🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

372k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-10: 312 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 682 2026-06: 941 2026-07: 1327 2026-08: 1827 2026-09: 1508 2026-10: 69 9.420 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-192026-10-03
≥90 %538364
≥50 %16031115
≥10 %173
<10 %56400485
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 98.232 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
– OHNE BEWERTUNG
EPSS 13%
CVE-2025-61913 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-61913 | FlowiseAI Flowise up to 3.0.7 WriteFileTool/ReadFileTool path traversal (GHSA-j44m-5v8f-gc9c / EUVD-2025-33322)

A vulnerability was found in FlowiseAI Flowise up to 3.0.7 and classified as critical. The affected element is an unknown function of the component WriteFileTool/ReadFileTool. Such manipulation leads to path traversal. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-59990 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59990 | Juniper Junos Space up to 24.1R3 cross site scripting (JSA103140)

A vulnerability labeled as problematic has been found in Juniper Junos Space up to 24.1R3. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting. This vulnerability appears as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-59988 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59988 | Juniper Junos Space up to 24.1R3 cross site scripting (JSA103140)

A vulnerability categorized as problematic has been discovered in Juniper Junos Space up to 24.1R3. This vulnerability affects unknown code. Executing a manipulation can lead to cross site scripting. This vulnerability appears as CVE-2025-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-59984 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59984 | Juniper Junos Space up to 24.1R3 cross site scripting (JSA103140)

A vulnerability was found in Juniper Junos Space up to 24.1R3. It has been declared as problematic. Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting. This vulnerability is documented as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-36636 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-36636 | Tenable Security Center up to 6.6.x access control (Nessus ID 269967)

A vulnerability was found in Tenable Security Center up to 6.6.x. It has been rated as critical. This vulnerability affects unknown code. This manipulation causes improper access controls. The identification of this vulnerability is CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-11495 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11495 | GNU Binutils 2.45 Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflow (Bug 33502 / Nessus ID 270764)

A vulnerability was found in GNU Binutils 2.45. It has been classified as problematic. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-11494 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11494 | GNU Binutils 2.45 Linker bfd/elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-bounds (Bug 33499 / Nessus ID 270764)

A vulnerability was found in GNU Binutils 2.45 and classified as problematic. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-59452 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59452 | YoSmart YoLink API up to 2025-10-02 generation of predictable numbers or identifiers

A vulnerability classified as problematic has been found in YoSmart YoLink API up to 2025-10-02. This vulnerability affects unknown code. This manipulation causes generation of predictable numbers or identifiers. The identification of this

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-11402 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11402 | SourceCodester Hotel and Lodge Management System 1.0 /del_curr.php id sql injection

A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /del_curr.php. Such manipulation of the argument ID leads t

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-11396 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11396 | code-projects Simple Food Ordering System 1.0 /product.php category sql injection

A vulnerability described as critical has been identified in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /product.php. Such manipulation of the argument Category leads to sql injection. This vu

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-11321 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11321 | zhuimengshaonian wisdom-education up to 1.0.4 WrongBookController.java subjectId authorization (EUVD-2025-32489)

A vulnerability was found in zhuimengshaonian wisdom-education up to 1.0.4. It has been rated as problematic. The affected element is an unknown function of the file src/main/java/com/education/api/controller/student/WrongBookController.jav

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.8%
CVE-2025-11300 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11300 | Belkin F9K1015 1.00.10 /goform/formWlanMP ateFunc buffer overflow (EUVD-2025-32466)

A vulnerability classified as critical was found in Belkin F9K1015 1.00.10. The impacted element is an unknown function of the file /goform/formWlanMP. The manipulation of the argument ateFunc results in buffer overflow. This vulnerability

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 1.1%
CVE-2025-11297 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11297 | Belkin F9K1015 1.00.10 /goform/formSetLanguage webpage buffer overflow (EUVD-2025-32462)

A vulnerability marked as critical has been reported in Belkin F9K1015 1.00.10. This issue affects some unknown processing of the file /goform/formSetLanguage. Performing a manipulation of the argument webpage results in buffer overflow. Th

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-9897 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9897 | AP Background Plugin up to 3.8.2 on WordPress advParallaxBackAdminSaveSlider cross-site request forgery

A vulnerability was found in AP Background Plugin up to 3.8.2 on WordPress and classified as problematic. Impacted is the function advParallaxBackAdminSaveSlider. Executing a manipulation can lead to cross-site request forgery. This vulnera

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-9892 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9892 | Restrict User Registration Plugin up to 1.0.1 on WordPress Setting update cross-site request forgery

A vulnerability has been found in Restrict User Registration Plugin up to 1.0.1 on WordPress and classified as problematic. Affected is the function update of the component Setting Handler. This manipulation causes cross-site request forger

