🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
1 🔴 Critical im Radar
1 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 105 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.868 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-17
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
7.5 HIGH
EPSS 22.4%
CVE-2026-89830 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89830 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 f2fs __allocate_data_block data_blkaddr allocation of resources (WID-SEC-2026-3438)

A vulnerability described as critical has been identified in Linux Kernel up to 6.12.109/6.18.50/7.2.4. Affected by this issue is the function __allocate_data_block of the component f2fs. The manipulation of the argument data_blkaddr result

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 31.5%
CVE-2026-89829 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89829 | Linux Kernel up to 6.18.50/7.2.4 f2fs f2fs_sanity_check_node_footer index infinite loop (WID-SEC-2026-3438)

A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.50/7.2.4. Affected by this vulnerability is the function f2fs_sanity_check_node_footer of the component f2fs. The manipulation of the argument index leads

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.7%
CVE-2026-89828 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89828 | Linux Kernel up to 6.18.50/7.2.4 amdgpu_vram_mgr drm/amdgpu amdgpu_vram_mgr_init free_trees null pointer dereference (WID-SEC-2026-3438)

A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.50/7.2.4. Affected is the function amdgpu_vram_mgr_init of the file drm/amdgpu of the component amdgpu_vram_mgr. Executing a manipulation of the argument free_tre

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.6%
CVE-2026-89826 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89826 | Linux Kernel up to 6.18.50/7.2.4 panthor panthor_fw_read_build_info out-of-bounds (WID-SEC-2026-3438)

A vulnerability identified as very critical has been detected in Linux Kernel up to 6.18.50/7.2.4. This impacts the function panthor_fw_read_build_info of the component panthor. Performing a manipulation results in out-of-bounds read. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22%
CVE-2026-89827 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89827 | Linux Kernel up to 7.2.4 UVD Ring drm/amdgpu amdgpu_uvd_resume uninitialized pointer (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 7.2.4. It has been rated as very critical. The impacted element is the function amdgpu_uvd_resume of the file drm/amdgpu of the component UVD Ring. This manipulation causes uninitialized point

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.4%
CVE-2026-89825 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89825 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 panthor drm/panthor panthor_init_cs_iface/panthor_init_csg_iface memory corruption (WID-SEC-2026-3438)

A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.12.109/6.18.50/7.2.4. This affects the function panthor_init_cs_iface/panthor_init_csg_iface of the file drm/panthor of the component panthor. Such man

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.7%
CVE-2026-93313 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93313 | Freedesktop Poppler 26.07.0 poppler/JBIG2Stream.cc readCodeTableSeg integer overflow (ID 1760 / EUVD-2026-82614)

A vulnerability identified as critical has been detected in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer ove

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.3%
CVE-2026-93456 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-93456 | batiste django-page-cms up to 2.0.13 Admin Views pages/admin/views.py cross site scripting (EUVD-2026-82616)

A vulnerability has been found in batiste django-page-cms up to 2.0.13 and classified as problematic. This vulnerability affects unknown code of the file pages/admin/views.py of the component Admin Views. The manipulation leads to cross sit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-93455 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93455 | batiste django-page-cms up to 2.0.13 permission (EUVD-2026-82615)

A vulnerability classified as problematic was found in batiste django-page-cms up to 2.0.13. Affected by this vulnerability is an unknown functionality. Such manipulation leads to permission issues. This vulnerability is referenced as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.5%
CVE-2026-82980 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82980 | Nextcloud Files Lock up to 33.0.0 WebDAV Plugin improper authorization (EUVD-2026-82617)

A vulnerability, which was classified as critical, has been found in Nextcloud Files Lock up to 33.0.0. Affected by this issue is some unknown functionality of the component WebDAV Plugin. Performing a manipulation results in improper autho

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.6%
CVE-2026-77169 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77169 | Nextcloud Team Folders up to 21.x improper authorization (EUVD-2026-82618)

A vulnerability classified as problematic has been found in Nextcloud Team Folders up to 21.x. Affected is an unknown function. This manipulation causes improper authorization. The identification of this vulnerability is CVE-2026-77169. It

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.1%
CVE-2026-82982 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82982 | Nextcloud Approval up to 3.0.0 etag improper authentication (EUVD-2026-82619)

