🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

369k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 48 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 1248 9.146 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Linux Microsoft Google Oracle Corporation
● Adobe ● Apple ● Linux ● Microsoft ● Google ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-112026-09-24
≥90 %0484
≥50 %01436
≥10 %016
<10 %30030
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 97.171 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
EPSS 5.5%
CVE-2026-4638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-4638 | Paessler PRTG Network Monitor up to 25.4.114 Demo Sensor windowspassword information disclosure (WID-SEC-2026-3565)

A vulnerability was found in Paessler PRTG Network Monitor. It has been declared as problematic. This vulnerability affects unknown code of the component Demo Sensor. Executing a manipulation of the argument windowspassword can lead to info

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.4%
CVE-2026-4637 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-4637 | Paessler PRTG Network Monitor up to 25.4.114 Web Interface welcome.htm cross site scripting (WID-SEC-2026-3565)

A vulnerability was found in Paessler PRTG Network Monitor. It has been classified as problematic. This affects an unknown part of the file welcome.htm of the component Web Interface. Performing a manipulation results in cross site scriptin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.5%
CVE-2025-39965 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2025-39965 | Linux Kernel up to 6.6.108/6.12.49/6.16.9 SPI xfrm_alloc_spi state issue (Nessus ID 271415 / WID-SEC-2025-2268)

A vulnerability classified as critical was found in Linux Kernel up to 6.6.108/6.12.49/6.16.9. Affected is the function xfrm_alloc_spi of the component SPI Handler. Such manipulation leads to state issue. This vulnerability is listed as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 4.3%
CVE-2026-89480 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89480 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nvme-tcp nvme_tcp_recv_data information disclosure (Nessus ID 349761)

A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this vulnerability is the function nvme_tcp_recv_data of the component nvme-tcp. The manipulation leads to inform

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 21.7%
CVE-2026-76444 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-76444 | Cisco Identity Services Engine Software Policy Runtime Repository Table missing authentication (Nessus ID 349789)

A vulnerability identified as problematic has been detected in Cisco Identity Services Engine Software and ISE Passive Identity Connector. This vulnerability affects unknown code of the component Policy Runtime Repository Table. Performing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
EPSS 22.6%
CVE-2026-84391 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Fortinet

CVE-2026-84391 | Fortinet FortiAnalyzer up to 7.6.6 uninitialized pointer (Nessus ID 349790)

A vulnerability classified as critical was found in Fortinet FortiAnalyzer up to 7.6.6. Affected by this vulnerability is an unknown functionality. Such manipulation leads to uninitialized pointer. This vulnerability is listed as CVE-2026-8

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.5%
CVE-2026-84810 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-84810 | claude-world claude-skill-antivirus up to 2.1.3 SKILL.md protection mechanism

A vulnerability marked as problematic has been reported in claude-world claude-skill-antivirus up to 2.1.3. Affected by this vulnerability is an unknown functionality of the file SKILL.md. The manipulation leads to protection mechanism fail

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.8%
CVE-2026-84217 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-84217 | Mamunur Rashid Classified Listing Plugin up to 6.1.1 on WordPress improper authorization (EUVD-2026-69945)

A vulnerability described as problematic has been identified in Mamunur Rashid Classified Listing Plugin up to 6.1.1 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to improper authorization. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 25.8%
CVE-2026-84835 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-84835 | DimaFreund Rentsyst Plugin up to 2.1.2 on WordPress authorization (CNNVD-2026-98894454)

A vulnerability categorized as problematic has been discovered in DimaFreund Rentsyst Plugin up to 2.1.2 on WordPress. Impacted is an unknown function. Such manipulation leads to missing authorization. This vulnerability is traded as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 22%
CVE-2026-80047 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-80047 | Hugging Face Transformers up to 5.8.1 Trust Verification dynamic_module_utils.py GenerativePreTrainedModel.load_custom_generate dropped privileges

A vulnerability was found in Hugging Face Transformers up to 5.8.1. It has been classified as critical. This affects the function GenerativePreTrainedModel.load_custom_generate of the file dynamic_module_utils.py of the component Trust Veri

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23.3%
CVE-2026-59302 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-59302 | VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 Logging log file (EUVD-2026-67188)

A vulnerability has been found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Logging. This manipulation causes sensitive info