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-9286 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9286 | Appy Pie Connect for WooCommerce Plugin up to 1.1.2 on WordPress REST reset_user_password authorization

A vulnerability has been found in Appy Pie Connect for WooCommerce Plugin up to 1.1.2 on WordPress and classified as critical. Affected by this issue is the function reset_user_password of the component REST Handler. This manipulation cause

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-59759 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59759 | AndSoft e-TMS 25.03 URL LOGINFRM_DELCROIX.ASP l/demo/demo2/TNTLOGIN/UO/SuppConn cross site scripting

A vulnerability identified as problematic has been detected in AndSoft e-TMS 25.03. This vulnerability affects unknown code of the file /clt/LOGINFRM_DELCROIX.ASP of the component URL Handler. Performing a manipulation of the argument l/dem

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11291 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11291 | ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0 HTTP GET Request /map.php trid cross site scripting (EUVD-2025-32458)

A vulnerability was found in ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0. It has been classified as problematic. This impacts an unknown function of the file /map.php of the component HTTP GET Request Handler. Performi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-10746 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-10746 | Integrate Dynamics 365 CRM Plugin up to 1.0.9 on WordPress Configuration authorization (EUVD-2025-32421)

A vulnerability was found in Integrate Dynamics 365 CRM Plugin up to 1.0.9 on WordPress. It has been rated as critical. This affects an unknown part of the component Configuration Handler. This manipulation causes missing authorization. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-10729 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10729 | Qt up to 6.8.4/6.9.2 Node Parser use after free (Nessus ID 270732 / WID-SEC-2025-2205)

A vulnerability classified as critical has been found in Qt up to 6.8.4/6.9.2. This issue affects some unknown processing of the component Node Parser. Performing a manipulation results in use after free. This vulnerability was named CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-43718 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-43718 | Poppler up to 25.03.x GTS_PDFEVersion incorrect regex (Nessus ID 270109)

A vulnerability was found in Poppler up to 25.03.x. It has been rated as problematic. Impacted is an unknown function. This manipulation of the argument GTS_PDFEVersion causes incorrect regular expression. This vulnerability appears as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-40646 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-40646 | ViDay information disclosure (EUVD-2025-32669)

A vulnerability has been found in ViDay and classified as problematic. Affected is an unknown function. Performing a manipulation results in information disclosure. This vulnerability is identified as CVE-2025-40646. The attack can only be

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 4.2%
CVE-2025-11138 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11138 | mirweiye wenkucms up to 3.4 app/common/common.php createPathOne os command injection (EUVD-2025-31491)

A vulnerability classified as critical was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation results in os command injection. This vulnerability is cataloged as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.8%
CVE-2025-11122 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11122 | Tenda AC18 15.03.05.19 /goform/WizardHandle WANT/mtuvalue stack-based overflow (EUVD-2025-31477)

A vulnerability, which was classified as critical, was found in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandle. The manipulation of the argument WANT/mtuvalue results in stack-based buffer overflow

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-11116 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11116 | code-projects Simple Scheduling System 1.0 /add.home.php faculty sql injection (EUVD-2025-31471)

A vulnerability labeled as critical has been found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /add.home.php. The manipulation of the argument faculty results in sql injection. This vulnerability

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.7%
CVE-2026-102489 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-9894 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9894 | Sync Feedly Plugin up to 1.0.1 on WordPress crsf_cron_job_func cross-site request forgery (EUVD-2025-31414)

A vulnerability, which was classified as problematic, was found in Sync Feedly Plugin up to 1.0.1 on WordPress. The impacted element is the function crsf_cron_job_func. Executing a manipulation can lead to cross-site request forgery. This v

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-60104 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-60104 | Jordy Meow Gallery Custom Links Plugin up to 2.2.5 on WordPress cross site scripting

A vulnerability, which was classified as problematic, was found in Jordy Meow Gallery Custom Links Plugin up to 2.2.5 on WordPress. Impacted is an unknown function. The manipulation results in cross site scripting. This vulnerability is cat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-59002 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-59002 | SeaTheme BM Content Builder Plugin prior 3.16.3.3 on WordPress path traversal

A vulnerability classified as critical has been found in SeaTheme BM Content Builder Plugin on WordPress. Affected by this issue is some unknown functionality. This manipulation causes path traversal. This vulnerability is registered as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-11109 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11109 | Campcodes Computer Sales and Inventory System 1.0 us_edit.php?action=edit id sql injection (EUVD-2025-31466)

A vulnerability has been found in Campcodes Computer Sales and Inventory System 1.0 and classified as critical. The affected element is an unknown function of the file /pages/us_edit.php?action=edit. The manipulation of the argument ID lead

