Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-05 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-72323 | Linux Kernel up to 7.2-rc2 IGMP igmp_gq_start_timer use after free
A vulnerability was found in Linux Kernel up to 6.6.144/6.12.96/6.18.39/7.1.4/7.2-rc2. It has been rated as critical. Affected by this vulnerability is the function igmp_gq_start_timer of the component IGMP. The manipulation leads to use af
CVE-2026-19478 | GitLab up to 18.11.10/19.0.7/19.1.5/19.2.3 GraphQL Directive authorization (WID-SEC-2026-2882)
A vulnerability was found in GitLab up to 18.11.10/19.0.7/19.1.5/19.2.3. It has been declared as critical. This affects an unknown part of the component GraphQL Directive. The manipulation results in missing authorization. This vulnerabilit
CVE-2026-34884 | Apache SkyWalking MCP up to 0.1.0 set_skywalking_url injection (EUVD-2026-60572)
A vulnerability was found in Apache SkyWalking MCP up to 0.1.0. It has been classified as critical. Impacted is the function set_skywalking_url. The manipulation leads to injection. This vulnerability is documented as CVE-2026-34884. The at
CVE-2026-72667 | Elastic Kibana up to 8.19.19/9.4.4 Observability log analysis feature allocation of resources
A vulnerability, which was classified as problematic, has been found in Elastic Kibana up to 8.19.19/9.4.4. Affected is an unknown function of the component Observability log analysis feature. Performing a manipulation results in allocation
CVE-2026-68476 | Linux Kernel up to 7.2-rc3 ipvs __ip_vs_get_out_rt allocation of resources (WID-SEC-2026-2852)
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 6.6.144/6.12.96/6.18.39/7.1.4/7.2-rc3. Impacted is the function __ip_vs_get_out_rt of the component ipvs. Executing a manipulation can lead to allocatio
CVE-2026-73841 | OpenChoreo up to 1.1.x API Handlers exec.go project improper authorization (EUVD-2026-58507)
A vulnerability described as critical has been identified in OpenChoreo up to 1.1.x. Affected by this issue is some unknown functionality of the file internal/openchoreo-api/api/handlers/exec.go of the component API Handlers. The manipulati
CVE-2026-47837 | Spring Cloud Config up to 3.1.14/4.2.8/4.3.4/5.0.4 Monitor Endpoint missing authentication (WID-SEC-2026-2952)
A vulnerability classified as problematic has been found in Spring Cloud Config up to 3.1.14/4.2.8/4.3.4/5.0.4. The impacted element is an unknown function of the component Monitor Endpoint. Performing a manipulation results in missing auth
CVE-2026-47836 | VMware Spring Cloud Config up to 3.1.14/4.2.8/4.3.4/5.0.4 SVN Cloning toctou (WID-SEC-2026-2952)
A vulnerability described as problematic has been identified in VMware Spring Cloud Config up to 3.1.14/4.2.8/4.3.4/5.0.4. The affected element is an unknown function of the component SVN Cloning. Such manipulation leads to time-of-check ti
CVE-2026-80428 | ILIAS-eLearning ILIAS up to 9.21/10.9/11.2 Shibboleth Logout shib_logout.php unserialize deserialization (EUVD-2026-66602)
A vulnerability described as critical has been identified in ILIAS-eLearning ILIAS up to 9.21/10.9/11.2. This affects the function unserialize of the file components/ILIAS/AuthShibboleth/resources/shib_logout.php of the component Shibboleth
CVE-2026-78367 | Red Hat Enterprise Linux Tarball Mode injection
A vulnerability categorized as very critical has been discovered in Red Hat Enterprise Linux, Hardened Images and OpenShift Container Platform. This affects an unknown part of the component Tarball Mode. Such manipulation leads to injection
CVE-2026-65644 | Rocket.Chat up to 7.10.14/8.7.0 Omnichannel Queue InquireSidePanelItem.tsx dangerouslySetInnerHTML Name injection (EUVD-2026-63806)
A vulnerability labeled as critical has been found in Rocket.Chat up to 7.10.14/8.7.0. The affected element is the function dangerouslySetInnerHTML of the file InquireSidePanelItem.tsx of the component Omnichannel Queue. The manipulation of
CVE-2026-65645 | Rocket.Chat up to 8.7.x Meteor DDP getThreadsList/getThreadMessages rid/tmid improper authorization (EUVD-2026-63805)
