. Executing a manipulation can lead to improper input validati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2025-21901 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2025-21901 | Linux Kernel up to 6.12.17/6.13.5 bnxt_re null pointer dereference (Nessus ID 352240 / WID-SEC-2025-0683)

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.17/6.13.5. Affected by this vulnerability is an unknown functionality of the component bnxt_re. Executing a manipulation can lead to null pointer derefer

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 1.9%
CVE-2020-14559 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2020-14559 | Oracle MySQL Server up to 5.6.48/5.7.30/8.0.20 Information Schema information disclosure (Nessus ID 352245)

A vulnerability identified as critical has been detected in Oracle MySQL Server up to 5.6.48/5.7.30/8.0.20. This affects an unknown part of the component Information Schema. Performing a manipulation results in information disclosure. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.2%
CVE-2020-14540 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2020-14540 | Oracle MySQL Server up to 5.7.30/8.0.20 DML denial of service (Nessus ID 352245)

A vulnerability categorized as critical has been discovered in Oracle MySQL Server up to 5.7.30/8.0.20. This impacts an unknown function of the component DML. The manipulation results in denial of service. This vulnerability is identified a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.9%
CVE-2022-45290 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45290 | Kbase Doc 1.0 IndexController.java denial of service (EUVD-2022-48190)

A vulnerability was found in Kbase Doc 1.0. It has been rated as problematic. The affected element is an unknown function of the file /web/IndexController.java. The manipulation leads to denial of service. This vulnerability is listed as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1%
CVE-2022-45287 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45287 | Temenos CWX 8.5.6 Registration.aspx access control (EUVD-2022-48187)

A vulnerability described as critical has been identified in Temenos CWX 8.5.6. This impacts an unknown function of the file Registration.aspx. Such manipulation leads to improper access controls. This vulnerability is documented as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2022-45283 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45283 | GPAC 2.0.0 MP4box svg_attributes.c smil_parse_time_list stack-based overflow (Issue 2295 / EUVD-2022-48183)

A vulnerability, which was classified as critical, has been found in GPAC 2.0.0. This affects an unknown part of the file /scenegraph/svg_attributes.c of the component MP4box. Performing a manipulation of the argument smil_parse_time_list r

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-103473 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Deno CVE-2026-103473 — CVSS 8.1 Command Injection in node:child_process on Windows

If your Deno app on Windows passes untrusted input to spawn, spawnSync, or exec with shell: true — patch now. CVE-2026-103473 (CVSS 8.1) is a command injection vulnerability in Deno&#039;s node:child_process polyfill. The escapeShellArg() h

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 0.4%
CVE-2022-45280 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45280 | EyouCMS 1.6.0 /login.php Url cross site scripting (Issue 32 / EUVD-2022-48180)

A vulnerability was found in EyouCMS 1.6.0. It has been declared as problematic. Impacted is an unknown function of the file /login.php. Executing a manipulation of the argument Url can lead to cross site scripting. This vulnerability appea

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.8%
CVE-2022-45278 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45278 | Jizhicms 2.3.3 get_fields.html sql injection (Issue 83 / EUVD-2022-48178)

A vulnerability, which was classified as critical, has been found in Jizhicms 2.3.3. This affects an unknown function of the file /index.php/admins/Fields/get_fields.html. Performing a manipulation results in sql injection. This vulnerabili

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.9%
CVE-2022-45276 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45276 | YJCMS 1.0.9 user_edit.html information disclosure (EUVD-2022-48176)

A vulnerability categorized as problematic has been discovered in YJCMS 1.0.9. The impacted element is an unknown function of the file /index/user/user_edit.html. The manipulation results in information disclosure. This vulnerability is kno

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.9%
CVE-2026-12227 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-12227 — How a Validate-Then-Mutate Bug Turns Into Unauthenticated LFI in Visual Composer

Overview Field Value CVE ID CVE-2026-12227 CVSS 3.1 9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CWE CWE-98 (Improper Control of Filename for Include/Require in PHP) Affected Visual Composer Website Builder WordPress plugin ≤ 45.16.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 15.3%
CVE-2022-45275 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-45275 | oretnom23 Dynamic Transaction Queuing System 1.0 PHP File ajax.php?action=save_settings unrestricted upload (EUVD-2022-48175)

A vulnerability classified as problematic has been found in oretnom23 Dynamic Transaction Queuing System 1.0. Impacted is an unknown function of the file /queuing/admin/ajax.php?action=save_settings of the component PHP File Handler. Perfor

