Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-19 | 2026-10-03 |
|---|---|---|
| ≥90 % | 538 | 364 |
| ≥50 % | 1603 | 1115 |
| ≥10 % | 17 | 3 |
| <10 % | 56400 | 485 |
CVE-2025-61913 | FlowiseAI Flowise up to 3.0.7 WriteFileTool/ReadFileTool path traversal (GHSA-j44m-5v8f-gc9c / EUVD-2025-33322)
A vulnerability was found in FlowiseAI Flowise up to 3.0.7 and classified as critical. The affected element is an unknown function of the component WriteFileTool/ReadFileTool. Such manipulation leads to path traversal. This vulnerability is
CVE-2025-59990 | Juniper Junos Space up to 24.1R3 cross site scripting (JSA103140)
A vulnerability labeled as problematic has been found in Juniper Junos Space up to 24.1R3. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting. This vulnerability appears as
CVE-2025-59988 | Juniper Junos Space up to 24.1R3 cross site scripting (JSA103140)
A vulnerability categorized as problematic has been discovered in Juniper Junos Space up to 24.1R3. This vulnerability affects unknown code. Executing a manipulation can lead to cross site scripting. This vulnerability appears as CVE-2025-5
CVE-2025-59984 | Juniper Junos Space up to 24.1R3 cross site scripting (JSA103140)
A vulnerability was found in Juniper Junos Space up to 24.1R3. It has been declared as problematic. Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting. This vulnerability is documented as C
CVE-2025-36636 | Tenable Security Center up to 6.6.x access control (Nessus ID 269967)
A vulnerability was found in Tenable Security Center up to 6.6.x. It has been rated as critical. This vulnerability affects unknown code. This manipulation causes improper access controls. The identification of this vulnerability is CVE-202
CVE-2025-11495 | GNU Binutils 2.45 Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflow (Bug 33502 / Nessus ID 270764)
A vulnerability was found in GNU Binutils 2.45. It has been classified as problematic. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based
CVE-2025-11494 | GNU Binutils 2.45 Linker bfd/elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-bounds (Bug 33499 / Nessus ID 270764)
A vulnerability was found in GNU Binutils 2.45 and classified as problematic. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. This
CVE-2025-59452 | YoSmart YoLink API up to 2025-10-02 generation of predictable numbers or identifiers
A vulnerability classified as problematic has been found in YoSmart YoLink API up to 2025-10-02. This vulnerability affects unknown code. This manipulation causes generation of predictable numbers or identifiers. The identification of this
CVE-2025-11402 | SourceCodester Hotel and Lodge Management System 1.0 /del_curr.php id sql injection
A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /del_curr.php. Such manipulation of the argument ID leads t
CVE-2025-11396 | code-projects Simple Food Ordering System 1.0 /product.php category sql injection
A vulnerability described as critical has been identified in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /product.php. Such manipulation of the argument Category leads to sql injection. This vu
CVE-2025-11321 | zhuimengshaonian wisdom-education up to 1.0.4 WrongBookController.java subjectId authorization (EUVD-2025-32489)
A vulnerability was found in zhuimengshaonian wisdom-education up to 1.0.4. It has been rated as problematic. The affected element is an unknown function of the file src/main/java/com/education/api/controller/student/WrongBookController.jav
CVE-2025-11300 | Belkin F9K1015 1.00.10 /goform/formWlanMP ateFunc buffer overflow (EUVD-2025-32466)
A vulnerability classified as critical was found in Belkin F9K1015 1.00.10. The impacted element is an unknown function of the file /goform/formWlanMP. The manipulation of the argument ateFunc results in buffer overflow. This vulnerability
CVE-2025-11297 | Belkin F9K1015 1.00.10 /goform/formSetLanguage webpage buffer overflow (EUVD-2025-32462)
A vulnerability marked as critical has been reported in Belkin F9K1015 1.00.10. This issue affects some unknown processing of the file /goform/formSetLanguage. Performing a manipulation of the argument webpage results in buffer overflow. Th
CVE-2025-9897 | AP Background Plugin up to 3.8.2 on WordPress advParallaxBackAdminSaveSlider cross-site request forgery
A vulnerability was found in AP Background Plugin up to 3.8.2 on WordPress and classified as problematic. Impacted is the function advParallaxBackAdminSaveSlider. Executing a manipulation can lead to cross-site request forgery. This vulnera
CVE-2025-9892 | Restrict User Registration Plugin up to 1.0.1 on WordPress Setting update cross-site request forgery
A vulnerability has been found in Restrict User Registration Plugin up to 1.0.1 on WordPress and classified as problematic. Affected is the function update of the component Setting Handler. This manipulation causes cross-site request forger