A vulnerability identified as problematic has been detected in Rocket.Chat up to 8.7.x. Impacted is the function getThreadsList/getThreadMessages of the component Meteor DDP. The manipulation of the argument rid/tmid leads to improper autho
CVE-2026-69419 | Microsoft Azure Data Manager for Energy integer overflow (EUVD-2026-63625)
A vulnerability was found in Microsoft Azure Data Manager for Energy and classified as critical. This affects an unknown function. Executing a manipulation can lead to integer overflow. This vulnerability is handled as CVE-2026-69419. The a
CVE-2026-75618 | TP-Link Tapo C100/Tapo C101 RTSP service null pointer dereference
A vulnerability identified as critical has been detected in TP-Link Tapo C100 and Tapo C101. This vulnerability affects unknown code of the component RTSP service. Performing a manipulation results in null pointer dereference. This vulnerab
CVE-2026-18824 | IBM AIX/PowerVM VIOS os command injection
A vulnerability categorized as very critical has been discovered in IBM AIX and PowerVM VIOS. This affects an unknown function. Executing a manipulation can lead to os command injection. This vulnerability is registered as CVE-2026-18824. I
CVE-2026-14978 | HashiCorp go-slug up to 0.18.2 Unicode Normalization privileges management (WID-SEC-2026-2978)
A vulnerability categorized as problematic has been discovered in HashiCorp go-slug up to 0.18.2. This affects an unknown part of the component Unicode Normalization. The manipulation results in improper privilege management. This vulnerabi
CVE-2026-14514 | IBM Reliable Scalable Cluster Technology 3.0 allocation of resources
A vulnerability was found in IBM Reliable Scalable Cluster Technology 3.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to allocation of resources. This vuln
CVE-2026-75619 | TP-Link Tapo C100/Tapo C101 RTSP Service heap-based overflow
A vulnerability labeled as critical has been found in TP-Link Tapo C100 and Tapo C101. This issue affects some unknown processing of the component RTSP Service. Executing a manipulation can lead to heap-based buffer overflow. This vulnerabi
CVE-2026-19582 | GNU Binutils PE File rsrc_print_name stack-based overflow (EUVD-2026-63197)
This issue seems to be a false positive. Please check the referenced sources and consider omitting this entry entirely. Weiterlesen
CVE-2026-15316 | TP-Link Tapo C200 Configuration Service input validation
A vulnerability marked as critical has been reported in TP-Link Tapo C200. Impacted is an unknown function of the component Configuration Service. Performing a manipulation results in improper input validation. This vulnerability is reporte
CVE-2026-71106 | Oracle Hospitality OPERA Property Services up to 5.6.28.1 Opera Servlet access control
A vulnerability categorized as critical has been discovered in Oracle Hospitality OPERA Property Services up to 5.6.28.1. Affected by this vulnerability is an unknown functionality of the component Opera Servlet. Executing a manipulation ca
CVE-2026-70724 | Oracle MySQL Cluster up to 8.0.48/8.4.11/9.7.2 Cluster General access control (WID-SEC-2026-2903)
A vulnerability marked as critical has been reported in Oracle MySQL Cluster up to 8.0.48/8.4.11/9.7.2. This affects an unknown part of the component Cluster General. The manipulation leads to improper access controls. This vulnerability is
CVE-2026-15315 | TP-Link Tapo C200 improper authentication
A vulnerability, which was classified as very critical, was found in TP-Link Tapo C200. Affected is an unknown function. Such manipulation leads to improper authentication. This vulnerability is uniquely identified as CVE-2026-15315. The at
Magento-Backdoor „StyleSmuggler“: Ungepatchte Zero-Day trifft Adobe Commerce
LONDON (IT BOLTWISE) – Eine ungesicherte Zero-Day-Lücke in Magento Open Source und Adobe Commerce wird offenbar aktiv ausgenutzt. Die Sicherheitsfirma Sansec nennt die Schwachstelle „StyleSmuggler“ und beschreibt eine Kette, die ohne Login
CVE-2026-66782 | Red Hat Advanced Cluster Management for Kubernetes Submariner Operator improper authorization (EUVD-2026-61066)
A vulnerability classified as very critical was found in Red Hat Advanced Cluster Management for Kubernetes. This issue affects some unknown processing of the component Submariner Operator. Executing a manipulation can lead to improper auth