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.4%
CVE-2026-53682 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-53682 | Dogtag PKI REST API access control

A vulnerability was found in Dogtag PKI. It has been declared as problematic. This affects an unknown function of the component REST API. Such manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.1%
CVE-2026-81102 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81102 | Dropbox mcp-server-dash Host Validation src/mcp_server_dash.py origin validation

A vulnerability was found in Dropbox mcp-server-dash. It has been rated as problematic. Impacted is an unknown function of the file src/mcp_server_dash.py of the component Host Validation. Performing a manipulation results in origin validat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29%
CVE-2026-54687 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-54687 | DangerBlack n8n-node-sqlite3 up to 0.x SqliteNode SqliteV1.node.ts db_path path traversal (WID-SEC-2026-3067)

A vulnerability, which was classified as problematic, has been found in DangerBlack n8n-node-sqlite3 up to 0.x. Affected by this vulnerability is an unknown functionality of the file nodes/SqliteNode/v1/SqliteV1.node.ts of the component Sql

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 4.3%
CVE-2026-81101 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81101 | Airtable airtable-mcp-cli up to 0.2.4 Configure Command src/cli.ts ConfigureCommand.execute endpoint information disclosure

A vulnerability categorized as problematic has been discovered in Airtable airtable-mcp-cli up to 0.2.4. This vulnerability affects the function ConfigureCommand.execute of the file src/cli.ts of the component Configure Command. Such manipu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 6.6%
CVE-2026-75573 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75573 | MongoDB BI Connector up to 2.14.29 information disclosure (WID-SEC-2026-3066)

A vulnerability, which was classified as problematic, was found in MongoDB BI Connector up to 2.14.29. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to information disclosure. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 31.2%
CVE-2026-43621 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-43621 | SimpleMachines SMF up to 2.1.7 Profile Loader User improper authorization

A vulnerability has been found in SimpleMachines SMF up to 2.1.7 and classified as critical. The impacted element is an unknown function of the component Profile Loader. This manipulation of the argument User causes improper authorization.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 31.8%
CVE-2026-75159 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75159 | MongoDB BI Connector up to 2.14.29 GSSAPI double free (WID-SEC-2026-3066)

A vulnerability was found in MongoDB BI Connector up to 2.14.29. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component GSSAPI. The manipulation leads to double free. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.5%
CVE-2026-81161 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81161 | Drupal Content Moderation Notifications up to 3.8.x privileges management

A vulnerability classified as critical was found in Drupal Content Moderation Notifications up to 3.8.x. This vulnerability affects unknown code. Executing a manipulation can lead to improper privilege management. The identification of this

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30%
CVE-2026-77997 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77997 | Yootheme Pro Extension 1.0.0-5.0.41 privileges management (EUVD-2026-65472)

A vulnerability described as problematic has been identified in Yootheme Pro Extension 1.0.0-5.0.41. This issue affects some unknown processing. Such manipulation leads to improper privilege management. This vulnerability is documented as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.8%
CVE-2026-58093 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-58093 | FreeBSD Kernel up to p2/p8/p12 TTY TIOCSCTTY ioctl handler race condition (WID-SEC-2026-3034)

A vulnerability was found in FreeBSD Kernel up to p2/p8/p12. It has been declared as very critical. This issue affects the function TIOCSCTTY ioctl handler of the component TTY. Executing a manipulation can lead to race condition. The ident

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 26.8%
CVE-2026-58091 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-58091 | FreeBSD up to p2/p8/p12 Audio use after free (EUVD-2026-66236 / WID-SEC-2026-3034)

A vulnerability labeled as very critical has been found in FreeBSD up to p2/p8/p12. Impacted is an unknown function of the component Audio. The manipulation results in use after free. This vulnerability is cataloged as CVE-2026-58091. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.2%
CVE-2026-58092 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-58092 | FreeBSD Kernel up to p2/p12 mac_do group_is_primary privileges management (EUVD-2026-66237 / WID-SEC-2026-3034)

A vulnerability identified as problematic has been detected in FreeBSD Kernel up to p2/p12. This issue affects the function group_is_primary of the component mac_do. The manipulation leads to improper privilege management. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 23.7%
CVE-2026-58089 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-58089 | FreeBSD hwpmc up to p2/p8/p12 privileges management (EUVD-2026-66234 / WID-SEC-2026-3034)

A vulnerability categorized as problematic has been discovered in FreeBSD hwpmc up to p2/p8/p12. This vulnerability affects unknown code. Executing a manipulation can lead to improper privilege management. This vulnerability is tracked as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.1%
CVE-2026-41707 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-41707 | VMware Spring Security up to 6.5.11/7.0.6/7.1.0 DPoPProofJwtDecoderFactory authentication replay

A vulnerability was found in VMware Spring Security up to 6.5.11/7.0.6/7.1.0. It has been rated as critical. This vulnerability affects unknown code of the component DPoPProofJwtDecoderFactory. Performing a manipulation results in authentic

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23.6%
CVE-2026-58090 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-58090 | FreeBSD Kernel up to p2/p12 Unix Socket use after free (EUVD-2026-66235 / WID-SEC-2026-3034)

A vulnerability was found in FreeBSD Kernel up to p2/p12. It has been rated as very critical. This affects an unknown part of the component Unix Socket. Performing a manipulation results in use after free. This vulnerability is identified a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 23.2%
CVE-2026-77996 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77996 | YOOtheme Pro Extension up to 5.0.41 location cross site scripting (EUVD-2026-65477)

A vulnerability classified as problematic has been found in YOOtheme Pro Extension up to 5.0.41. Impacted is an unknown function. Performing a manipulation of the argument location results in cross site scripting. This vulnerability is repo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.3%
CVE-2025-36939 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-36939 | Google Nest 3.78.518349 MLE stack-based overflow

A vulnerability classified as problematic was found in Google Nest 3.78.518349. The affected element is an unknown function of the component MLE Handler. Such manipulation leads to stack-based buffer overflow. This vulnerability is referenc

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.6%
CVE-2026-73482 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-73482 | phpList up to 3.7.0-RC4 Administrator Deletion lists/admin/admins.php cross-site request forgery

A vulnerability classified as problematic was found in phpList up to 3.7.0-RC4. This affects an unknown function of the file lists/admin/admins.php of the component Administrator Deletion. The manipulation results in cross-site request forg

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.7%
CVE-2024-1753 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-1753 | podman Containerfile symlink (RHSA-2024:2055 / EUVD-2024-0867)

A vulnerability was found in podman. It has been declared as critical. This vulnerability affects unknown code of the component Containerfile Handler. The manipulation results in symlink following. This vulnerability is reported as CVE-2024

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19%
CVE-2026-77914 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77914 | rConfig up to 8.2.12 Export Download Endpoint filename path traversal (EUVD-2026-64952)

A vulnerability categorized as problematic has been discovered in rConfig up to 8.2.12. Affected by this vulnerability is an unknown functionality of the component Export Download Endpoint. Such manipulation of the argument filename leads t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.9%
CVE-2026-39915 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-39915 | TIM Solutions TIM Flow up to 26.0.5 rt/access_token crlf injection

A vulnerability has been found in TIM Solutions TIM Flow up to 26.0.5 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument rt/access_token leads to crlf injection. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.2%
CVE-2026-55648 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-55648 | FreeRDP up to 3.26.9 Color Codec libfreerdp/codec/color.c freerdp_image_copy_from_icon_data memory corruption

A vulnerability was found in FreeRDP up to 3.26.9. It has been declared as critical. Impacted is the function freerdp_image_copy_from_icon_data of the file libfreerdp/codec/color.c of the component Color Codec. Such manipulation leads to me

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.3%
CVE-2026-73039 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73039 | Fosowl Streama up to 2.41.1 Viewing Status Controller ViewingStatusController authorization

A vulnerability described as critical has been identified in Fosowl Streama up to 2.41.1. The affected element is the function ViewingStatusController of the component Viewing Status Controller. Such manipulation leads to authorization bypa

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.1%
CVE-2026-55194 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-55194 | FreeRDP up to 3.26.9 RPC Client rpc_client.c rpc_client_recv_fragment heap-based overflow (Nessus ID 342434)

A vulnerability, which was classified as critical, was found in FreeRDP up to 3.26.9. Affected by this issue is the function rpc_client_recv_fragment of the file libfreerdp/core/gateway/rpc_client.c of the component RPC Client. Executing a

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.6%
CVE-2026-72776 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72776 | Fosowl AgenticSeek up to 2.41.1 BashInterpreter subprocess.Popen os command injection (fc242c7)

A vulnerability, which was classified as critical, was found in Fosowl AgenticSeek up to 2.41.1. The impacted element is the function subprocess.Popen of the component BashInterpreter. Executing a manipulation can lead to os command injecti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.3%
CVE-2026-73479 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73479 | Byron dua-cli up to 2.41.1 TUI interface escape output

A vulnerability was found in Byron dua-cli up to 2.41.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component TUI interface. Performing a manipulation results in escaping of output. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.1%
CVE-2026-94540 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-94540 | MrPear DesktopSMS up to 1.11.0 improper authorization (EUVD-2026-84215)

A vulnerability described as problematic has been identified in MrPear DesktopSMS up to 1.11.0. This affects an unknown part. Executing a manipulation can lead to improper authorization. This vulnerability is tracked as CVE-2026-94540. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.1%
CVE-2026-94426 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-94426 | xuxueli xxl-job up to 3.5.0 /jobgroup/insert Name cross site scripting (EUVD-2026-84245)

A vulnerability identified as problematic has been detected in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the argument Name causes cross site scripting. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.1%
CVE-2026-94626 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-94626 | vllm-project vLLM up to 0.29.0 Completion Endpoint kv_transfer_params tp_size allocation of resources (EUVD-2026-84220 / WID-SEC-2026-3507)

A vulnerability, which was classified as problematic, was found in vllm-project vLLM up to 0.29.0. The affected element is the function kv_transfer_params of the component Completion Endpoint. Such manipulation of the argument tp_size leads

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.7%
CVE-2026-94493 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-94493 | Gigatech PDV5701 1.0.31_240305_112640 WebSocket Service /index.html missing authentication (EUVD-2026-84259)

A vulnerability categorized as very critical has been discovered in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in mi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.3%
CVE-2026-70560 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70560 | Ultimate Fosters Ultimate POS up to 7.2 Account Creation first-name cross site scripting

A vulnerability labeled as problematic has been found in Ultimate Fosters Ultimate POS up to 7.2. This issue affects some unknown processing of the component Account Creation. The manipulation of the argument first-name results in cross sit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.6%
CVE-2026-29036 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-29036 | DaveGamble cJSON up to 1.7.19 JSON Pointer cJSON_Utils.c decode_pointer_inplace path traversal (Nessus ID 335311)

A vulnerability was found in DaveGamble cJSON up to 1.7.19. It has been classified as critical. The affected element is the function decode_pointer_inplace of the file cJSON_Utils.c of the component JSON Pointer. The manipulation leads to p

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.7%
CVE-2026-73038 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73038 | NodeBB up to 4.14.x Emoji Rendering renderEmoji tag.icon.url/tag.name cross site scripting

A vulnerability was found in NodeBB up to 4.14.x and classified as problematic. Affected by this issue is the function renderEmoji of the component Emoji Rendering. Executing a manipulation of the argument tag.icon.url/tag.name can lead to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27%
CVE-2026-73481 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73481 | phpList up to .7.0-RC4 Bounce Rule Deletion Endpoint bouncerules.php tk cross-site request forgery

A vulnerability classified as problematic has been found in phpList up to .7.0-RC4. The impacted element is an unknown function of the file bouncerules.php of the component Bounce Rule Deletion Endpoint. The manipulation of the argument tk

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.9%
CVE-2026-73514 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73514 | PostGIS up to 3.7.0 address_standardizer standardize_address out-of-bounds write (423570b)

A vulnerability has been found in PostGIS up to 3.7.0 and classified as very critical. This impacts the function standardize_address of the component address_standardizer. The manipulation leads to out-of-bounds write. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32%
CVE-2026-73519 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73519 | Wolfsoftwaresystems WolfStack up to 25.9.1 Auth src/auth/mod.rs require_auth hard-coded credentials

A vulnerability was found in Wolfsoftwaresystems WolfStack up to 25.9.1. It has been rated as very critical. Affected by this issue is the function require_auth of the file src/auth/mod.rs of the component Auth Module. The manipulation lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.7%
CVE-2026-53996 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-53996 | NetBSD up to 11 hdaudio hdaudio.c hdafg_detach use after free

A vulnerability has been found in NetBSD up to 11 and classified as very critical. Affected by this vulnerability is the function hdafg_detach of the file sys/dev/hdaudio/hdaudio.c of the component hdaudio. This manipulation causes use afte