CVE-2025-9286 | Appy Pie Connect for WooCommerce Plugin up to 1.1.2 on WordPress REST reset_user_password authorization
A vulnerability has been found in Appy Pie Connect for WooCommerce Plugin up to 1.1.2 on WordPress and classified as critical. Affected by this issue is the function reset_user_password of the component REST Handler. This manipulation cause
CVE-2025-59759 | AndSoft e-TMS 25.03 URL LOGINFRM_DELCROIX.ASP l/demo/demo2/TNTLOGIN/UO/SuppConn cross site scripting
A vulnerability identified as problematic has been detected in AndSoft e-TMS 25.03. This vulnerability affects unknown code of the file /clt/LOGINFRM_DELCROIX.ASP of the component URL Handler. Performing a manipulation of the argument l/dem
CVE-2025-11291 | ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0 HTTP GET Request /map.php trid cross site scripting (EUVD-2025-32458)
A vulnerability was found in ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0. It has been classified as problematic. This impacts an unknown function of the file /map.php of the component HTTP GET Request Handler. Performi
CVE-2025-10746 | Integrate Dynamics 365 CRM Plugin up to 1.0.9 on WordPress Configuration authorization (EUVD-2025-32421)
A vulnerability was found in Integrate Dynamics 365 CRM Plugin up to 1.0.9 on WordPress. It has been rated as critical. This affects an unknown part of the component Configuration Handler. This manipulation causes missing authorization. Thi
CVE-2025-10729 | Qt up to 6.8.4/6.9.2 Node Parser use after free (Nessus ID 270732 / WID-SEC-2025-2205)
A vulnerability classified as critical has been found in Qt up to 6.8.4/6.9.2. This issue affects some unknown processing of the component Node Parser. Performing a manipulation results in use after free. This vulnerability was named CVE-20
CVE-2025-43718 | Poppler up to 25.03.x GTS_PDFEVersion incorrect regex (Nessus ID 270109)
A vulnerability was found in Poppler up to 25.03.x. It has been rated as problematic. Impacted is an unknown function. This manipulation of the argument GTS_PDFEVersion causes incorrect regular expression. This vulnerability appears as CVE-
CVE-2025-40646 | ViDay information disclosure (EUVD-2025-32669)
A vulnerability has been found in ViDay and classified as problematic. Affected is an unknown function. Performing a manipulation results in information disclosure. This vulnerability is identified as CVE-2025-40646. The attack can only be
CVE-2025-11138 | mirweiye wenkucms up to 3.4 app/common/common.php createPathOne os command injection (EUVD-2025-31491)
A vulnerability classified as critical was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation results in os command injection. This vulnerability is cataloged as
CVE-2025-11122 | Tenda AC18 15.03.05.19 /goform/WizardHandle WANT/mtuvalue stack-based overflow (EUVD-2025-31477)
A vulnerability, which was classified as critical, was found in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandle. The manipulation of the argument WANT/mtuvalue results in stack-based buffer overflow
CVE-2025-11116 | code-projects Simple Scheduling System 1.0 /add.home.php faculty sql injection (EUVD-2025-31471)
A vulnerability labeled as critical has been found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /add.home.php. The manipulation of the argument faculty results in sql injection. This vulnerability
U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities
CVE-2025-9894 | Sync Feedly Plugin up to 1.0.1 on WordPress crsf_cron_job_func cross-site request forgery (EUVD-2025-31414)
A vulnerability, which was classified as problematic, was found in Sync Feedly Plugin up to 1.0.1 on WordPress. The impacted element is the function crsf_cron_job_func. Executing a manipulation can lead to cross-site request forgery. This v
CVE-2025-60104 | Jordy Meow Gallery Custom Links Plugin up to 2.2.5 on WordPress cross site scripting
A vulnerability, which was classified as problematic, was found in Jordy Meow Gallery Custom Links Plugin up to 2.2.5 on WordPress. Impacted is an unknown function. The manipulation results in cross site scripting. This vulnerability is cat
CVE-2025-59002 | SeaTheme BM Content Builder Plugin prior 3.16.3.3 on WordPress path traversal
A vulnerability classified as critical has been found in SeaTheme BM Content Builder Plugin on WordPress. Affected by this issue is some unknown functionality. This manipulation causes path traversal. This vulnerability is registered as CVE
CVE-2025-11109 | Campcodes Computer Sales and Inventory System 1.0 us_edit.php?action=edit id sql injection (EUVD-2025-31466)
A vulnerability has been found in Campcodes Computer Sales and Inventory System 1.0 and classified as critical. The affected element is an unknown function of the file /pages/us_edit.php?action=edit. The manipulation of the argument ID lead
