Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-15 | 2026-09-28 |
|---|---|---|
| ≥90 % | 0 | 299 |
| ≥50 % | 0 | 958 |
| ≥10 % | 0 | 3 |
| <10 % | 300 | 250 |
CVE-2025-64541 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115 / Nessus ID 278346)
A vulnerability classified as problematic was found in Adobe Experience Manager up to 6.5.23. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability is registered as CVE-20
CVE-2025-64545 | Adobe Experience Manager up to 6.5.23 URL cross site scripting (apsb25-115 / Nessus ID 278346)
A vulnerability classified as problematic has been found in Adobe Experience Manager up to 6.5.23. This vulnerability affects unknown code of the component URL Handler. This manipulation causes cross site scripting. This vulnerability is re
CVE-2025-64543 | Adobe Experience Manager up to 6.5.23 URL cross site scripting (apsb25-115 / Nessus ID 278346)
A vulnerability marked as problematic has been reported in Adobe Experience Manager up to 6.5.23. Affected by this issue is some unknown functionality of the component URL Handler. The manipulation leads to cross site scripting. This vulner
CVE-2025-64544 | Adobe Experience Manager up to 6.5.23 URL cross site scripting (apsb25-115 / Nessus ID 278346)
A vulnerability described as problematic has been identified in Adobe Experience Manager up to 6.5.23. This affects an unknown part of the component URL Handler. The manipulation results in cross site scripting. This vulnerability is catalo
CVE-2025-64539 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115 / Nessus ID 278346)
A vulnerability labeled as problematic has been found in Adobe Experience Manager up to 6.5.23. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting. This vulnerability is tra
CVE-2025-64537 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115 / Nessus ID 278346)
A vulnerability categorized as problematic has been discovered in Adobe Experience Manager up to 6.5.23. This impacts an unknown function. Such manipulation leads to cross site scripting. This vulnerability is referenced as CVE-2025-64537.
CVE-2026-101263 | Ziroom ZHOME A0101 1.0.1.0 set_online_client mac command injection (EUVD-2026-88571)
A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0 and classified as very critical. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection.
CVE-2026-18417 | Zephyr Project up to 4.4.1 BSD Socket Layer sockets_inet.c user_data null pointer dereference (EUVD-2026-88573)
A vulnerability marked as critical has been reported in Zephyr Project Zephyr up to 4.4.1. The affected element is the function zsock_accepted_cb/zsock_received_cb/zsock_connected_cb/zsock_close_ctx of the file subsys/net/lib/sockets/socket
CVE-2026-101264 | Ziroom ZHOME A0101 1.0.1.0 set_passwd password1 command injection (EUVD-2026-88572)
A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. It has been classified as very critical. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. T
CVE-2026-18747 | Zephyr Project up to 4.4.1 Serial Transport serial_util.c mcumgr_serial_extract_len out-of-bounds (EUVD-2026-88575)
A vulnerability labeled as problematic has been found in Zephyr Project Zephyr up to 4.4.1. Impacted is the function mcumgr_serial_extract_len of the file subsys/mgmt/mcumgr/transport/src/serial_util.c of the component Serial Transport. Suc
CVE-2026-18746 | Zephyr Project up to 4.4.x LwM2M lwm2m_message_handling.c parse_write_op null pointer dereference (EUVD-2026-88574)
A vulnerability identified as critical has been detected in Zephyr Project Zephyr up to 4.4.x. This issue affects the function parse_write_op of the file subsys/net/lib/lwm2m/lwm2m_message_handling.c of the component LwM2M. This manipulatio
CVE-2026-101265 | Intelbras TIP 125i 4.3.35/4.3.41 Básico Page sensitive information in source (EUVD-2026-88576)
A vulnerability was found in Intelbras TIP 125i 4.3.35/4.3.41. It has been declared as problematic. The affected element is an unknown function of the component Básico Page. Such manipulation leads to inclusion of sensitive information in s
CVE-2025-34423 | MailEnable up to 10.53 MEAIAU.DLL uncontrolled search path (EUVD-2025-202442)
A vulnerability was found in MailEnable up to 10.53. It has been declared as problematic. This issue affects some unknown processing in the library MEAIAU.DLL. Executing a manipulation can lead to uncontrolled search path. The identificatio
CVE-2025-12046 | Lenovo App Store/Browser prior 9.0.2530.1027 uncontrolled search path
A vulnerability was found in Lenovo App Store and Browser. It has been declared as problematic. Affected by this issue is some unknown functionality. Such manipulation leads to uncontrolled search path. This vulnerability is referenced as C
CVE-2025-13184 | TOTOLINK AX1800 cstecgi.cgi?action=telnet missing authentication (EUVD-2025-202419)
A vulnerability classified as critical has been found in TOTOLINK AX1800. This affects an unknown part of the file /cgi-bin/cstecgi.cgi?action=telnet. The manipulation leads to missing authentication. This vulnerability is traded as CVE-202
CVE-2023-53757 | Linux Kernel up to 6.2.2 irq-mvebu-gicp of_irq_find_parent reference count (EUVD-2023-60071 / WID-SEC-2025-2756)
A vulnerability has been found in Linux Kernel up to 6.2.2 and classified as critical. Affected is the function of_irq_find_parent of the component irq-mvebu-gicp. This manipulation causes improper update of reference count. The identificat
CVE-2023-53755 | Linux Kernel up to 6.1.15/6.2.2 PTDMA Driver pt_issue_pending null pointer dereference (EUVD-2023-60073 / WID-SEC-2025-2756)
A vulnerability was found in Linux Kernel up to 6.1.15/6.2.2. It has been rated as critical. This affects the function pt_issue_pending of the component PTDMA Driver. This manipulation causes null pointer dereference. This vulnerability is
CVE-2023-53753 | Linux Kernel up to 6.1.15/6.2.2 out-of-bounds (EUVD-2023-60075 / Nessus ID 277669)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.15/6.2.2. This impacts an unknown function. The manipulation results in out-of-bounds read. This vulnerability was named CVE-2023-53753. The attack needs
CVE-2023-53754 | Linux Kernel up to 6.3.1 scsi lpfc_sli4_pci_mem_setup null pointer dereference (EUVD-2023-60074 / Nessus ID 277771)
A vulnerability was found in Linux Kernel up to 6.3.1. It has been declared as critical. The impacted element is the function lpfc_sli4_pci_mem_setup of the component scsi. The manipulation results in null pointer dereference. This vulnerab
CVE-2023-53752 | Linux Kernel up to 6.1.53/6.4.15/6.5.2 net net/core/skbuff.c kmalloc_reserve integer overflow (EUVD-2023-60076 / Nessus ID 277785)
A vulnerability classified as critical was found in Linux Kernel up to 6.1.53/6.4.15/6.5.2. Affected by this issue is the function kmalloc_reserve of the file net/core/skbuff.c of the component net. The manipulation results in integer overf
CVE-2023-53751 | Linux Kernel up to 6.1.27/6.2.14/6.3.1 cifs hostname use after free (EUVD-2023-60077 / Nessus ID 297065)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.27/6.2.14/6.3.1. This affects the function TCP_Server_Info::hostname of the component cifs. The manipulation leads to use after free. This vulnerabi
CVE-2025-13339 | Hippoo Mobile App for WooCommerce Plugin up to 1.7.1 on WordPress template_redirect path traversal (EUVD-2025-202393)
A vulnerability classified as problematic was found in Hippoo Mobile App for WooCommerce Plugin up to 1.7.1 on WordPress. The impacted element is the function template_redirect. The manipulation results in path traversal. This vulnerability
CVE-2025-61809 | Adobe ColdFusion up to 2021.22/2023.16/2025.4 Security Feature input validation (apsb25-105 / Nessus ID 278173)
A vulnerability identified as critical has been detected in Adobe ColdFusion up to 2021.22/2023.16/2025.4. This vulnerability affects unknown code of the component Security Feature. Performing a manipulation results in improper input valida
CVE-2025-64897 | Adobe ColdFusion up to 2021.22/2023.16/2025.4 access control (apsb25-105)
A vulnerability was found in Adobe ColdFusion up to 2021.22/2023.16/2025.4 and classified as critical. This impacts an unknown function. Executing a manipulation can lead to improper access controls. This vulnerability is tracked as CVE-202
CVE-2025-61808 | Adobe ColdFusion up to 2021.22/2023.16/2025.4 unrestricted upload (apsb25-105 / Nessus ID 278173)
A vulnerability classified as critical was found in Adobe ColdFusion up to 2021.22/2023.16/2025.4. Impacted is an unknown function. The manipulation results in unrestricted upload. This vulnerability was named CVE-2025-61808. The attack may
CVE-2025-64896 | Adobe Creative Cloud Desktop up to 6.4.0.361 File temp file (apsb25-120)
A vulnerability categorized as problematic has been discovered in Adobe Creative Cloud Desktop up to 6.4.0.361. Impacted is an unknown function of the component File Handler. Executing a manipulation can lead to creation of temporary file i
CVE-2025-64447 | Fortinet FortiWeb up to 8.0.1 HTTP cookie validation (FG-IR-25-945)
A vulnerability classified as critical was found in Fortinet FortiWeb up to 7.0.11/7.2.11/7.4.10/7.6.5/8.0.1. The affected element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to cookies without va
CVE-2025-64899 | Adobe Acrobat Reader up to 25.001.20982 File Parser out-of-bounds (apsb25-119)
A vulnerability classified as critical has been found in Adobe Acrobat Reader up to 20.005.30793/20.005.30803/24.001.30264/24.001.30273/25.001.20982. The impacted element is an unknown function of the component File Parser. This manipulatio
CVE-2025-64787 | Adobe Acrobat Reader up to 25.001.20982 Security Feature signature verification (apsb25-119)
A vulnerability labeled as problematic has been found in Adobe Acrobat Reader up to 20.005.30793/20.005.30803/24.001.30264/24.001.30273/25.001.20982. Affected by this issue is some unknown functionality of the component Security Feature. Su
CVE-2025-64785 | Adobe Acrobat Reader up to 25.001.20982 untrusted search path (apsb25-119)
A vulnerability categorized as problematic has been discovered in Adobe Acrobat Reader up to 20.005.30793/20.005.30803/24.001.30264/24.001.30273/25.001.20982. Affected is an unknown function. The manipulation results in untrusted search pat
CVE-2025-64786 | Adobe Acrobat Reader up to 25.001.20982 Security Feature signature verification (apsb25-119)
A vulnerability identified as problematic has been detected in Adobe Acrobat Reader up to 20.005.30793/20.005.30803/24.001.30264/24.001.30273/25.001.20982. Affected by this vulnerability is an unknown functionality of the component Security
CVE-2025-64661 | Microsoft Windows up to Server 2025 Shell race condition (EUVD-2025-202207)
A vulnerability has been found in Microsoft Windows and classified as critical. The affected element is an unknown function of the component Shell. The manipulation leads to race condition. This vulnerability is traded as CVE-2025-64661. An
CVE-2025-64471 | Fortinet FortiWeb up to 8.0.1 password hash instead of password for authentication (FG-IR-25-984)
A vulnerability described as problematic has been identified in Fortinet FortiWeb up to 7.0.11/7.2.11/7.4.10/7.6.4/8.0.1. The impacted element is an unknown function. Executing a manipulation can lead to use of password hash instead of pass
CVE-2025-62455 | Microsoft Windows up to Server 2019 Message Queuing input validation (EUVD-2025-202231)
A vulnerability was found in Microsoft Windows. It has been classified as critical. Affected is an unknown function of the component Message Queuing. This manipulation causes improper input validation. The identification of this vulnerabili
CVE-2025-62221 | Microsoft Windows up to Server 2025 Cloud Files Mini Filter Driver use after free (EUVD-2025-202200)
A vulnerability has been found in Microsoft Windows and classified as critical. This affects an unknown function of the component Cloud Files Mini Filter Driver. The manipulation leads to use after free. This vulnerability is uniquely ident
CVE-2025-64156 | Fortinet FortiVoice up to 7.2.1 sql injection (FG-IR-25-362 / EUVD-2025-202278)
A vulnerability marked as critical has been reported in Fortinet FortiVoice up to 7.2.1. The affected element is an unknown function. Performing a manipulation results in sql injection. This vulnerability is identified as CVE-2025-64156. Th
CVE-2025-60024 | Fortinet FortiVoice up to 7.0.7/7.2.2 path traversal (FG-IR-25-812)
A vulnerability was found in Fortinet FortiVoice up to 7.0.7/7.2.2. It has been classified as critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in path traversal. This vulnerability is k
CVE-2025-14188 | UGREEN DH2100+ up to 5.3.0.251125 nas_svr /v1/file/backup/create handler_file_backup_create path command injection (EUVD-2025-201598 / CNNVD-202512-827)
A vulnerability was found in UGREEN DH2100+ up to 5.3.0.251125. It has been rated as critical. This impacts the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. The manipulation of the argumen
CVE-2025-14136 | Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 up to 1.2.07.001 mod_form.so clientsname_0 stack-based overflow (EUVD-2025-201548)
A vulnerability categorized as critical has been discovered in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function RE2000v2Repeater_get_w
CVE-2025-14187 | UGREEN DH2100+ up to 5.3.0.251125 nas_svr /v1/file/backup/create handler_file_backup_create path buffer overflow (EUVD-2025-201596 / CNNVD-202512-829)
A vulnerability was found in UGREEN DH2100+ up to 5.3.0.251125. It has been declared as critical. This affects the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. Executing a manipulation of
CVE-2025-14133 | Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 up to 1.2.07.001 mod_form.so AP_get_wireless_clientlist_setClientsName clientsname_0 stack-based overflow (EUVD-2025-201546)
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been classified as critical. Affected by this vulnerability is the function AP_get_wirele
CVE-2025-14135 | Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 up to 1.2.07.001 mod_form.so AP_get_wired_clientlist_setClientsName clientsname_0 stack-based overflow (EUVD-2025-201547)
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been rated as critical. This affects the function AP_get_wired_clientlist_setClientsName
CVE-2023-53750 | Linux Kernel up to 6.3.12/6.4.3 pinctrl num_configs out-of-bounds (EUVD-2023-60078 / WID-SEC-2025-2756)
A vulnerability classified as critical was found in Linux Kernel up to 6.3.12/6.4.3. The impacted element is the function num_configs of the component pinctrl. Executing a manipulation can lead to out-of-bounds read. This vulnerability is h
CVE-2023-53749 | Linux Kernel up to 6.2.15 clear_page_64.S clear_user_rep_good memory corruption (EUVD-2023-60079 / WID-SEC-2025-2756)
It seems this issue is a false-positive. Please confirm the sources provided and consider disregarding this entry. Weiterlesen
CVE-2023-53748 | Linux Kernel up to 6.1.29/6.3.3 queue_setup out-of-bounds (EUVD-2023-60080 / Nessus ID 297090)
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.29/6.3.3. The affected element is the function queue_setup. Performing a manipulation results in out-of-bounds read. This vulnerability is known as CVE-2023-537
CVE-2023-53747 | Linux Kernel up to 6.3.3 vc_screen.c vcs_write use after free (EUVD-2023-60081 / Nessus ID 277787)
A vulnerability marked as critical has been reported in Linux Kernel up to 6.3.3. This impacts the function vcs_write of the file drivers/tty/vt/vc_screen.c. Performing a manipulation results in use after free. This vulnerability is known a
CVE-2023-53746 | Linux Kernel up to 6.2.9 vfio_ap null pointer dereference (EUVD-2023-60082 / WID-SEC-2025-2756)
A vulnerability labeled as critical has been found in Linux Kernel up to 5.4.239/5.10.176/5.15.105/6.1.22/6.2.9. This affects the function vfio_ap. Such manipulation leads to null pointer dereference. This vulnerability is traded as CVE-202
CVE-2023-53745 | Linux Kernel up to 6.2.4 uml_parse_vector_ifspec return value (EUVD-2023-60083 / WID-SEC-2025-2756)
A vulnerability was found in Linux Kernel up to 6.2.4. It has been rated as critical. Impacted is the function uml_parse_vector_ifspec. The manipulation leads to unchecked return value. This vulnerability is documented as CVE-2023-53745. Th
CVE-2023-53744 | Linux Kernel up to 6.3.1 soc wkup_m3_ipc_get reference count (EUVD-2023-60084 / WID-SEC-2025-2756)
A vulnerability was found in Linux Kernel up to 5.10.179/5.15.110/6.1.27/6.2.14/6.3.1. It has been classified as critical. This vulnerability affects the function wkup_m3_ipc_get of the component soc. Performing a manipulation results in im
CVE-2023-53743 | Linux Kernel up to 6.1.52/6.4.15/6.5.2 PCI release_resource privilege escalation (EUVD-2023-60085 / Nessus ID 277782)
A vulnerability classified as critical was found in Linux Kernel up to 6.1.52/6.4.15/6.5.2. This impacts the function release_resource of the component PCI. Executing a manipulation can lead to privilege escalation. The identification of th
CVE-2022-50630 | Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2 mm handle_userfault use after free (Nessus ID 297090 / WID-SEC-2025-2756)
A vulnerability marked as critical has been reported in Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2. The affected element is the function handle_userfault of the component mm. This manipulation causes use after free. This vulnerabilit
CVE-2023-53742 | Linux Kernel up to 6.1.27/6.2.14/6.3.1 read_instrumented_memory privilege escalation (EUVD-2023-60086 / Nessus ID 277645)
A vulnerability was found in Linux Kernel up to 6.1.27/6.2.14/6.3.1. It has been declared as problematic. Affected by this issue is the function read_instrumented_memory. Such manipulation leads to privilege escalation. This vulnerability i
CVE-2022-50628 | Linux Kernel up to 6.1.15/6.2.2 iosys_map_clear uninitialized pointer (Nessus ID 277773 / WID-SEC-2025-2756)
A vulnerability was found in Linux Kernel up to 6.1.15/6.2.2. It has been classified as critical. Affected by this vulnerability is the function iosys_map_clear. This manipulation causes uninitialized pointer. This vulnerability is register
CVE-2022-50627 | Linux Kernel up to 6.1.15/6.2.2 ath11k null pointer dereference (Nessus ID 277630 / WID-SEC-2025-2756)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.15/6.2.2. Impacted is an unknown function of the component ath11k. The manipulation results in null pointer dereference. This vulnerability is known as CVE-2022-50
CVE-2022-50626 | Linux Kernel up to 6.1.1 dvb_usb_adapter_init num_adapters_initalized reference count (Nessus ID 277776 / WID-SEC-2025-2756)
A vulnerability was found in Linux Kernel up to 6.1.1. It has been declared as critical. This issue affects the function dvb_usb_adapter_init. Executing a manipulation of the argument num_adapters_initalized can lead to improper update of r
CVE-2022-50624 | Linux Kernel up to 6.0.6 netsec_register_mdio reference count (WID-SEC-2025-2756)
A vulnerability described as critical has been identified in Linux Kernel up to 4.19.263/5.4.222/5.10.152/5.15.76/6.0.6. Affected is the function netsec_register_mdio. Executing a manipulation can lead to improper update of reference count.
CVE-2022-50625 | Linux Kernel up to 6.1.1 UART Interface memory corruption (Nessus ID 277774 / WID-SEC-2025-2756)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.1. This affects an unknown function of the component UART Interface. Executing a manipulation can lead to memory corruption. This vulnerability is tracke
CVE-2022-50622 | Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2 ext4 ext4_fc_record_modified_inode memory leak (Nessus ID 277739 / WID-SEC-2025-2756)
A vulnerability identified as critical has been detected in Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2. The impacted element is the function ext4_fc_record_modified_inode of the component ext4. This manipulation causes memory leak. T
CVE-2022-50621 | Linux Kernel up to 6.0.2 dm denial of service (Nessus ID 277780 / WID-SEC-2025-2756)
A vulnerability classified as critical has been found in Linux Kernel up to 6.0.2. This affects an unknown function of the component dm. Performing a manipulation results in denial of service. This vulnerability was named CVE-2022-50621. Th
CVE-2022-50617 | Linux Kernel up to 5.15.85/6.0.15/6.1.1 memory leak (Nessus ID 277784 / WID-SEC-2025-2756)
A vulnerability described as critical has been identified in Linux Kernel up to 5.15.85/6.0.15/6.1.1. The impacted element is an unknown function. Such manipulation leads to memory leak. This vulnerability is uniquely identified as CVE-2022