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2022-45228 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45228 | Dragino Lora LG01 18ed40 IoT 4.3.4 Logout Page cross-site request forgery (EUVD-2022-48128)

A vulnerability categorized as problematic has been discovered in Dragino Lora LG01 18ed40 IoT 4.3.4. Impacted is an unknown function of the component Logout Page. The manipulation results in cross-site request forgery. This vulnerability i

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.7%
CVE-2022-45227 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45227 | Dragino Lora LG01 18ed40 IoT 4.3.4 Backup File /lib exposure of information through directory listing (EUVD-2022-48127)

A vulnerability has been found in Dragino Lora LG01 18ed40 IoT 4.3.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /lib of the component Backup File Handler. This manipulation causes expo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2022-45225 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45225 | Book Store Management System 1.0 /bsms_ci/index.php/book book_title cross site scripting (EUVD-2022-48125)

A vulnerability identified as problematic has been detected in Book Store Management System 1.0. Affected by this issue is some unknown functionality of the file /bsms_ci/index.php/book. The manipulation of the argument book_title leads to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2022-45224 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-45224 | Web-Based Student Clearance System 1.0 Admin/add-admin.php txtfullname cross site scripting (EUVD-2022-48124)

A vulnerability was found in Web-Based Student Clearance System 1.0 and classified as problematic. The affected element is an unknown function of the file Admin/add-admin.php. Such manipulation of the argument txtfullname leads to cross sit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-84411 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

A first-day response plan for CVE-2026-84411 in MikroTik RouterOS

A first-day response plan for CVE-2026-84411 in MikroTik RouterOS What is known CVE-2026-84411 affects MikroTik RouterOS before 7.24. CISA published advisory ICSA-26-272-06 on September 29, 2026, assigning a CVSS score of 9.8 Critical and c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2020-11656 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2020-11656 | Oracle ZFS Storage Appliance Kit 8.8 Operating System Image use after free (Nessus ID 352245)

A vulnerability, which was classified as very critical, was found in Oracle ZFS Storage Appliance Kit 8.8. Impacted is an unknown function of the component Operating System Image. Executing a manipulation can lead to use after free. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2020-11656 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2020-11656 | Oracle Communications Network Charging/Control up to 12.0.3 Data Access Pack use after free (Nessus ID 352245)

A vulnerability described as very critical has been identified in Oracle Communications Network Charging and Control 6.0.1/12.0.0/12.0.1/12.0.2/12.0.3. Affected by this vulnerability is an unknown functionality of the component Data Access

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2020-11656 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2020-11656 | SQLite up to 3.31.1 ALTER TABLE Statement use after free (ssa-389290 / Nessus ID 352245)

A vulnerability was found in SQLite up to 3.31.1 and classified as critical. Affected is an unknown function of the component ALTER TABLE Statement Handler. Such manipulation leads to use after free. This vulnerability is traded as CVE-2020

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2026-100885 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-100885 | Krayin laravel-crm up to 2.2.4 admin-config-setup API Endpoint CanInstall.php authorization (EUVD-2026-88049)

A vulnerability described as critical has been identified in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API E

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-103585 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-103585 | Wikimedia Foundation MediaWiki 1.43/1.45/1.46 MediaSearch cross site scripting (EUVD-2026-90431)

A vulnerability identified as problematic has been detected in Wikimedia Foundation MediaWiki 1.43/1.45/1.46. The impacted element is an unknown function of the component MediaSearch. The manipulation leads to cross site scripting. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-19553 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19553 | Python Software Foundation up to 3.15.x SSLObject ssl.SSLContext.wrap_bio server_hostname input validation (EUVD-2026-90078)

A vulnerability classified as critical has been found in Python Software Foundation Python up to 3.15.x. The impacted element is the function ssl.SSLContext.wrap_bio of the component SSLObject. This manipulation of the argument server_hostn

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-19445 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19445 | Python up to 3.15.x SSL Context Management Modules/_ssl.c sni_callback context use after free (EUVD-2026-90077)

A vulnerability classified as problematic was found in Python up to 3.15.x. This affects the function sni_callback of the file Modules/_ssl.c of the component SSL Context Management. Such manipulation of the argument context leads to use af

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2022-45223 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-45223 | Web-Based Student Clearance System 1.0 /Admin/add-student.php txtfullname cross site scripting (EUVD-2022-48123)

A vulnerability has been found in Web-Based Student Clearance System 1.0 and classified as problematic. Impacted is an unknown function of the file /Admin/add-student.php. This manipulation of the argument txtfullname causes cross site scri

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2022-45221 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45221 | Web-Based Student Clearance System 1.0 changepassword.php txtnew_password cross site scripting (EUVD-2022-48121)

A vulnerability, which was classified as problematic, was found in Web-Based Student Clearance System 1.0. This issue affects some unknown processing of the file changepassword.php. The manipulation of the argument txtnew_password results i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.6%
CVE-2022-45217 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45217 | Book Store Management System 1.0.0 Add New System User Level cross site scripting (EUVD-2022-48117)

A vulnerability has been found in Book Store Management System 1.0.0 and classified as problematic. This affects an unknown part of the component Add New System User Module. Performing a manipulation of the argument Level results in cross s

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2026-54872 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-54872 | OpenSSL up to 4.0.2 Elliptic-Curve Scalar Multiplication timing discrepancy (Nessus ID 352195)

A vulnerability identified as problematic has been detected in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. Impacted is an unknown function of the component Elliptic-Curve Scalar Multiplication. This manipulation causes observable timing d

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.1%
CVE-2026-35189 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-35189 | OpenSSL up to 4.0.2 CRL Distribution Points allocation of resources (Nessus ID 352195)

A vulnerability marked as problematic has been reported in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. The impacted element is an unknown function of the component CRL Distribution Points. Performing a manipulation results in allocation o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2026-84782 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-84782 | OpenSSL up to 4.0.2 DTLS retransmission logic SSL_read out-of-bounds (Nessus ID 352195)

A vulnerability identified as critical has been detected in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. This affects the function SSL_read of the component DTLS retransmission logic. Performing a manipulation results in out-of-bounds read

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1.1%
CVE-2026-88771 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

IT Security News Hourly Summary 2026-10-01 01h : 5 posts

5 posts published in the last hour 22:31Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30) 22:31Meta AI Shares Seller’s Address: Facebook Marketplace Buyer Shows Up at His Home 2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-96355 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-96355: How to Inventory Drupal Extensions Before You Patch

CVE-2026-96355: How to Inventory Drupal Extensions Before You Patch Patching is the easy half of the work. Knowing what you actually run is the harder half, and this advisory makes that ordering unavoidable. Vulnerability overview The CERT-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1.1%
CVE-2026-88771 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)

Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2023-54403 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Yonyou

CVE-2023-54403 | Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files containing database or service credentials. Exploitation evidence w

Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an u

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102105 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Kiteworks

CVE-2026-102105 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway renders message content that references external resources. Depending o

Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102106 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Kiteworks

CVE-2026-102106 | Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and change their security-feature configuration without authentic

Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password chec

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102107 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Kiteworks

CVE-2026-102107 | Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account. This could be used to solicit files or information from a recipient under a trusted identity; exploitation requires the feature to be enabled for the attacker's profile and the targeted

Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authori

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2024-58387 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Inspur

CVE-2024-58387 | Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as /api/model_report/file/download?index=/&ext=<path> to traverse the filesystem and disclose sensitive files including /etc/passwd, application database files, and system configuration

Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ex

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102108 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
Kiteworks

CVE-2026-102108 | An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.

An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code executi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102109 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Kiteworks

CVE-2026-102109 | A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature is in use.

A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could po

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2023-54402 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
iDocView

CVE-2023-54402 | iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application configuration files, and to reach internal network hosts and servi

iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102110 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Kiteworks

CVE-2026-102110 | An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-trigger the privileged activation process. This could disrupt setup and leave the appliance in an incompletely configured state. The issue is only reachable while an appliance is being activated for the first time and not ye

An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-tr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102111 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
Kiteworks

CVE-2026-102111 | Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the control continued to appear enabled in the administrative interface and audit log, allowing it to be silently rendered ineffective.

Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the contr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102112 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Kiteworks

CVE-2026-102112 | A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.

A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest pr

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102113 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Kiteworks

CVE-2026-102113 | A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem path that the lower-privileged account could influence, allowing the attacker to cause a root-owned operation to run arbitrary commands with the highest privileges. Exploitation requires existing local access to

A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102114 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
Kiteworks

CVE-2026-102114 | A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges.

A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102115 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Kiteworks

CVE-2026-102115 | Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.

Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102116 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
Kiteworks

CVE-2026-102116 | -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.

-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the un

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102117 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
Kiteworks

CVE-2026-102117 | On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resulting in remote code execution with the privileges of a local serv

On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-102118 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Kiteworks

CVE-2026-102118 | A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.

A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
60 von ~0 Einträgen geladen Ende der Trefferliste — 60 Einträge geladen. Tipp: Filter leichtern für tieferes Blättern.