CVE-2025-11098 | D-Link DIR-823X 250416 set_wifi_blacklists macList command injection (EUVD-2025-31453 / CNNVD-202509-4307)
A vulnerability was found in D-Link DIR-823X 250416. It has been declared as critical. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipulation of the argument macList results in command injectio
CVE-2025-11095 | D-Link DIR-823X 250416 delete_offline_device delvalue command injection (EUVD-2025-31450 / CNNVD-202509-4310)
A vulnerability has been found in D-Link DIR-823X 250416 and classified as critical. This vulnerability affects unknown code of the file /goform/delete_offline_device. Performing a manipulation of the argument delvalue results in command in
CVE-2025-11081 | GNU Binutils 2.45 binutils/objdump.c dump_dwarf_section out-of-bounds (Bug 33406 / EUVD-2025-31443)
A vulnerability was found in GNU Binutils 2.45. It has been classified as problematic. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing a manipulation results in out-of-bounds read. This vulnerab
CVE-2025-11080 | zhuimengshaonian wisdom-education up to 1.0.4 ExamInfoController.java selectStudentExamInfoList subjectId improper authorization (EUVD-2025-31441)
A vulnerability was found in zhuimengshaonian wisdom-education up to 1.0.4 and classified as problematic. This vulnerability affects the function selectStudentExamInfoList of the file src/main/java/com/education/api/controller/student/ExamI
CVE-2025-11069 | westboy CicadasCMS 1.0 Add Department /system/org/save name cross site scripting (EUVD-2025-31431)
A vulnerability was found in westboy CicadasCMS 1.0. It has been classified as problematic. Affected by this issue is some unknown functionality of the file /system/org/save of the component Add Department Handler. This manipulation of the
CVE-2025-11061 | Campcodes Online Learning Management System 1.0 /admin/edit_student.php cys sql injection (EUVD-2025-31423)
A vulnerability identified as critical has been detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/edit_student.php. Performing a manipulation of the argument cys results in sql inje
CVE-2025-11041 | itsourcecode Open Source Job Portal 1.0 index.php?view=edit id sql injection (EUVD-2025-31389)
A vulnerability was found in itsourcecode Open Source Job Portal 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/user/index.php?view=edit. The manipulation of the argument ID leads
CVE-2025-11037 | code-projects E-Commerce Website 1.0 admin_index_search.php search sql injection (EUVD-2025-31383)
A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. This impacts an unknown function of the file /pages/admin_index_search.php. Performing a manipulation of the argument Search results in sql in
Exchange Server Sicherheits-Updates vom 2.10.2026 schließen CVE-2026-96940
Microsoft hat zum 2. Oktober 2026 Sicherheits-Updates für Microsoft Exchange Server 2016, Microsoft Exchange Server 2019 und Microsoft Exchange Server SE veröffentlicht. Diese adressieren die Elevation of Privilege-Schwachstelle CVE-2026-96
CVE-2025-60249 | CIRCL vulnerability-lookup 2.16.0 bundle.py cross site scripting
A vulnerability categorized as problematic has been discovered in CIRCL vulnerability-lookup 2.16.0. The affected element is an unknown function of the file bundle.py. The manipulation results in cross site scripting. This vulnerability is
CVE-2025-59527 | FlowiseAI Flowise 3.0.5 /api/v1/fetch-links server-side request forgery
A vulnerability labeled as critical has been found in FlowiseAI Flowise 3.0.5. Affected is an unknown function of the file /api/v1/fetch-links. The manipulation results in server-side request forgery. This vulnerability is identified as CVE
CVE-2025-59434 | FlowiseAI Flowise Environment Variable information disclosure
A vulnerability was found in FlowiseAI Flowise and classified as problematic. This affects an unknown function of the component Environment Variable Handler. The manipulation results in information disclosure. This vulnerability is identifi
CVE-2025-10940 | Total.js CMS 1.0.0 Layout Page /admin/ layouts_save HTML cross site scripting (EUVD-2025-31081 / CNNVD-202509-4006)
A vulnerability, which was classified as problematic, has been found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file /admin/ of the component Layout Page. Performing a manipulation of the argum
CVE-2025-10541 | iMonitor EAM 9.63.94 eamusbsrv64.exe permission assignment
A vulnerability was found in iMonitor EAM 9.63.94 and classified as critical. This issue affects some unknown processing of the file eamusbsrv64.exe. Such manipulation leads to incorrect permission assignment. This vulnerability is listed a
CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4
CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4 What Apache disclosed The Apache Software Foundation published CVE-2026-63292 as a stack-based buffer overflow in mod_vhost_alias, fixed in Apache HTTP Server 2.4.
