🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

369k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
4 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 48 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 1248 9.146 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Linux Microsoft Google Oracle Corporation
● Adobe ● Apple ● Linux ● Microsoft ● Google ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-112026-09-24
≥90 %0484
≥50 %01436
≥10 %016
<10 %30030
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 97.171 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
EPSS 25.8%
CVE-2026-77503 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-77503 | Microsoft Windows up to Server 2025 NTFS out-of-bounds

A vulnerability classified as very critical was found in Microsoft Windows. This affects an unknown part of the component NTFS. Such manipulation leads to out-of-bounds read. This vulnerability is uniquely identified as CVE-2026-77503. Loca

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 21.9%
CVE-2026-28663 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28663 | Google Android 16/16-qpr2/17 Launcher Apps Service LauncherAppsService.java buildIntentSenderForUser privileges management

A vulnerability categorized as very critical has been discovered in Google Android 16/16-qpr2/17. The affected element is the function buildIntentSenderForUser of the file LauncherAppsService.java of the component Launcher Apps Service. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.7%
CVE-2026-72927 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-72927 | Microsoft Windows up to Server 2025 Winsock buffer overflow

A vulnerability was found in Microsoft Windows. It has been declared as very critical. This affects an unknown function of the component Winsock. Executing a manipulation can lead to buffer overflow. The identification of this vulnerability

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 31.9%
CVE-2026-81355 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-81355 | Microsoft Windows up to Server 2025 Virtual Hard Disk VHD Miniport Driver buffer overflow

A vulnerability labeled as critical has been found in Microsoft Windows. This affects an unknown function of the component Virtual Hard Disk VHD Miniport Driver. Executing a manipulation can lead to buffer overflow. This vulnerability appea

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 20.3%
CVE-2026-70575 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-70575 | Microsoft Windows up to Server 2025 Schannel null pointer dereference

A vulnerability, which was classified as critical, was found in Microsoft Windows up to Server 2025. This impacts an unknown function of the component Schannel. Executing a manipulation can lead to null pointer dereference. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 25%
CVE-2026-78523 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-78523 | Microsoft Windows up to Server 2025 DNS use after free

A vulnerability has been found in Microsoft Windows up to Server 2025 and classified as critical. The impacted element is an unknown function of the component DNS. Performing a manipulation results in use after free. This vulnerability is k

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 26.8%
CVE-2026-81352 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-81352 | Microsoft Web Media Extensions 1.0.40831.0 Codecs Library heap-based overflow

A vulnerability was found in Microsoft Web Media Extensions 1.0.40831.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component Codecs Library. The manipulation leads to heap-based buffer overfl

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 21.5%
CVE-2026-81380 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-81380 | Microsoft GitHub Copilot/Visual Studio Code up to 1.136.1 command injection

A vulnerability was found in Microsoft GitHub Copilot and Visual Studio Code up to 1.136.1 and classified as problematic. The impacted element is an unknown function. Such manipulation leads to command injection. This vulnerability is refer

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 21.2%
CVE-2026-28664 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28664 | Google Android up to 17 runtime_image.cc WriteImageToDisk privileges management

A vulnerability identified as very critical has been detected in Google Android 14/15/16/16-qpr2/17. The impacted element is the function WriteImageToDisk of the file runtime_image.cc. This manipulation causes improper privilege management.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.9%
CVE-2026-78510 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-78510 | Microsoft Office buffer overflow (Nessus ID 344562)

A vulnerability has been found in Microsoft Office and classified as critical. Impacted is an unknown function. The manipulation leads to buffer overflow. This vulnerability is listed as CVE-2026-78510. The attack may be initiated remotely.

