Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-17 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
Pixel-Update schnell installieren: Hacker nutzen Sicherheitslücke bereits aus
Google hat ein neues Update für seine Pixel-Smartphones veröffentlicht. Neben praktischen Funktionen enthält die Aktualisierung aber auch einen wichtigen Fix für eine aktiv ausgenutzte Sicherheitslücke. Was dazu bekannt ist. Weiterlesen
Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek. Weiter
CVE-2025-10072 | Portabilis i-Educar up to 2.10 enturmar access control (EUVD-2025-27098)
A vulnerability marked as critical has been reported in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing a manipulation results in improper access controls.
CVE-2025-65024 | Portabilis i-Educar up to 2.10.0 agenda_admin_cad.php cod_agenda sql injection (GHSA-6c8p-xqcv-rghx)
A vulnerability has been found in Portabilis i-Educar up to 2.10.0 and classified as critical. This vulnerability affects unknown code of the file ieducar/intranet/agenda_admin_cad.php. The manipulation of the argument cod_agenda leads to s
CVE-2025-65023 | Portabilis i-Educar up to 2.10.0 funcionario_vinculo_cad.php cod_funcionario_vinculo sql injection (GHSA-8rv6-x8h9-fjfc)
A vulnerability, which was classified as critical, was found in Portabilis i-Educar up to 2.10.0. This affects an unknown part of the file ieducar/intranet/funcionario_vinculo_cad.php. Executing a manipulation of the argument cod_funcionari
[UPDATE] [mittel] vim: Schwachstelle ermöglicht Codeausführung
Ein Angreifer kann eine Schwachstelle in vim ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[UPDATE] [hoch] vim: Schwachstelle ermöglicht Codeausführung
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in vim ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
CVE-2022-44401 | Online Tours & Travels Management System 1.0 /tour/admin/file.php unrestricted upload (EUVD-2022-47344)
A vulnerability described as very critical has been identified in Online Tours &amp; Travels Management System 1.0. This affects an unknown function of the file /tour/admin/file.php. The manipulation results in unrestricted upload. This
CVE-2022-44400 | oretnom23 Purchase Order Management System 1.0 ?page=system_info unrestricted upload (EUVD-2022-47343)
A vulnerability was found in oretnom23 Purchase Order Management System 1.0. It has been declared as very critical. Impacted is an unknown function of the file /purchase_order/admin/?page=system_info. Such manipulation leads to unrestricted
CVE-2022-44399 | Poultry Farm Management System 1.0 category.php del sql injection (EUVD-2022-47342)
A vulnerability marked as critical has been reported in Poultry Farm Management System 1.0. The impacted element is an unknown function of the file /Redcock-Farm/farm/category.php. The manipulation of the argument del leads to sql injection
CVE-2022-44393 | oretnom23 Sanitization Management System 1.0 view_service ID sql injection (EUVD-2022-47336)
A vulnerability was found in oretnom23 Sanitization Management System 1.0. It has been rated as critical. The affected element is an unknown function of the file /php-sms/admin/?page=services/view_service. This manipulation of the argument
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed. Check Point addressed CVE-2026-91843 (CVSS score of 9.8), a critical vulnerability in i
Root-Sicherheitslücke gefährdet Check Point Security Management and Log Servers
Ein Sicherheitsupdate schließt eine kritische Schadcode-Schwachstelle in Check Point Security Management and Log Servers. Weiterlesen
CVE-2026-89008 | Bookit Plugin 2.5.1/2.5.4.1/2.6.0.1 on WordPress information disclosure (EUVD-2026-82681)
A vulnerability labeled as problematic has been found in Bookit Plugin 2.5.1/2.5.4.1/2.6.0.1 on WordPress. Impacted is an unknown function. Executing a manipulation can lead to information disclosure. This vulnerability appears as CVE-2026-
CVE-2026-90978 | Filter Gallery Plugin up to 1.1.4 on WordPress AJAX handlers nonce access control (EUVD-2026-82682)
A vulnerability was found in Filter Gallery Plugin up to 1.1.4 on WordPress. It has been rated as problematic. This affects an unknown part of the component AJAX handlers. This manipulation of the argument nonce causes improper access contr
CVE-2026-79713 | Breeze Cache Plugin up to 2.5.14 on WordPress request smuggling (EUVD-2026-82684)