CVE-2026-17084 | Python up to 3.15.x stringprep in_table_b2 interpretation conflict (WID-SEC-2026-2924)
A vulnerability labeled as critical has been found in Python up to 3.15.x. This affects the function in_table_b2 of the component stringprep. Such manipulation leads to interpretation conflict. This vulnerability is documented as CVE-2026-1
CVE-2026-74234 | Legora prior 2026-08-14 Front-Matter Parser eval cross site scripting
This issue was flagged as a false-positive. Please consult the sources mentioned and consider not using this entry at all. Weiterlesen
CVE-2026-66783 | Red Hat Advanced Cluster Management for Kubernetes submariner-operator permission (EUVD-2026-61067)
A vulnerability categorized as very critical has been discovered in Red Hat Advanced Cluster Management for Kubernetes. This impacts an unknown function of the component submariner-operator. Executing a manipulation can lead to permission i
CVE-2026-72532 | Joomla! Project Joomla Extension up to 4.0.0/5.4.7/6.0.0/6.1.2 Category improper authorization (WID-SEC-2026-2926)
A vulnerability classified as problematic was found in Joomla! Project Joomla Extension up to 4.0.0/5.4.7/6.0.0/6.1.2. This impacts an unknown function of the component Category. The manipulation results in improper authorization. This vuln
CVE-2026-73337 | Joomla Extension up to 4.0.0/5.4.6/6.0.0/6.1.2 state issue (WID-SEC-2026-2926)
A vulnerability was found in Joomla Extension up to 4.0.0/5.4.6/6.0.0/6.1.2. It has been classified as critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in state issue. This vulnerabilit
CVE-2026-73373 | Joomla! Project Joomla! CMS/Joomla! Framework Filesystem package up to 5.4.7/6.1.2 SHTML file unrestricted upload (WID-SEC-2026-2926)
A vulnerability, which was classified as critical, was found in Joomla! Project Joomla! CMS and Joomla! Framework Filesystem package up to 5.4.7/6.1.2. This affects an unknown function of the component SHTML file Handler. The manipulation r
CVE-2026-71574 | Joomla! Project Joomla! CMS Extension up to 5.4.6/6.1.2 Webservice Endpoint improper authorization (WID-SEC-2026-2926)
A vulnerability has been found in Joomla! Project Joomla! CMS Extension up to 5.4.6/6.1.2 and classified as problematic. This impacts an unknown function of the component Webservice Endpoint. This manipulation causes improper authorization.
CVE-2026-19500 | Brainstorm Force SureForms Plugin up to 2.1.2 Entries resource consumption
A vulnerability described as problematic has been identified in Brainstorm Force SureForms Plugin up to 2.1.2. This impacts an unknown function of the component Entries. Executing a manipulation can lead to resource consumption. The identif
CVE-2026-73371 | Joomla! Project Joomla Extension up to 5.4.7/6.1.2 Batch Copy improper authorization (WID-SEC-2026-2926)
A vulnerability, which was classified as critical, has been found in Joomla! Project Joomla Extension up to 5.4.7/6.1.2. The impacted element is an unknown function of the component Batch Copy. The manipulation leads to improper authorizati
CVE-2026-66795 | Red Hat Multicluster Engine for Kubernetes managedcluster-import-controller certificate validation
A vulnerability was found in Red Hat Multicluster Engine for Kubernetes. It has been rated as problematic. Affected by this issue is some unknown functionality of the component managedcluster-import-controller. This manipulation causes impr
CVE-2026-66781 | Red Hat Advanced Cluster Management for Kubernetes Submariner Operator information disclosure (EUVD-2026-61065)
A vulnerability described as problematic has been identified in Red Hat Advanced Cluster Management for Kubernetes. This affects an unknown part of the component Submariner Operator. Such manipulation leads to information disclosure. This v
CVE-2022-43250 | Libde265 1.0.8 Video File fallback-motion.cc put_qpel_0_0_fallback_16 heap-based overflow (Issue 346 / EUVD-2022-46294)
A vulnerability, which was classified as critical, has been found in Libde265 1.0.8. This issue affects the function put_qpel_0_0_fallback_16 of the file fallback-motion.cc of the component Video File Handler. The manipulation leads to heap