CVE-2025-59573 | CozyThemes Cozy Blocks Plugin up to 2.1.29 on WordPress cross site scripting
A vulnerability was found in CozyThemes Cozy Blocks Plugin up to 2.1.29 on WordPress. It has been declared as problematic. Affected by this issue is some unknown functionality. Executing a manipulation can lead to basic cross site scripting
CVE-2025-59430 | FrontFin mesh-web-sdk up to 3.3.1 URL Protocol cross site scripting (GHSA-vh3f-qppr-j97f)
A vulnerability, which was classified as problematic, has been found in FrontFin mesh-web-sdk up to 3.3.1. The affected element is an unknown function of the component URL Protocol Handler. This manipulation causes cross site scripting. Thi
CVE-2025-58992 | impleCode Product Catalog Simple Plugin up to 1.8.2 on WordPress cross site scripting
A vulnerability marked as problematic has been reported in impleCode Product Catalog Simple Plugin up to 1.8.2 on WordPress. This issue affects some unknown processing. Performing a manipulation results in cross site scripting. This vulnera
CVE-2025-58968 | Christiaan Pieterse MaxiBlocks Plugin up to 2.1.3 on WordPress authorization
A vulnerability was found in Christiaan Pieterse MaxiBlocks Plugin up to 2.1.3 on WordPress. It has been declared as problematic. This impacts an unknown function. Such manipulation leads to missing authorization. This vulnerability is list
CVE-2025-58960 | brijeshk89 IP Based Login Plugin up to 2.4.3 on WordPress cross site scripting
A vulnerability identified as problematic has been detected in brijeshk89 IP Based Login Plugin up to 2.4.3 on WordPress. This affects an unknown part. This manipulation causes cross site scripting. This vulnerability is tracked as CVE-2025
CVE-2025-58915 | Emarket-design YouTube Showcase Plugin up to 3.5.0 on WordPress cross site scripting
A vulnerability described as problematic has been identified in Emarket-design YouTube Showcase Plugin up to 3.5.0 on WordPress. The impacted element is an unknown function. The manipulation results in cross site scripting. This vulnerabili
CVE-2025-58683 | Luke Mlsna Last Updated Shortcode Plugin up to 1.0.1 on WordPress cross site scripting
A vulnerability classified as problematic has been found in Luke Mlsna Last Updated Shortcode Plugin up to 1.0.1 on WordPress. The impacted element is an unknown function. The manipulation leads to cross site scripting. This vulnerability i
CVE-2025-10846 | Portabilis i-Educar up to 2.10 edit id sql injection
A vulnerability, which was classified as critical, has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/ComponenteCurricular/edit. This manipulation of the argument ID causes sql inje
CVE-2025-10845 | Portabilis i-Educar up to 2.10 view id sql injection
A vulnerability classified as critical was found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/ComponenteCurricular/view. The manipulation of the argument ID results in sql injection. This vulnerability
CVE-2025-10839 | SourceCodester Pet Grooming Management Software 1.0 /admin/inv-print.php id sql injection
A vulnerability categorized as critical has been discovered in SourceCodester Pet Grooming Management Software 1.0. The impacted element is an unknown function of the file /admin/inv-print.php. The manipulation of the argument ID results in
CVE-2025-58665 | tmontg1 Form Generator for WordPress Plugin up to 1.5.2 on WordPress cross site scripting
A vulnerability classified as problematic was found in tmontg1 Form Generator for WordPress Plugin up to 1.5.2 on WordPress. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting. This vulner
CVE-2025-58662 | awesomesupport Awesome Support Plugin up to 6.3.4 on WordPress deserialization
A vulnerability has been found in awesomesupport Awesome Support Plugin up to 6.3.4 on WordPress and classified as problematic. This affects an unknown function. This manipulation causes deserialization. This vulnerability is handled as CVE
CVE-2025-58269 | weDevs WP Project Manager Plugin up to 2.6.25 on WordPress hard-coded credentials
A vulnerability, which was classified as critical, has been found in weDevs WP Project Manager Plugin up to 2.6.25 on WordPress. This vulnerability affects unknown code. Performing a manipulation results in hard-coded credentials. This vuln
CVE-2025-58268 | WPMK PDF Generator Plugin up to 1.0.1 on WordPress cross-site request forgery
A vulnerability was found in WPMK PDF Generator Plugin up to 1.0.1 on WordPress. It has been classified as problematic. Impacted is an unknown function. This manipulation causes cross-site request forgery. This vulnerability is handled as C
CVE-2025-58266 | Fumiki Takahashi Gianism Plugin up to 5.2.2 on WordPress cross site scripting
A vulnerability classified as problematic was found in Fumiki Takahashi Gianism Plugin up to 5.2.2 on WordPress. This affects an unknown part. Such manipulation leads to cross site scripting. This vulnerability is traded as CVE-2025-58266.