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 24.5%
CVE-2026-68391 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-68391 | Linux Kernel up to 7.2-rc3 mgmt hci_sync null pointer dereference (Nessus ID 349731)

A vulnerability classified as very critical was found in Linux Kernel up to 6.6.147/6.12.100/6.18.41/7.1.5/7.2-rc3. The affected element is the function hci_sync of the component mgmt. Such manipulation leads to null pointer dereference. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 28.2%
CVE-2026-68188 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-68188 | Linux Kernel up to 7.2-rc4 RFCOMM rfcomm_tty_set_termios use after free (Nessus ID 349731)

A vulnerability was found in Linux Kernel up to 6.6.147/6.12.100/6.18.41/7.1.5/7.2-rc4. It has been rated as very critical. Affected by this vulnerability is the function rfcomm_tty_set_termios of the component RFCOMM. This manipulation cau

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 23.2%
CVE-2026-68293 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-68293 | Linux Kernel up to 6.12.100/6.18.41/7.1.5/7.2-rc4 mlx5 lib/string_helpers.c mlx5_query_mcia buffer overflow (Nessus ID 349731)

A vulnerability was found in Linux Kernel up to 6.12.100/6.18.41/7.1.5/7.2-rc4. It has been declared as critical. The impacted element is the function mlx5_query_mcia of the file lib/string_helpers.c of the component mlx5. Such manipulation

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 27%
CVE-2026-76172 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-76172 | fastify fast-uri up to 2.4.4/3.1.5/4.1.2 Scheme server-side request forgery (Nessus ID 349732)

A vulnerability marked as critical has been reported in fastify fast-uri up to 2.4.4/3.1.5/4.1.2. Affected by this issue is some unknown functionality of the component Scheme Component. This manipulation causes server-side request forgery.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.7%
CVE-2026-75975 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75975 | fastify fast-uri up to 2.4.4/3.1.5/4.1.2 IPv6 Literal Parser input validation (Nessus ID 349732)

A vulnerability identified as problematic has been detected in fastify fast-uri up to 2.4.4/3.1.5/4.1.2. Affected is an unknown function of the component IPv6 Literal Parser. The manipulation leads to improper input validation. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22.1%
CVE-2026-75899 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75899 | fastify fast-uri up to 2.4.4/3.1.5/4.1.2 server-side request forgery (Nessus ID 349732)

A vulnerability has been found in fastify fast-uri up to 2.4.4/3.1.5/4.1.2 and classified as critical. This issue affects some unknown processing. The manipulation leads to server-side request forgery. This vulnerability is uniquely identif

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.3%
CVE-2026-74860 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74860 | Red Hat Enterprise Linux/OpenShift Container Platform SAX bindings attributeDecl double free (Nessus ID 349735)

A vulnerability labeled as very critical has been found in Red Hat Enterprise Linux and OpenShift Container Platform. The impacted element is the function attributeDecl of the component SAX bindings. The manipulation results in double free.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 21.6%
CVE-2026-89846 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89846 | Linux Kernel up to 7.2.4 qla2xxx qla2x00_status_entry rsp_info_len out-of-bounds (Nessus ID 349759)

A vulnerability classified as problematic was found in Linux Kernel up to 7.2.4. The affected element is the function qla2x00_status_entry of the component qla2xxx. Executing a manipulation of the argument rsp_info_len can lead to out-of-bo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 30.3%
CVE-2026-72261 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-72261 | Linux Kernel up to 7.1.4 ASoC snd_sof_update_control num_elems buffer overflow (Nessus ID 349759)

A vulnerability, which was classified as very critical, was found in Linux Kernel up to 6.1.177/6.6.144/6.12.96/6.18.39/7.1.4. Affected is the function snd_sof_update_control of the component ASoC. Such manipulation of the argument num_elem

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 20.5%
CVE-2026-69929 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69929 | Microsoft Windows up to Server 2025 DHCP Server out-of-bounds

A vulnerability was found in Microsoft Windows up to Server 2025 and classified as problematic. Affected is an unknown function of the component DHCP Server. Executing a manipulation can lead to out-of-bounds read. The identification of thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 25.6%
CVE-2026-69803 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69803 | Microsoft Windows up to Server 2025 DHCP Server out-of-bounds

A vulnerability, which was classified as problematic, has been found in Microsoft Windows up to Server 2025. This affects an unknown part of the component DHCP Server. The manipulation leads to out-of-bounds read. This vulnerability is trad

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 32.2%
CVE-2026-86516 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86516 | elenavanengelenmaslova mocknest-serverless 0.9.0 AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management