A vulnerability identified as problematic has been detected in Nextcloud Approval up to 3.0.0. The affected element is an unknown function. Performing a manipulation of the argument etag results in improper authentication. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.7%
CVE-2026-77170 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77170 | Nextcloud Deck up to 1.18.0 Deck config API permission (EUVD-2026-82620)

A vulnerability marked as problematic has been reported in Nextcloud Deck up to 1.18.0. This affects an unknown function of the component Deck config API. The manipulation leads to permission issues. This vulnerability is uniquely identifie

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.2%
CVE-2026-87283 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87283 | Oracle VirtualBox 7.2.16 Core privileges management (Nessus ID 346974)

A vulnerability marked as problematic has been reported in Oracle VirtualBox 7.2.16. This vulnerability affects unknown code of the component Core. The manipulation leads to improper privilege management. This vulnerability is listed as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.7%
CVE-2026-92413 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92413 | Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9 PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dereference (Bug 709610 / Nessus ID 346975)

A vulnerability described as problematic has been identified in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.6%
CVE-2026-92987 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92987 | RazrFalcon roxmltree up to 0.21.1 XML Parsing resource consumption (Nessus ID 346976)

A vulnerability was found in RazrFalcon roxmltree up to 0.21.1. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component XML Parsing. This manipulation causes resource consumption. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.7%
CVE-2026-87278 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87278 | Oracle VirtualBox 7.2.16 Core denial of service (Nessus ID 346977)

A vulnerability was found in Oracle VirtualBox 7.2.16. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Core. Such manipulation leads to denial of service. This vulnerability is uniq

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.6%
CVE-2026-93375 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2026-93375 | Google Chrome up to 153.0.8010.47 Tracing sandbox (Nessus ID 346979)

A vulnerability identified as problematic has been detected in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Tracing. This manipulation causes sandbox issue. This vulnerability appears as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.4%
CVE-2022-44387 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44387 | EyouCMS 1.5.9-UTF8-SP1 Basic Information cross-site request forgery (Issue 29 / EUVD-2022-47330)

A vulnerability described as problematic has been identified in EyouCMS 1.5.9-UTF8-SP1. Impacted is an unknown function of the component Basic Information Component. Such manipulation leads to cross-site request forgery. This vulnerability

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2022-44390 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44390 | EyouCMS 1.5.9-UTF8-SP1 Public Security Record Number cross site scripting (Issue 31 / EUVD-2022-47333)

A vulnerability has been found in EyouCMS 1.5.9-UTF8-SP1 and classified as problematic. The impacted element is an unknown function of the component Public Security Record Number Handler. The manipulation leads to cross site scripting. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.1%
CVE-2022-44389 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44389 | EyouCMS 1.5.9-UTF8-SP1 Edit Admin Profile cross-site request forgery (Issue 30 / EUVD-2022-47332)

A vulnerability, which was classified as problematic, was found in EyouCMS 1.5.9-UTF8-SP1. The affected element is an unknown function of the component Edit Admin Profile Module. Executing a manipulation can lead to cross-site request forge

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.6%
CVE-2022-44384 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44384 | rConfig 3.9.6 PHP File unrestricted upload (Exploit 49783 / EUVD-2022-47327)

A vulnerability was found in rConfig 3.9.6. It has been classified as critical. This issue affects some unknown processing of the component PHP File Handler. Performing a manipulation results in unrestricted upload. This vulnerability is kn

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 20.8%
CVE-2022-44379 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44379 | Automotive Shop Management System 1.0 Master.php?f=delete_service sql injection (EUVD-2022-47324)

A vulnerability was found in Automotive Shop Management System 1.0. It has been declared as critical. This impacts an unknown function of the file /asms/classes/Master.php?f=delete_service. Such manipulation leads to sql injection. This vul

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.6%
CVE-2026-89824 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89824 | Linux Kernel up to 7.2.4 i2c adapter panel-edp.c memory leak (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 6.1.187/6.6.156/6.12.109/6.18.50/7.2.4. It has been classified as critical. Impacted is an unknown function of the file panel-edp.c of the component i2c adapter. The manipulation leads to memo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.3%
CVE-2026-89823 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89823 | Linux Kernel up to 7.2.4 drm drm_dev_register race condition (WID-SEC-2026-3438)