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.8%
CVE-2026-57858 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-57858 | calcom cal.com/cal.diy up to 6.2.0 BookingPageTagManager cross site scripting

A vulnerability, which was classified as problematic, was found in calcom cal.com and cal.diy up to 6.2.0. Affected is an unknown function of the component BookingPageTagManager. The manipulation results in cross site scripting. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.3%
CVE-2026-9318 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-9318 | Jazzband Tablib up to 3.9.x HTML Export _html.py export_book HTML injection

A vulnerability classified as problematic was found in Jazzband Tablib up to 3.9.x. Affected by this issue is the function export_book of the file _html.py of the component HTML Export. Executing a manipulation can lead to HTML injection. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23.6%
CVE-2026-5917 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-5917 | libgit2 up to 1.9.0 libssh2 ssh_libssh2.c gen_proto command injection (Nessus ID 335900)

A vulnerability was found in libgit2 up to 1.9.0. It has been rated as problematic. This affects the function gen_proto of the file ssh_libssh2.c of the component libssh2. This manipulation causes command injection. The identification of th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18%
CVE-2026-73036 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73036 | Bash-it up to 3.2.0 Python virtualenv prompt segment __prompt-command requires-python injection

A vulnerability was found in Bash-it up to 3.2.0. It has been classified as problematic. Impacted is the function __prompt-command of the component Python virtualenv prompt segment. The manipulation of the argument requires-python leads to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.2%
CVE-2026-29035 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-29035 | CivetWeb WebSocket Frame read_websocket buffer overflow (4a4f0c95)

A vulnerability was found in CivetWeb and classified as critical. Impacted is the function read_websocket of the component WebSocket Frame Handler. The manipulation results in buffer overflow. This vulnerability is reported as CVE-2026-2903

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 4.3%
CVE-2026-72712 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72712 | Nmap Project up to 7.99 Packet Parsing nselib/packet.lua Packet:parse_options denial of service

A vulnerability classified as problematic has been found in Nmap Project Nmap up to 7.99. Affected is the function Packet:parse_options of the file nselib/packet.lua of the component Packet Parsing. This manipulation causes denial of servic

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.9%
CVE-2026-72713 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72713 | OpenBMB XAgent Workspace File Endpoint /workspace/file file_name path traversal (26f2b6e)

A vulnerability has been found in OpenBMB XAgent and classified as problematic. This vulnerability affects unknown code of the file /workspace/file of the component Workspace File Endpoint. The manipulation of the argument file_name leads t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.5%
CVE-2026-73031 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73031 | GramSearch telegram-search up to 1.2.8 MessageList.vue highlightKeyword cross site scripting

A vulnerability labeled as problematic has been found in GramSearch telegram-search up to 1.2.8. This impacts the function highlightKeyword of the file MessageList.vue. Such manipulation leads to cross site scripting. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23.3%
CVE-2026-73032 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73032 | PapersGPT for Zotero up to 0.6.1 LLM Endpoint views.ts window.eval code injection

A vulnerability classified as critical has been found in PapersGPT for Zotero up to 0.6.1. This impacts the function window.eval of the file views.ts of the component LLM Endpoint. Performing a manipulation results in code injection. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.6%
CVE-2026-72742 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72742 | Stanford NLP DSPy up to 3.3.0b1 Image/Audio output field adapters image.py encode_image/encode_audio url injection

A vulnerability labeled as problematic has been found in Stanford NLP DSPy up to 3.3.0b1. This vulnerability affects the function encode_image/encode_audio of the file image.py of the component Image/Audio output field adapters. Executing a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.1%
CVE-2026-69117 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-69117 | NetBox Labs up to 4.5.8 WritableNestedSerializer injection

A vulnerability was found in NetBox Labs NetBox up to 4.5.8 and classified as problematic. This affects an unknown part of the component WritableNestedSerializer. The manipulation results in injection. This vulnerability is cataloged as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30%
CVE-2026-69119 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-69119 | Taubyte Tau up to 1.1.10 Services/Auth HTTP Service authorization

A vulnerability, which was classified as critical, has been found in Taubyte Tau up to 1.1.10. Impacted is an unknown function of the component Services/Auth HTTP Service. This manipulation causes missing authorization. The identification o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.