A vulnerability marked as problematic has been reported in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OID

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.8%
CVE-2026-69443 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69443 | Microsoft Windows 10 1809/Server 2019/Server 2022/Server 2025 Device Health Attestation memory corruption

A vulnerability categorized as problematic has been discovered in Microsoft Windows 10 1809/Server 2019/Server 2022/Server 2025. Affected is an unknown function of the component Device Health Attestation. Executing a manipulation can lead t

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 18.8%
CVE-2026-70124 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-70124 | Microsoft Windows up to Server 2025 DHCP Server out-of-bounds

A vulnerability identified as problematic has been detected in Microsoft Windows up to Server 2025. This issue affects some unknown processing of the component DHCP Server. Performing a manipulation results in out-of-bounds read. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 24.8%
CVE-2026-69930 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69930 | Microsoft Windows up to Server 2025 DHCP Server out-of-bounds

A vulnerability was found in Microsoft Windows up to Server 2025. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component DHCP Server. The manipulation leads to out-of-bounds read.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 28.4%
CVE-2026-70570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-70570 | Microsoft Windows up to Server 2025 Routing/Remote Access Service privileges management

A vulnerability labeled as very critical has been found in Microsoft Windows. This affects an unknown part of the component Routing/Remote Access Service. Such manipulation leads to improper privilege management. This vulnerability is docum

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 25.6%
CVE-2026-69553 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69553 | Microsoft Windows up to Server 2025 Hyper-V privileges management

A vulnerability was found in Microsoft Windows up to Server 2025 and classified as very critical. This issue affects some unknown processing of the component Hyper-V. The manipulation results in improper privilege management. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 30.6%
CVE-2026-69512 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69512 | Microsoft Windows up to Server 2025 Spaceport.sys heap-based overflow

A vulnerability marked as very critical has been reported in Microsoft Windows. This affects an unknown function of the file Spaceport.sys. The manipulation leads to heap-based buffer overflow. This vulnerability is uniquely identified as C

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 5.5%
CVE-2026-4638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-4638 | Paessler PRTG Network Monitor up to 25.4.114 Demo Sensor windowspassword information disclosure (WID-SEC-2026-3565)

A vulnerability was found in Paessler PRTG Network Monitor. It has been declared as problematic. This vulnerability affects unknown code of the component Demo Sensor. Executing a manipulation of the argument windowspassword can lead to info

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.4%
CVE-2026-4637 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-4637 | Paessler PRTG Network Monitor up to 25.4.114 Web Interface welcome.htm cross site scripting (WID-SEC-2026-3565)

A vulnerability was found in Paessler PRTG Network Monitor. It has been classified as problematic. This affects an unknown part of the file welcome.htm of the component Web Interface. Performing a manipulation results in cross site scriptin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.5%
CVE-2025-39965 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2025-39965 | Linux Kernel up to 6.6.108/6.12.49/6.16.9 SPI xfrm_alloc_spi state issue (Nessus ID 271415 / WID-SEC-2025-2268)

A vulnerability classified as critical was found in Linux Kernel up to 6.6.108/6.12.49/6.16.9. Affected is the function xfrm_alloc_spi of the component SPI Handler. Such manipulation leads to state issue. This vulnerability is listed as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 4.3%
CVE-2026-89480 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89480 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nvme-tcp nvme_tcp_recv_data information disclosure (Nessus ID 349761)

A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this vulnerability is the function nvme_tcp_recv_data of the component nvme-tcp. The manipulation leads to inform

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 21.7%
CVE-2026-76444 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-76444 | Cisco Identity Services Engine Software Policy Runtime Repository Table missing authentication (Nessus ID 349789)

A vulnerability identified as problematic has been detected in Cisco Identity Services Engine Software and ISE Passive Identity Connector. This vulnerability affects unknown code of the component Policy Runtime Repository Table. Performing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
EPSS 22.6%
CVE-2026-84391 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Fortinet

CVE-2026-84391 | Fortinet FortiAnalyzer up to 7.6.6 uninitialized pointer (Nessus ID 349790)

A vulnerability classified as critical was found in Fortinet FortiAnalyzer up to 7.6.6. Affected by this vulnerability is an unknown functionality. Such manipulation leads to uninitialized pointer. This vulnerability is listed as CVE-2026-8

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.5%
CVE-2026-84810 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-84810 | claude-world claude-skill-antivirus up to 2.1.3 SKILL.md protection mechanism

A vulnerability marked as problematic has been reported in claude-world claude-skill-antivirus up to 2.1.3. Affected by this vulnerability is an unknown functionality of the file SKILL.md. The manipulation leads to protection mechanism fail

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.8%
CVE-2026-84217 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-84217 | Mamunur Rashid Classified Listing Plugin up to 6.1.1 on WordPress improper authorization (EUVD-2026-69945)

A vulnerability described as problematic has been identified in Mamunur Rashid Classified Listing Plugin up to 6.1.1 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to improper authorization. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 25.8%
CVE-2026-84835 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-84835 | DimaFreund Rentsyst Plugin up to 2.1.2 on WordPress authorization (CNNVD-2026-98894454)

A vulnerability categorized as problematic has been discovered in DimaFreund Rentsyst Plugin up to 2.1.2 on WordPress. Impacted is an unknown function. Such manipulation leads to missing authorization. This vulnerability is traded as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 22%
CVE-2026-80047 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-80047 | Hugging Face Transformers up to 5.8.1 Trust Verification dynamic_module_utils.py GenerativePreTrainedModel.load_custom_generate dropped privileges

A vulnerability was found in Hugging Face Transformers up to 5.8.1. It has been classified as critical. This affects the function GenerativePreTrainedModel.load_custom_generate of the file dynamic_module_utils.py of the component Trust Veri

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23.3%
CVE-2026-59302 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-59302 | VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 Logging log file (EUVD-2026-67188)

A vulnerability has been found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Logging. This manipulation causes sensitive info

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.4%
CVE-2026-53682 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-53682 | Dogtag PKI REST API access control

A vulnerability was found in Dogtag PKI. It has been declared as problematic. This affects an unknown function of the component REST API. Such manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.1%
CVE-2026-81102 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81102 | Dropbox mcp-server-dash Host Validation src/mcp_server_dash.py origin validation

A vulnerability was found in Dropbox mcp-server-dash. It has been rated as problematic. Impacted is an unknown function of the file src/mcp_server_dash.py of the component Host Validation. Performing a manipulation results in origin validat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29%
CVE-2026-54687 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-54687 | DangerBlack n8n-node-sqlite3 up to 0.x SqliteNode SqliteV1.node.ts db_path path traversal (WID-SEC-2026-3067)

A vulnerability, which was classified as problematic, has been found in DangerBlack n8n-node-sqlite3 up to 0.x. Affected by this vulnerability is an unknown functionality of the file nodes/SqliteNode/v1/SqliteV1.node.ts of the component Sql

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 4.3%
CVE-2026-81101 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81101 | Airtable airtable-mcp-cli up to 0.2.4 Configure Command src/cli.ts ConfigureCommand.execute endpoint information disclosure

A vulnerability categorized as problematic has been discovered in Airtable airtable-mcp-cli up to 0.2.4. This vulnerability affects the function ConfigureCommand.execute of the file src/cli.ts of the component Configure Command. Such manipu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 6.6%
CVE-2026-75573 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75573 | MongoDB BI Connector up to 2.14.29 information disclosure (WID-SEC-2026-3066)

A vulnerability, which was classified as problematic, was found in MongoDB BI Connector up to 2.14.29. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to information disclosure. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 31.2%
CVE-2026-43621 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-43621 | SimpleMachines SMF up to 2.1.7 Profile Loader User improper authorization

A vulnerability has been found in SimpleMachines SMF up to 2.1.7 and classified as critical. The impacted element is an unknown function of the component Profile Loader. This manipulation of the argument User causes improper authorization.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 31.8%
CVE-2026-75159 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75159 | MongoDB BI Connector up to 2.14.29 GSSAPI double free (WID-SEC-2026-3066)