A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 7.2.4. Affected by this issue is the function drm_dev_register of the component drm. This manipulation causes race condition. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 29.1%
CVE-2026-89822 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89822 | Linux Kernel up to 7.3-rc1 i915 i915_pci_probe null pointer dereference (WID-SEC-2026-3438)

A vulnerability identified as problematic has been detected in Linux Kernel up to 7.3-rc1. The affected element is the function i915_pci_probe of the component i915. This manipulation causes null pointer dereference. This vulnerability is h

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 31.1%
CVE-2026-89821 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89821 | Linux Kernel up to 7.2.4 drm/amd/display __is_lut_linear divide by zero (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 7.2.4 and classified as critical. This issue affects the function __is_lut_linear of the file drm/amd/display. Executing a manipulation can lead to divide by zero. This vulnerability is regist

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.5%
CVE-2026-89820 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89820 | Linux Kernel up to 6.18.50/7.2.4 AMD Display drm/amd/display amdgpu_dm_commit_zero_streams locking (WID-SEC-2026-3438)

A vulnerability classified as critical was found in Linux Kernel up to 6.18.50/7.2.4. Affected by this vulnerability is the function amdgpu_dm_commit_zero_streams of the file drm/amd/display of the component AMD Display. The manipulation re

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

DFN-CERT-2026-4940 libvirt: Eine Schwachstelle ermöglicht die Eskalation von Privilegien

sowie Red Hat Enterprise Linux Server in Version AUS 9.2, 9.4 und 9.6 ... Gruppenleiter*in Managed Windows ServerBerlin, Home Office. PSI Software ... Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 24.3%
CVE-2026-66395 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66395 | siyuan-note SiYuan up to 3.7.1 Bazaar Plugin Readme plugin name cross site scripting

A vulnerability, which was classified as problematic, was found in siyuan-note SiYuan up to 3.7.1. This affects an unknown function of the component Bazaar Plugin Readme Handler. The manipulation of the argument plugin name results in cross

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.3%
CVE-2026-65013 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-65013 | Onlook up to 0.2.32 tRPC API projectId/conversationId authorization (423e2e9)

A vulnerability classified as critical was found in Onlook up to 0.2.32. Affected by this vulnerability is the function project.get/member.remove/chat.conversation.delete of the component tRPC API. Such manipulation of the argument projectI

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.5%
CVE-2026-66396 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66396 | siyuan-note SiYuan up to 3.7.1 Gallery/Kanban Cover Images cross site scripting

A vulnerability, which was classified as problematic, has been found in siyuan-note SiYuan up to 3.7.1. The impacted element is an unknown function of the component Gallery/Kanban Cover Images. The manipulation leads to cross site scripting

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.3%
CVE-2026-66005 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66005 | janhq Jan up to 0.8.4 Local API Server cross-domain policy (EUVD-2026-48611)

A vulnerability categorized as problematic has been discovered in janhq Jan up to 0.8.4. This issue affects some unknown processing of the component Local API Server. Executing a manipulation can lead to permissive cross-domain policy with

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.5%
CVE-2026-65606 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-65606 | siyuan-note SiYuan up to 3.7.1 Protocol app/src/layout/Tab.ts innerHTML icon cross site scripting

A vulnerability, which was classified as problematic, has been found in siyuan-note SiYuan up to 3.7.1. The impacted element is the function innerHTML of the file app/src/layout/Tab.ts of the component Protocol Handler. The manipulation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.2%
CVE-2026-63765 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63765 | Chatwoot up to 4.15.x Direct Uploads Controller missing authentication

A vulnerability was found in Chatwoot up to 4.15.x and classified as critical. Affected by this vulnerability is an unknown functionality of the component Direct Uploads Controller. Such manipulation leads to missing authentication. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.9%
CVE-2026-65605 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-65605 | siyuan-note SiYuan up to 3.7.1 Attribute View innerHTML Template column value cross site scripting

A vulnerability labeled as problematic has been found in siyuan-note SiYuan up to 3.7.1. This affects the function innerHTML of the component Attribute View. The manipulation of the argument Template column value results in cross site scrip

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.4%
CVE-2026-50696 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-50696 | Microsoft Windows up to Server 2025 Internet Key Exchange buffer overflow

A vulnerability categorized as critical has been discovered in Microsoft Windows up to Server 2025. Impacted is an unknown function of the component Internet Key Exchange. Executing a manipulation can lead to buffer overflow. This vulnerabi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 28.9%
CVE-2026-59258 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-59258 | immich-app immich up to 3.0.2 id/user access control (EUVD-2026-44755)

A vulnerability classified as critical was found in immich-app immich up to 3.0.2. This impacts an unknown function. The manipulation of the argument id/user results in improper access controls. This vulnerability is cataloged as CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2026-59255 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-59255 | SpecterOps BloodHound up to 9.4.0 Custom-Nodes API authorization (EUVD-2026-44754)

A vulnerability described as critical has been identified in SpecterOps BloodHound up to 9.4.0. The impacted element is an unknown function of the component Custom-Nodes API. Executing a manipulation can lead to missing authorization. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.7%
CVE-2026-56176 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-56176 | Microsoft Windows up to Server 2025 Win32K out-of-bounds

A vulnerability described as problematic has been identified in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component Win32K. Such manipulation leads to out-of-bounds read. This vulnerability is refe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 24.7%
CVE-2026-62240 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-62240 | crewAIInc crewAI up to 1.15.0 URL Validation validate_url server-side request forgery

A vulnerability was found in crewAIInc crewAI up to 1.15.0 and classified as problematic. This vulnerability affects the function validate_url of the component URL Validation. Executing a manipulation can lead to server-side request forgery

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.2%
CVE-2026-62239 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-62239 | Dao-AILab FlashAttention up to 2.8.3.post1 Archive Extraction hopper/setup.py download_and_copy symlink

A vulnerability, which was classified as problematic, was found in Dao-AILab FlashAttention up to 2.8.3.post1. Affected by this issue is the function download_and_copy of the file hopper/setup.py of the component Archive Extraction. Such ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
EPSS 92.7%
CVE-PENDING 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

Steam Windows 0-Day Vulnerability Allows Users to Silently Escalate to Full SYSTEM Privileges

A newly disclosed Windows zero-day affecting the Steam Client Service can reportedly let a standard local user obtain NT AUTHORITY\SYSTEM privileges without administrator credentials, a User Account Control prompt, Steam authentication, or

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 25.1%
CVE-2026-93331 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93331 | GPAC 26.08-DEV RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt size out-of-bounds (Issue 3868 / EUVD-2026-82639)

A vulnerability labeled as critical has been found in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument siz

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.5%
CVE-2026-93468 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93468 | HGiga OAKclouds up to 106 path traversal (EUVD-2026-82642)

A vulnerability was found in HGiga OAKclouds up to 106. It has been rated as problematic. The impacted element is an unknown function. Performing a manipulation results in path traversal. This vulnerability is reported as CVE-2026-93468. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.8%
CVE-2026-93467 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93467 | HGiga OAKclouds-custom_page-4.0 up to 25 deserialization (EUVD-2026-82641)

A vulnerability was found in HGiga OAKclouds-custom_page-2.0, OAKclouds-custom_page-3.0 and OAKclouds-custom_page-4.0 up to 25. It has been classified as critical. Impacted is an unknown function. This manipulation causes deserialization. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.3%
CVE-2026-93371 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93371 | marcopiovanello yt-dlp-web-ui up to v4 generic.go NewGenericDownload params command injection (EUVD-2026-82640)

A vulnerability labeled as critical has been found in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params le

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.7%
CVE-2026-15650 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-15650 | themewant RT Mega Menu Plugin up to 1.5.2 on WordPress Block Attribute pointer_menu_item cross site scripting (EUVD-2026-82643)

A vulnerability was found in themewant RT Mega Menu Plugin up to 1.5.2 on WordPress. It has been declared as problematic. The affected element is an unknown function of the component Block Attribute. Such manipulation of the argument pointe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 24.1%
CVE-2026-14855 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-14855 | themewant RT Mega Menu Plugin up to 1.5.1 on WordPress css[left] cross site scripting (EUVD-2026-82644)

A vulnerability was found in themewant RT Mega Menu Plugin up to 1.5.1 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation of the argument css[left] results in cross site scripting. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 30.4%
CVE-2026-92991 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
WordPress

CVE-2026-92991 | bdthemes Element Pack Addons for Elementor Plugin on WordPress Sigmative API display_id cross site scripting (EUVD-2026-82645)

A vulnerability categorized as problematic has been discovered in bdthemes Element Pack Addons for Elementor Plugin, Elementor Pixel Gallery Addons Plugin, Live Copy Paste for Elementor Plugin, Prime Slider Plugin, Smart Admin Assistant Plu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 30.3%
CVE-2026-87886 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87886 | Acronis Backup Plugin permission

A vulnerability was found in Acronis Backup Plugin, Acronis Backup Extension and Acronis Backup Plugin. It has been classified as very critical. Affected is an unknown function. Performing a manipulation results in permission issues. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.2%
CVE-2026-89819 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89819 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 Plane Degamma LUT Validation drm/amd/display __set_dm_plane_degamma out-of-bounds (WID-SEC-2026-3438)

A vulnerability classified as very critical has been found in Linux Kernel up to 6.12.109/6.18.50/7.2.4. Affected is the function __set_dm_plane_degamma of the file drm/amd/display of the component Plane Degamma LUT Validation. The manipula

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.4%
CVE-2026-89818 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89818 | Linux Kernel up to 7.2.4 Vcn drm/amdgpu/vcn num_buffers integer overflow (WID-SEC-2026-3438)

A vulnerability has been found in Linux Kernel up to 6.1.187/6.6.156/6.12.109/6.18.50/7.2.4 and classified as critical. This vulnerability affects unknown code of the file drm/amdgpu/vcn of the component Vcn. Performing a manipulation of th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 29.7%
CVE-2026-89817 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89817 | Linux Kernel up to 7.3-rc1 gud gud_drv.c gud_connector_add_tv_mode out-of-bounds (WID-SEC-2026-3438)

A vulnerability, which was classified as critical, was found in Linux Kernel up to 7.3-rc1. This affects the function gud_connector_add_tv_mode of the file drivers/gpu/drm/gud/gud_drv.c of the component gud. Such manipulation leads to out-o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 27.7%
CVE-2026-89816 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89816 | Linux Kernel up to 7.3-rc1 drm drm/ complete_signaling memory leak (WID-SEC-2026-3438)

A vulnerability described as problematic has been identified in Linux Kernel up to 7.3-rc1. This impacts the function complete_signaling of the file drm/ of the component drm. Executing a manipulation can lead to memory leak. The identifica

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 31.1%
CVE-2026-89814 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89814 | Linux Kernel up to 6.18.50/7.2.4 drm/amdgpu out-of-bounds (WID-SEC-2026-3438)

A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.50/7.2.4. This affects an unknown function of the component drm/amdgpu. Performing a manipulation results in out-of-bounds read. This vulnerability was nam

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 19.7%
CVE-2026-89815 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89815 | Linux Kernel up to 7.2.4 ttm ttm_pool_restore_and_alloc stack-based overflow (WID-SEC-2026-3438)

A vulnerability labeled as critical has been found in Linux Kernel up to 7.2.4. The impacted element is the function ttm_pool_restore_and_alloc of the component ttm. Such manipulation leads to stack-based buffer overflow. This vulnerability

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.9%
CVE-2026-77164 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77164 | Nextcloud Server up to 32.0.0 Circles server-side request forgery (EUVD-2026-82621)

A vulnerability described as problematic has been identified in Nextcloud Server up to 32.0.0. This impacts an unknown function of the component Circles. The manipulation results in server-side request forgery. This vulnerability was named

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.2%
CVE-2026-68493 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-68493 | Nextcloud Server up to 34.0.0 privileges management (EUVD-2026-82623)

A vulnerability, which was classified as problematic, was found in Nextcloud Server up to 34.0.0. This affects an unknown part. Executing a manipulation can lead to improper privilege management. This vulnerability is tracked as CVE-2026-68

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.6%
CVE-2026-82985 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82985 | Nextcloud up to 31.x Photos privileges management (EUVD-2026-82622)

A vulnerability labeled as problematic has been found in Nextcloud up to 31.x. The impacted element is an unknown function of the component Photos. Executing a manipulation can lead to improper privilege management. This vulnerability is ha

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.