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 4.1%
CVE-2025-11098 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11098 | D-Link DIR-823X 250416 set_wifi_blacklists macList command injection (EUVD-2025-31453 / CNNVD-202509-4307)

A vulnerability was found in D-Link DIR-823X 250416. It has been declared as critical. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipulation of the argument macList results in command injectio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 4.1%
CVE-2025-11095 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11095 | D-Link DIR-823X 250416 delete_offline_device delvalue command injection (EUVD-2025-31450 / CNNVD-202509-4310)

A vulnerability has been found in D-Link DIR-823X 250416 and classified as critical. This vulnerability affects unknown code of the file /goform/delete_offline_device. Performing a manipulation of the argument delvalue results in command in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-11081 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11081 | GNU Binutils 2.45 binutils/objdump.c dump_dwarf_section out-of-bounds (Bug 33406 / EUVD-2025-31443)

A vulnerability was found in GNU Binutils 2.45. It has been classified as problematic. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing a manipulation results in out-of-bounds read. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11080 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11080 | zhuimengshaonian wisdom-education up to 1.0.4 ExamInfoController.java selectStudentExamInfoList subjectId improper authorization (EUVD-2025-31441)

A vulnerability was found in zhuimengshaonian wisdom-education up to 1.0.4 and classified as problematic. This vulnerability affects the function selectStudentExamInfoList of the file src/main/java/com/education/api/controller/student/ExamI

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11069 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11069 | westboy CicadasCMS 1.0 Add Department /system/org/save name cross site scripting (EUVD-2025-31431)

A vulnerability was found in westboy CicadasCMS 1.0. It has been classified as problematic. Affected by this issue is some unknown functionality of the file /system/org/save of the component Add Department Handler. This manipulation of the

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-11061 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2025-11061 | Campcodes Online Learning Management System 1.0 /admin/edit_student.php cys sql injection (EUVD-2025-31423)

A vulnerability identified as critical has been detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/edit_student.php. Performing a manipulation of the argument cys results in sql inje

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11041 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2025-11041 | itsourcecode Open Source Job Portal 1.0 index.php?view=edit id sql injection (EUVD-2025-31389)

A vulnerability was found in itsourcecode Open Source Job Portal 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/user/index.php?view=edit. The manipulation of the argument ID leads

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-11037 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11037 | code-projects E-Commerce Website 1.0 admin_index_search.php search sql injection (EUVD-2025-31383)

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. This impacts an unknown function of the file /pages/admin_index_search.php. Performing a manipulation of the argument Search results in sql in

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-96940 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Exchange Server Sicherheits-Updates vom 2.10.2026 schließen CVE-2026-96940

Microsoft hat zum 2. Oktober 2026 Sicherheits-Updates für Microsoft Exchange Server 2016, Microsoft Exchange Server 2019 und Microsoft Exchange Server SE veröffentlicht. Diese adressieren die Elevation of Privilege-Schwachstelle CVE-2026-96

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-60249 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-60249 | CIRCL vulnerability-lookup 2.16.0 bundle.py cross site scripting

A vulnerability categorized as problematic has been discovered in CIRCL vulnerability-lookup 2.16.0. The affected element is an unknown function of the file bundle.py. The manipulation results in cross site scripting. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 5%
CVE-2025-59527 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59527 | FlowiseAI Flowise 3.0.5 /api/v1/fetch-links server-side request forgery

A vulnerability labeled as critical has been found in FlowiseAI Flowise 3.0.5. Affected is an unknown function of the file /api/v1/fetch-links. The manipulation results in server-side request forgery. This vulnerability is identified as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 3.4%
CVE-2025-59434 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59434 | FlowiseAI Flowise Environment Variable information disclosure

A vulnerability was found in FlowiseAI Flowise and classified as problematic. This affects an unknown function of the component Environment Variable Handler. The manipulation results in information disclosure. This vulnerability is identifi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-10940 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2025-10940 | Total.js CMS 1.0.0 Layout Page /admin/ layouts_save HTML cross site scripting (EUVD-2025-31081 / CNNVD-202509-4006)

A vulnerability, which was classified as problematic, has been found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file /admin/ of the component Layout Page. Performing a manipulation of the argum

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-10541 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10541 | iMonitor EAM 9.63.94 eamusbsrv64.exe permission assignment

A vulnerability was found in iMonitor EAM 9.63.94 and classified as critical. This issue affects some unknown processing of the file eamusbsrv64.exe. Such manipulation leads to incorrect permission assignment. This vulnerability is listed a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-63292 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4

CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4 What Apache disclosed The Apache Software Foundation published CVE-2026-63292 as a stack-based buffer overflow in mod_vhost_alias, fixed in Apache HTTP Server 2.4.

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-59573 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-59573 | CozyThemes Cozy Blocks Plugin up to 2.1.29 on WordPress cross site scripting

A vulnerability was found in CozyThemes Cozy Blocks Plugin up to 2.1.29 on WordPress. It has been declared as problematic. Affected by this issue is some unknown functionality. Executing a manipulation can lead to basic cross site scripting

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-59430 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59430 | FrontFin mesh-web-sdk up to 3.3.1 URL Protocol cross site scripting (GHSA-vh3f-qppr-j97f)

A vulnerability, which was classified as problematic, has been found in FrontFin mesh-web-sdk up to 3.3.1. The affected element is an unknown function of the component URL Protocol Handler. This manipulation causes cross site scripting. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58992 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58992 | impleCode Product Catalog Simple Plugin up to 1.8.2 on WordPress cross site scripting

A vulnerability marked as problematic has been reported in impleCode Product Catalog Simple Plugin up to 1.8.2 on WordPress. This issue affects some unknown processing. Performing a manipulation results in cross site scripting. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-58968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58968 | Christiaan Pieterse MaxiBlocks Plugin up to 2.1.3 on WordPress authorization

A vulnerability was found in Christiaan Pieterse MaxiBlocks Plugin up to 2.1.3 on WordPress. It has been declared as problematic. This impacts an unknown function. Such manipulation leads to missing authorization. This vulnerability is list

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58960 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58960 | brijeshk89 IP Based Login Plugin up to 2.4.3 on WordPress cross site scripting

A vulnerability identified as problematic has been detected in brijeshk89 IP Based Login Plugin up to 2.4.3 on WordPress. This affects an unknown part. This manipulation causes cross site scripting. This vulnerability is tracked as CVE-2025

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58915 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58915 | Emarket-design YouTube Showcase Plugin up to 3.5.0 on WordPress cross site scripting

A vulnerability described as problematic has been identified in Emarket-design YouTube Showcase Plugin up to 3.5.0 on WordPress. The impacted element is an unknown function. The manipulation results in cross site scripting. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58683 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58683 | Luke Mlsna Last Updated Shortcode Plugin up to 1.0.1 on WordPress cross site scripting

A vulnerability classified as problematic has been found in Luke Mlsna Last Updated Shortcode Plugin up to 1.0.1 on WordPress. The impacted element is an unknown function. The manipulation leads to cross site scripting. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-10846 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10846 | Portabilis i-Educar up to 2.10 edit id sql injection

A vulnerability, which was classified as critical, has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/ComponenteCurricular/edit. This manipulation of the argument ID causes sql inje

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-10845 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10845 | Portabilis i-Educar up to 2.10 view id sql injection

A vulnerability classified as critical was found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/ComponenteCurricular/view. The manipulation of the argument ID results in sql injection. This vulnerability

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-10839 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2025-10839 | SourceCodester Pet Grooming Management Software 1.0 /admin/inv-print.php id sql injection

A vulnerability categorized as critical has been discovered in SourceCodester Pet Grooming Management Software 1.0. The impacted element is an unknown function of the file /admin/inv-print.php. The manipulation of the argument ID results in

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58665 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58665 | tmontg1 Form Generator for WordPress Plugin up to 1.5.2 on WordPress cross site scripting

A vulnerability classified as problematic was found in tmontg1 Form Generator for WordPress Plugin up to 1.5.2 on WordPress. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-58662 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58662 | awesomesupport Awesome Support Plugin up to 6.3.4 on WordPress deserialization

A vulnerability has been found in awesomesupport Awesome Support Plugin up to 6.3.4 on WordPress and classified as problematic. This affects an unknown function. This manipulation causes deserialization. This vulnerability is handled as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-58269 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58269 | weDevs WP Project Manager Plugin up to 2.6.25 on WordPress hard-coded credentials

A vulnerability, which was classified as critical, has been found in weDevs WP Project Manager Plugin up to 2.6.25 on WordPress. This vulnerability affects unknown code. Performing a manipulation results in hard-coded credentials. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-58268 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58268 | WPMK PDF Generator Plugin up to 1.0.1 on WordPress cross-site request forgery

A vulnerability was found in WPMK PDF Generator Plugin up to 1.0.1 on WordPress. It has been classified as problematic. Impacted is an unknown function. This manipulation causes cross-site request forgery. This vulnerability is handled as C

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58266 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58266 | Fumiki Takahashi Gianism Plugin up to 5.2.2 on WordPress cross site scripting

A vulnerability classified as problematic was found in Fumiki Takahashi Gianism Plugin up to 5.2.2 on WordPress. This affects an unknown part. Such manipulation leads to cross site scripting. This vulnerability is traded as CVE-2025-58266.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
60 von ~0 Einträgen geladen Ende der Trefferliste — 60 Einträge geladen. Tipp: Filter leichtern für tieferes Blättern.