A vulnerability was found in MongoDB BI Connector up to 2.14.29. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component GSSAPI. The manipulation leads to double free. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.5%
CVE-2026-81161 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81161 | Drupal Content Moderation Notifications up to 3.8.x privileges management

A vulnerability classified as critical was found in Drupal Content Moderation Notifications up to 3.8.x. This vulnerability affects unknown code. Executing a manipulation can lead to improper privilege management. The identification of this

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.3%
CVE-2026-97818 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
phpipam

CVE-2026-97818 | phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.

phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 4.2%
CVE-2026-97764 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
allauth

CVE-2026-97764 | django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.

django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.1%
CVE-2026-97737 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
muety

CVE-2026-97737 | In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.

In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 3.5%
CVE-2026-97736 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
tinyauth

CVE-2026-97736 | tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.

tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30%
CVE-2026-77997 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77997 | Yootheme Pro Extension 1.0.0-5.0.41 privileges management (EUVD-2026-65472)

A vulnerability described as problematic has been identified in Yootheme Pro Extension 1.0.0-5.0.41. This issue affects some unknown processing. Such manipulation leads to improper privilege management. This vulnerability is documented as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.8%
CVE-2026-58093 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-58093 | FreeBSD Kernel up to p2/p8/p12 TTY TIOCSCTTY ioctl handler race condition (WID-SEC-2026-3034)

A vulnerability was found in FreeBSD Kernel up to p2/p8/p12. It has been declared as very critical. This issue affects the function TIOCSCTTY ioctl handler of the component TTY. Executing a manipulation can lead to race condition. The ident

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 26.8%
CVE-2026-58091 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-58091 | FreeBSD up to p2/p8/p12 Audio use after free (EUVD-2026-66236 / WID-SEC-2026-3034)

A vulnerability labeled as very critical has been found in FreeBSD up to p2/p8/p12. Impacted is an unknown function of the component Audio. The manipulation results in use after free. This vulnerability is cataloged as CVE-2026-58091. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.2%
CVE-2026-58092 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-58092 | FreeBSD Kernel up to p2/p12 mac_do group_is_primary privileges management (EUVD-2026-66237 / WID-SEC-2026-3034)

A vulnerability identified as problematic has been detected in FreeBSD Kernel up to p2/p12. This issue affects the function group_is_primary of the component mac_do. The manipulation leads to improper privilege management. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 23.7%
CVE-2026-58089 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-58089 | FreeBSD hwpmc up to p2/p8/p12 privileges management (EUVD-2026-66234 / WID-SEC-2026-3034)

A vulnerability categorized as problematic has been discovered in FreeBSD hwpmc up to p2/p8/p12. This vulnerability affects unknown code. Executing a manipulation can lead to improper privilege management. This vulnerability is tracked as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.1%
CVE-2026-41707 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-41707 | VMware Spring Security up to 6.5.11/7.0.6/7.1.0 DPoPProofJwtDecoderFactory authentication replay

A vulnerability was found in VMware Spring Security up to 6.5.11/7.0.6/7.1.0. It has been rated as critical. This vulnerability affects unknown code of the component DPoPProofJwtDecoderFactory. Performing a manipulation results in authentic

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23.6%
CVE-2026-58090 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-58090 | FreeBSD Kernel up to p2/p12 Unix Socket use after free (EUVD-2026-66235 / WID-SEC-2026-3034)

A vulnerability was found in FreeBSD Kernel up to p2/p12. It has been rated as very critical. This affects an unknown part of the component Unix Socket. Performing a manipulation results in use after free. This vulnerability is identified a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 23.2%
CVE-2026-77996 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77996 | YOOtheme Pro Extension up to 5.0.41 location cross site scripting (EUVD-2026-65477)

A vulnerability classified as problematic has been found in YOOtheme Pro Extension up to 5.0.41. Impacted is an unknown function. Performing a manipulation of the argument location results in cross site scripting. This vulnerability is repo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.9%
CVE-2026-97735 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
ITFlow

CVE-2026-97735 | ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.

ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.