A vulnerability classified as problematic was found in Breeze Cache Plugin up to 2.5.14 on WordPress. This impacts an unknown function. Such manipulation leads to http request smuggling. This vulnerability is uniquely identified as CVE-2026
CVE-2026-90984 | Generate PDF using Contact Form 7 Plugin up to 4.2.1 on WordPress server-side request forgery (EUVD-2026-82683)
A vulnerability was found in Generate PDF using Contact Form 7 Plugin up to 4.2.1 on WordPress. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to server-side request
CVE-2026-86800 | Hide My WP Ghost Plugin up to 7.0.10 on WordPress protection mechanism (EUVD-2026-82686)
A vulnerability, which was classified as problematic, was found in Hide My WP Ghost Plugin up to 7.0.10 on WordPress. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to protection mechanism fail
CVE-2026-86796 | Hide My WP Ghost Plugin up to 7.0.10 on WordPress protection mechanism (EUVD-2026-82685)
A vulnerability described as problematic has been identified in Hide My WP Ghost Plugin up to 7.0.10 on WordPress. The impacted element is an unknown function. The manipulation results in protection mechanism failure. This vulnerability is
CVE-2026-90977 | Clean Login Plugin up to 1.18 on WordPress comparison (EUVD-2026-82689)
A vulnerability was found in Clean Login Plugin up to 1.18 on WordPress. It has been classified as problematic. The affected element is an unknown function. Performing a manipulation results in incorrect comparison. This vulnerability is id
CVE-2026-90976 | Clean Login Plugin up to 1.18 on WordPress Registration access control (EUVD-2026-82688)
A vulnerability, which was classified as problematic, has been found in Clean Login Plugin up to 1.18 on WordPress. Affected is an unknown function of the component Registration Handler. Performing a manipulation results in improper access
CVE-2026-88994 | All Bootstrap Blocks Plugin up to 1.3.31 on WordPress Block Attribute php file inclusion (EUVD-2026-82687)
A vulnerability classified as critical has been found in All Bootstrap Blocks Plugin up to 1.3.31 on WordPress. This affects an unknown function of the component Block Attribute. This manipulation causes improper control of filename for inc
CVE-2026-18911 | Zohocorp ManageEngine DataSecurity Plus prior 6310 input validation (EUVD-2026-82655)
A vulnerability described as critical has been identified in Zohocorp ManageEngine DataSecurity Plus. Affected by this issue is some unknown functionality. Such manipulation leads to improper input validation. This vulnerability is uniquely
Agentic AI Security: Credentials and Permissions Define the Blast Radius
Agentic AI Security: Credentials and Permissions Define the Blast Radius Prompt injection can't be patched away. Three 2026 agentic AI incidents show that credentials and permissions decide the damage. The trick matters less than the a
CVE-2026-67636 | Microsoft SQL Server out-of-bounds
A vulnerability categorized as very critical has been discovered in Microsoft SQL Server. This impacts an unknown function. The manipulation results in out-of-bounds read. This vulnerability is reported as CVE-2026-67636. The attack can be
CVE-2026-67631 | Microsoft SQL Server 2017/2019/2022/2025 heap-based overflow
A vulnerability was found in Microsoft SQL Server 2017/2019/2022/2025. It has been rated as very critical. This affects an unknown function. The manipulation leads to heap-based buffer overflow. This vulnerability is documented as CVE-2026-
CVE-2026-67378 | Microsoft SQL Server 2019/2022/2025 improper authorization
A vulnerability classified as very critical has been found in Microsoft SQL Server 2019/2022/2025. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper authorization. This vulnerability w
CVE-2026-82069 | MongoDB Server up to 8.3.8 Query Statistics Serialization information disclosure
A vulnerability classified as problematic was found in MongoDB Server up to 8.3.8. This affects an unknown function of the component Query Statistics Serialization. The manipulation results in information disclosure. This vulnerability is c
CVE-2026-82066 | MongoDB up to 7.0.40/8.0.29/8.3.8 Query Planning out-of-bounds (Nessus ID 344375)
A vulnerability was found in MongoDB up to 7.0.40/8.0.29/8.3.8. It has been classified as problematic. Affected is an unknown function of the component Query Planning. Performing a manipulation results in out-of-bounds read. This vulnerabil
CVE-2026-82059 | MongoDB Server up to 7.0.40/8.0.29/8.3.8 Index Key Generation resource consumption