CVE-2022-43249 | Libde265 1.0.8 Video File fallback-motion.cc put_epel_hv_fallback heap-based overflow (Issue 345 / EUVD-2022-46293)
A vulnerability classified as critical was found in Libde265 1.0.8. This vulnerability affects the function put_epel_hv_fallback of the file fallback-motion.cc of the component Video File Handler. Executing a manipulation can lead to heap-b
CVE-2022-43248 | Libde265 1.0.8 Video File fallback-motion.cc put_weighted_pred_avg_16_fallback heap-based overflow (Issue 349 / EUVD-2022-46292)
A vulnerability classified as critical has been found in Libde265 1.0.8. This affects the function put_weighted_pred_avg_16_fallback of the file fallback-motion.cc of the component Video File Handler. Performing a manipulation results in he
CVE-2022-43245 | Libde265 1.0.8 Video File sao.cc apply_sao_internal memory corruption (Issue 352 / EUVD-2022-46289)
A vulnerability described as critical has been identified in Libde265 1.0.8. Affected by this issue is the function apply_sao_internal of the file sao.cc of the component Video File Handler. Such manipulation leads to memory corruption. Thi
CVE-2022-43244 | Libde265 1.0.8 Video File fallback-motion.cc put_qpel_fallback heap-based overflow (Issue 342 / EUVD-2022-46288)
A vulnerability marked as critical has been reported in Libde265 1.0.8. Affected by this vulnerability is the function put_qpel_fallback of the file fallback-motion.cc of the component Video File Handler. This manipulation causes heap-based
CVE-2022-43243 | Libde265 1.0.8 Video File sse-motion.cc ff_hevc_put_weighted_pred_avg_8_sse heap-based overflow (Issue 339 / EUVD-2022-46287)
A vulnerability labeled as critical has been found in Libde265 1.0.8. Affected is the function ff_hevc_put_weighted_pred_avg_8_sse of the file sse-motion.cc of the component Video File Handler. The manipulation results in heap-based buffer
CVE-2022-43242 | Libde265 1.0.8 Video File motion.cc mc_luma heap-based overflow (Issue 340 / EUVD-2022-46286)
A vulnerability identified as critical has been detected in Libde265 1.0.8. This impacts the function mc_luma of the file motion.cc of the component Video File Handler. The manipulation leads to heap-based buffer overflow. This vulnerabilit
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advi
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
Broadcom schließt kritische Lücke in VMware Workstation und Fusion (CVE-2026-59346)
LONDON (IT BOLTWISE) – Broadcom hat Sicherheitsupdates für VMware Workstation und VMware Fusion veröffentlicht und schließt dabei zwei Lücken, darunter einen kritischen Integer-Overflow mit CVSS 9,3. Unter bestimmten Bedingungen kann ein An
Elementor Pro WordPress Flaw Exploited to Upload Webshells and Execute Commands
A critical vulnerability in the Elementor Pro WordPress plugin is being actively exploited to upload malicious PHP files and execute commands remotely on the affected websites. The vulnerability, tracked as CVE-2026-32475, affects the Ele
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026
Switchvox Vulnerability Triggers Active Exploitation Risk
Sangoma Switchvox CVE-2026-9586 is a serious unauthenticated SQL injection flaw that can lead to remote code execution, and Horizon3 says it has already seen real-world exploitation attempts. The issue was patched in Switchvox 8.4.0.2, ma
CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft
CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. This article has been indexed from Security Archives – TechRepublic Read the original article: C
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. This article has been indexed from SecurityWeek Read the original article: Elementor Pro WordP
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o
PaperCut-Schwachstellen: Angreifer stehlen Anmeldedaten an Schulen und Universitäten
LONDON (IT BOLTWISE) – Angreifer nutzen neu gemeldete PaperCut-Schwachstellen, um an Schulen und Universitäten in den USA und Europa Zugangsdaten auszuspähen. In den Beobachtungen wurden CVE-2026-81578 und CVE-2026-82078 für Authentifizieru
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect