🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

370k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 33 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 682 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 1339 9.221 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Linux Microsoft Adobe Apple Google Oracle Corporation
● Linux ● Microsoft ● Adobe ● Apple ● Google ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-152026-09-28
≥90 %0299
≥50 %0958
≥10 %03
<10 %300250
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 97.687 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Aktiv ausgenutzte F5-Sicherheitslücke ermöglicht RCE ohne Login

Eine Schwachstelle in F5 BIG-IP APM ermöglicht nicht angemeldeten Angreifern Remote Code Execution. Betroffen sind jedoch nur Systeme, die APM als OAuth Authorization Server einsetzen. F5 stellt Hotfixes und eine Mitigation bereit. (Bild: o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2026-77144 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77144 | TYPO3 Events 2 Plugin up to 10.2.11 permission

A vulnerability labeled as problematic has been found in TYPO3 Events 2 Plugin up to 10.2.11. This issue affects some unknown processing. The manipulation results in permission issues. This vulnerability is reported as CVE-2026-77144. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.1%
CVE-2026-21753 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-21753 | HCL Hive 1.0 unmaintained third party components

A vulnerability marked as critical has been reported in HCL Hive 1.0. This affects an unknown function. Performing a manipulation results in use of unmaintained third party components. This vulnerability is reported as CVE-2026-21753. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2026-12600 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-12600 | Innodata Poppler JPXDecode readCodestream memory allocation

A vulnerability labeled as problematic has been found in Innodata Poppler. The impacted element is the function JPXStream::readCodestream of the component JPXDecode Handler. Such manipulation leads to uncontrolled memory allocation. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.1%
CVE-2026-75038 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75038 | ilya-zlobintsev LACT up to 0.10.0 symlink

A vulnerability was found in ilya-zlobintsev LACT up to 0.10.0 and classified as problematic. Affected by this issue is some unknown functionality. Such manipulation leads to symlink following. This vulnerability is referenced as CVE-2026-7

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-16231 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-16231 | pillarjs hbs up to 4.2.1 Async Helper cross site scripting

A vulnerability has been found in pillarjs hbs up to 4.2.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Async Helper. This manipulation causes cross site scripting. The identific

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.1%
CVE-2026-75037 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75037 | ilya-zlobintsev LACT up to 0.10.0 improper authentication (WID-SEC-2026-3015)

A vulnerability, which was classified as very critical, was found in ilya-zlobintsev LACT up to 0.10.0. Affected is an unknown function. The manipulation results in improper authentication. This vulnerability was named CVE-2026-75037. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-76128 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-76128 | implecode eCommerce Product Catalog Plugin up to 3.5.10 on WordPress Shortcode style cross site scripting

A vulnerability, which was classified as problematic, has been found in implecode eCommerce Product Catalog Plugin up to 3.5.10 on WordPress. This impacts an unknown function of the component Shortcode Handler. The manipulation of the argum

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.2%
CVE-2026-77146 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77146 | TYPO3 femanager up to 8.4.1 Invitation Controller redirect

A vulnerability identified as problematic has been detected in TYPO3 femanager up to 8.4.1. This vulnerability affects unknown code of the component Invitation Controller. The manipulation leads to open redirect. This vulnerability is docum

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2026-49050 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-49050 | Apache DolphinScheduler up to 3.4.1 Access Token /access-tokens authorization

A vulnerability has been found in Apache DolphinScheduler up to 3.4.1 and classified as critical. Impacted is an unknown function of the file /access-tokens of the component Access Token Handler. Performing a manipulation results in incorre

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
EPSS 0.2%
CVE-2026-77143 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77143 | TYPO3 Forum up to 6.2.3 Topic Editing privileges management

A vulnerability was found in TYPO3 Forum up to 6.2.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Topic Editing. Such manipulation leads to improper privilege management.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-77145 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77145 | TYPO3 Events 2 up to 10.2.11 permission

A vulnerability categorized as problematic has been discovered in TYPO3 Events 2 up to 10.2.11. This affects an unknown part. Executing a manipulation can lead to permission issues. This vulnerability is registered as CVE-2026-77145. It is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-77142 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77142 | TYPO3 Industry Directory up to 8.1.1 Frontend Company Self-Service Editing Feature access control

A vulnerability was found in TYPO3 Industry Directory up to 8.1.1. It has been classified as problematic. Affected is an unknown function of the component Frontend Company Self-Service Editing Feature. This manipulation causes improper acce

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-77141 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77141 | TYPO3 Club Directory Extension up to 8.1.2 privileges management

A vulnerability was found in TYPO3 Club Directory Extension up to 8.1.2. It has been rated as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in improper privilege management. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-77135 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77135 | TYPO3 Femanager Plugin up to 6.4.4/7.5.4/8.4.1/13.3.4 User Detail View privileges management

A vulnerability was found in TYPO3 Femanager Plugin up to 6.4.4/7.5.4/8.4.1/13.3.4 and classified as problematic. This impacts an unknown function of the component User Detail View. The manipulation results in improper privilege management.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-77140 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77140 | TYPO3 Telephone Directory Extension up to 6.1.x access control

A vulnerability classified as problematic was found in TYPO3 Telephone Directory Extension up to 6.1.x. Impacted is an unknown function. Such manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2026-77139 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77139 | TYPO3 Mask up to 8.3.11/9.0.10 Mask module template element key path traversal

A vulnerability classified as critical has been found in TYPO3 Mask up to 8.3.11/9.0.10. This issue affects some unknown processing of the component Mask module. This manipulation of the argument template element key causes path traversal.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.6%
CVE-2026-77136 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77136 | TYPO3 Powermail up to 10.9.2/12.6.0/13.2.0 Fluid View sender_name code injection

A vulnerability was found in TYPO3 Powermail up to 10.9.2/12.6.0/13.2.0 and classified as critical. The affected element is an unknown function of the component Fluid View. Executing a manipulation of the argument sender_name can lead to co

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-77137 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77137 | TYPO3 Forms Export Extension up to 5.0.4/6.1.2/7.1.0 sql injection

A vulnerability described as critical has been identified in TYPO3 Forms Export Extension up to 5.0.4/6.1.2/7.1.0. This vulnerability affects unknown code of the component Forms Export. The manipulation results in sql injection. This vulner

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2026-78654 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-78654 | cleverbrush framework/deep up to 4.4.0 deepExtend.ts deepExtend prototype pollution (Issue 213)

A vulnerability identified as critical has been detected in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modificati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2026-77138 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77138 | TYPO3 HTML5 Video Player vs. Powermail Plugin up to 0.2.1 unserialize cookie deserialization

A vulnerability classified as critical was found in TYPO3 HTML5 Video Player vs. Powermail Plugin up to 0.2.1. This affects the function unserialize. The manipulation of the argument cookie results in deserialization. This vulnerability was

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-16481 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-16481 | Google MCP Toolbox for Databases up to 1.4.0 pageURL server-side request forgery

A vulnerability, which was classified as problematic, was found in Google MCP Toolbox for Databases up to 1.4.0. This impacts an unknown function. Such manipulation of the argument pageURL leads to server-side request forgery. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2026-78478 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-78478 | Elated-mes Mane Plugin up to 1.7 on WordPress file inclusion

A vulnerability was found in Elated-mes Mane Plugin up to 1.7 on WordPress. It has been declared as critical. Affected is an unknown function. The manipulation results in file inclusion. This vulnerability is reported as CVE-2026-78478. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.2%
CVE-2026-78470 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-78470 | wedevs WP Project Manager Pro Plugin up to 4.0.1 on WordPress sql injection

A vulnerability labeled as critical has been found in wedevs WP Project Manager Pro Plugin up to 4.0.1 on WordPress. This vulnerability affects unknown code. Executing a manipulation can lead to sql injection. This vulnerability is handled

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.3%
CVE-2026-20263 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-20263 | Cisco IOS XE Software up to 26.2.1ea BEEP denial of service (Nessus ID 334512)

A vulnerability categorized as critical has been discovered in Cisco IOS XE Software. This impacts an unknown function of the component BEEP. Executing a manipulation can lead to denial of service. This vulnerability is handled as CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.1%
CVE-2026-20786 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-20786 | Intel NPU Driver out-of-bounds (Nessus ID 335912)

A vulnerability, which was classified as problematic, has been found in Intel NPU Driver. This vulnerability affects unknown code. The manipulation leads to out-of-bounds read. This vulnerability is referenced as CVE-2026-20786. The attack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-12561 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-12561 | tagDiv Composer Plugin up to 5.4.5 on WordPress Shortcode vc_raw_html::render cross site scripting

A vulnerability was found in tagDiv Composer Plugin up to 5.4.5 on WordPress and classified as problematic. This affects the function vc_raw_html::render of the component Shortcode. Executing a manipulation can lead to cross site scripting.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.5%
CVE-2026-13214 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-13214 | Zephyr Project up to 4.4.1 OCPP Client ocpp_j.c parse_getconfig_msg key stack-based overflow (EUVD-2026-65291)

A vulnerability has been found in Zephyr Project Zephyr up to 4.4.1 and classified as very critical. The impacted element is the function parse_getconfig_msg of the file subsys/net/lib/ocpp/ocpp_j.c of the component OCPP Client. Performing

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-13215 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-13215 | Zephyr Project up to 4.4.1 ext2 filesystem driver ext2_impl.c ext2_verify_disk_superblock s_log_block_size out-of-bounds write (EUVD-2026-65292)

A vulnerability, which was classified as very critical, was found in Zephyr Project Zephyr up to 4.4.1. The affected element is the function ext2_verify_disk_superblock of the file subsys/fs/ext2/ext2_impl.c of the component ext2 filesystem

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2026-78637 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-78637 | Fdawgs node-poppler up to 9.1.2/10.0.1 Argument Injection src/index.js file_path argument injection (Issue 822 / EUVD-2026-65293)

A vulnerability was found in Fdawgs node-poppler up to 9.1.2/10.0.1. It has been rated as critical. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSepar

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.1%
CVE-2026-78638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-78638 | peerigon unzip-crx/unzip-crx-3 up to 0.2.0 Archive Extraction dist/index.js unzip destination path traversal (Issue 19)

A vulnerability categorized as problematic has been discovered in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dist/index.js of the component Archive Extraction. Executing a manipulation of the

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2026-73624 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73624 | gitpython-developers GitPython up to 3.1.53 Diffable Diffable.diff other/output file inclusion

A vulnerability, which was classified as critical, was found in gitpython-developers GitPython up to 3.1.53. This impacts the function Diffable.diff of the component Diffable. Executing a manipulation of the argument other/output can lead t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2026-66616 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-66616 | 10Web Form Maker Plugin up to 1.15.46 on WordPress cross site scripting

A vulnerability classified as problematic was found in 10Web Form Maker Plugin up to 1.15.46 on WordPress. The impacted element is an unknown function. The manipulation results in cross site scripting. This vulnerability was named CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.2%
CVE-2026-20906 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-20906 | Intel Neural Compressor up to 3.5 protection mechanism

A vulnerability was found in Intel Neural Compressor up to 3.5. It has been declared as problematic. This affects an unknown function. Executing a manipulation can lead to protection mechanism failure. This vulnerability is registered as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.1%
CVE-2026-20908 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-20908 | Intel NPU Driver for Windows Device Drivers race condition

A vulnerability described as critical has been identified in Intel NPU Driver for Windows. This vulnerability affects unknown code of the component Device Drivers. Executing a manipulation can lead to race condition. This vulnerability is h

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 2.1%
CVE-2026-75650 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

132,792 Matches for Magento and 10.0 CVSS: Sizing the Commerce Surface Behind CVE-2026-75650

132,792 Matches for Magento and 10.0 CVSS: Sizing the Commerce Surface Behind CVE-2026-75650 A commerce platform population that maps directly to attacker value CVE-2026-75650 is a template engine vulnerability in Adobe Commerce and Magento

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.6%
CVE-2025-68475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-68475 | fedify-dev fedify up to 1.6.12/1.7.13/1.8.14/1.9.1 docloader.ts redos (GHSA-rchf-xwx2-hm93)

A vulnerability labeled as problematic has been found in fedify-dev fedify up to 1.6.12/1.7.13/1.8.14/1.9.1. This vulnerability affects unknown code of the file packages/fedify/src/runtime/docloader.ts. Such manipulation leads to inefficien

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.1%
CVE-2026-13742 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-13742 | Honeywell IQ MultiAccess up to 28 toctou

A vulnerability described as problematic has been identified in Honeywell IQ MultiAccess up to 28. This vulnerability affects unknown code. The manipulation results in time-of-check time-of-use. This vulnerability is reported as CVE-2026-13

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.8%
CVE-2023-54365 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-54365 | Traefik up to 2.10.4/3.0.0-beta3 resource consumption

A vulnerability was found in Traefik up to 2.10.4/3.0.0-beta3 and classified as problematic. This affects an unknown part. Executing a manipulation can lead to resource consumption. This vulnerability is registered as CVE-2023-54365. It is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2023-33854 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-33854 | IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data authentication replay

A vulnerability was found in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data and classified as problematic. The impacted element is an unknown function. Such manipulation leads to authentication bypass by capture-repla

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.6%
CVE-2023-45796 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-45796 | Pilz PMI v8xx/PASvisu Runtime cross site scripting (VDE-2023-050)

A vulnerability marked as problematic has been reported in Pilz PMI v8xx and PASvisu. Impacted is an unknown function of the component Runtime. Performing a manipulation results in cross site scripting. This vulnerability was named CVE-2023

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2023-45795 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-45795 | Pilz PMI v8xx/PASvisu prior 1.14.1 Builder cross site scripting (VDE-2023-050)

A vulnerability classified as problematic was found in Pilz PMI v8xx and PASvisu. This affects an unknown function of the component Builder. The manipulation results in cross site scripting. This vulnerability is identified as CVE-2023-4579

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2026-49076 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-49076 | Jetimpex JetEngine Plugin up to 3.8.9.1 on WordPress sql injection

A vulnerability labeled as critical has been found in Jetimpex JetEngine Plugin up to 3.8.9.1 on WordPress. Affected is an unknown function. Executing a manipulation can lead to sql injection. This vulnerability is registered as CVE-2026-49

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 1.3%
CVE-2025-65199 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2025-65199 | Windscribe for Linux Desktop App up to 2.18.7 changeMTU adapterName os command injection

A vulnerability described as critical has been identified in Windscribe for Linux Desktop App up to 2.18.7. Impacted is the function changeMTU. Such manipulation of the argument adapterName leads to os command injection. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.4%
CVE-2025-62181 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-62181 | Pegasystems Pega Infinity up to 25.1.0 Authentication Service response discrepancy

A vulnerability identified as problematic has been detected in Pegasystems Pega Infinity up to 25.1.0. This affects an unknown function of the component Authentication Service Handler. This manipulation causes observable response discrepanc

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2025-65823 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-65823 | Meatmeet App on Android hard-coded credentials

A vulnerability, which was classified as critical, was found in Meatmeet App on Android. This issue affects some unknown processing. Such manipulation leads to hard-coded credentials. This vulnerability is traded as CVE-2025-65823. The atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2025-9343 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9343 | ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System Plugin cross site scripting (EUVD-2025-204662)

A vulnerability, which was classified as problematic, was found in ELEXtensions ELEX WordPress HelpDesk &amp;amp; Customer Ticketing System Plugin up to 3.3.4 on WordPress. The impacted element is an unknown function. Executing a manipulati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.7%
CVE-2025-14995 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-14995 | Tenda FH1201 1.2.0.14(408) /goform/SetIpBind sprintf page stack-based overflow (EUVD-2025-204670)

A vulnerability categorized as critical has been discovered in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads to stack-based buffer overflow. This vul

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2026-15442 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-15442 | wolfSSL up to 5.9.2 TLS Shutdown wolfSSL_read use after free (Nessus ID 350849)

A vulnerability was found in wolfSSL up to 5.9.2. It has been classified as critical. This affects the function wolfSSL_read of the component TLS Shutdown. This manipulation causes use after free. This vulnerability appears as CVE-2026-1544

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.1%
CVE-2026-94418 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-94418 | wolfSSL up to 5.9.2 Certificate Signature Verification wolfssl/test.h ProcessPeerCertParse certificate validation (Nessus ID 350850)

A vulnerability labeled as problematic has been found in wolfSSL up to 5.9.2. This issue affects the function ProcessPeerCertParse of the file wolfssl/test.h of the component Certificate Signature Verification. Executing a manipulation can

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2026-77037 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77037 | expressjs multer up to 2.2.0 Disk Storage Engine denial of service (Nessus ID 350851)

A vulnerability has been found in expressjs multer up to 2.2.0 and classified as problematic. Affected is an unknown function of the component Disk Storage Engine. Performing a manipulation results in denial of service. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.1%
CVE-2026-17113 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-17113 | Red Hat OpenShift Container Platform privilege escalation (EUVD-2026-65156 / Nessus ID 350855)

A vulnerability described as very critical has been identified in Red Hat OpenShift Container Platform. The affected element is an unknown function. Executing a manipulation can lead to privilege escalation. This vulnerability is registered

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-89133 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89133 | wolfSSL up to 5.9.2 certificate validation (Nessus ID 350861)

A vulnerability, which was classified as problematic, was found in wolfSSL up to 5.9.2. Affected is an unknown function. Executing a manipulation can lead to improper certificate validation. This vulnerability is registered as CVE-2026-8913

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-8107 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-8107 | OB OceanBase Server prior 3.2.4.9/4.2.1.10/4.2.5/4.3.3.2/4.3.4 exposure of resource (EUVD-2025-22483 / Nessus ID 350910)

A vulnerability classified as critical has been found in OB OceanBase Server. This impacts an unknown function. This manipulation causes exposure of resource. This vulnerability is handled as CVE-2025-8107. The attack can be initiated remot

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-64541 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-64541 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115 / Nessus ID 278346)

A vulnerability classified as problematic was found in Adobe Experience Manager up to 6.5.23. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability is registered as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2025-64545 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-64545 | Adobe Experience Manager up to 6.5.23 URL cross site scripting (apsb25-115 / Nessus ID 278346)

A vulnerability classified as problematic has been found in Adobe Experience Manager up to 6.5.23. This vulnerability affects unknown code of the component URL Handler. This manipulation causes cross site scripting. This vulnerability is re

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-64543 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-64543 | Adobe Experience Manager up to 6.5.23 URL cross site scripting (apsb25-115 / Nessus ID 278346)

A vulnerability marked as problematic has been reported in Adobe Experience Manager up to 6.5.23. Affected by this issue is some unknown functionality of the component URL Handler. The manipulation leads to cross site scripting. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-64544 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-64544 | Adobe Experience Manager up to 6.5.23 URL cross site scripting (apsb25-115 / Nessus ID 278346)

A vulnerability described as problematic has been identified in Adobe Experience Manager up to 6.5.23. This affects an unknown part of the component URL Handler. The manipulation results in cross site scripting. This vulnerability is catalo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2025-64539 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-64539 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115 / Nessus ID 278346)

A vulnerability labeled as problematic has been found in Adobe Experience Manager up to 6.5.23. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting. This vulnerability is tra

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.7%
CVE-2025-64537 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-64537 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115 / Nessus ID 278346)

A vulnerability categorized as problematic has been discovered in Adobe Experience Manager up to 6.5.23. This impacts an unknown function. Such manipulation leads to cross site scripting. This vulnerability is referenced as CVE-2025-64537.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.