A vulnerability, which was classified as problematic, has been found in MongoDB Server up to 7.0.40/8.0.29/8.3.8. The affected element is an unknown function of the component Index Key Generation. The manipulation leads to resource consumpt
CVE-2026-82060 | MongoDB up to 7.0.40/8.0.29/8.3.8 Change Stream data query logic injection
A vulnerability, which was classified as problematic, was found in MongoDB up to 7.0.40/8.0.29/8.3.8. The impacted element is an unknown function of the component Change Stream. The manipulation results in improper neutralization of special
CVE-2026-82065 | MongoDB Server up to 7.0.40/8.0.29/8.3.8 Storage Engine Integration Layer assertion
A vulnerability categorized as critical has been discovered in MongoDB Server up to 7.0.40/8.0.29/8.3.8. Affected is an unknown function of the component Storage Engine Integration Layer. Executing a manipulation can lead to reachable asser
CVE-2026-82058 | MongoDB Server up to 7.0.40/8.0.29/8.3.8 JSON Schema Validation uncaught exception
A vulnerability classified as problematic was found in MongoDB Server up to 7.0.40/8.0.29/8.3.8. Impacted is an unknown function of the component JSON Schema Validation. Executing a manipulation can lead to uncaught exception. This vulnerab
CVE-2026-87285 | Oracle VirtualBox 7.2.16 Core privileges management (Nessus ID 346968)
A vulnerability categorized as problematic has been discovered in Oracle VirtualBox 7.2.16. Affected by this vulnerability is an unknown functionality of the component Core. Such manipulation leads to improper privilege management. This vul
CVE-2026-87276 | Oracle VirtualBox 7.2.16 Core privileges management (Nessus ID 346969)
A vulnerability classified as problematic was found in Oracle VirtualBox 7.2.16. The affected element is an unknown function of the component Core. Such manipulation leads to improper privilege management. This vulnerability is documented a
CVE-2026-87270 | Oracle VM VirtualBox 7.2.16 Core privileges management (Nessus ID 346971)
A vulnerability was found in Oracle VM VirtualBox 7.2.16. It has been declared as very critical. This impacts an unknown function of the component Core. The manipulation results in improper privilege management. This vulnerability was named
CVE-2026-87267 | Oracle VM VirtualBox 7.2.16 Core privileges management (Nessus ID 346970)
A vulnerability classified as problematic has been found in Oracle VM VirtualBox 7.2.16. This affects an unknown part of the component Core. The manipulation leads to improper privilege management. This vulnerability is documented as CVE-20
CVE-2026-87279 | Oracle VirtualBox 7.2.16 Core privileges management (Nessus ID 346972)
A vulnerability classified as problematic has been found in Oracle VirtualBox 7.2.16. Impacted is an unknown function of the component Core. This manipulation causes improper privilege management. This vulnerability is registered as CVE-202
CVE-2026-87269 | Oracle VM VirtualBox 7.2.16 Core privileges management (Nessus ID 346973)
A vulnerability was found in Oracle VM VirtualBox 7.2.16. It has been classified as problematic. This affects an unknown function of the component Core. The manipulation leads to improper privilege management. This vulnerability is uniquely
CVE-2026-84578 | Apple macOS up to 15.7/26.6/26 sandbox (EUVD-2026-78101)
A vulnerability was found in Apple macOS up to 15.7/26.6/26 and classified as very critical. Affected is an unknown function. The manipulation results in sandbox issue. This vulnerability is cataloged as CVE-2026-84578. The attack may be la
CVE-2026-76409 | Cisco Nexus Dashboard up to 4.2.1 path traversal (EUVD-2026-81115)
A vulnerability was found in Cisco Nexus Dashboard. It has been classified as very critical. Affected is an unknown function. The manipulation leads to path traversal. This vulnerability is traded as CVE-2026-76409. It is possible to initia
CVE-2026-20350 | Cisco ThousandEyes Virtual Appliance up to 5.2.0 Web-based Management Interface os command injection (EUVD-2026-81117)
A vulnerability classified as very critical has been found in Cisco ThousandEyes Virtual Appliance up to 5.2.0. Affected by this issue is some unknown functionality of the component Web-based Management Interface. Performing a manipulation
CVE-2026-20340 | Cisco Secure Firewall Management Center up to 10.0.1 deserialization (EUVD-2026-81116)
A vulnerability marked as very critical has been reported in Cisco Secure Firewall Management Center. Affected is an unknown function. This manipulation causes deserialization. This vulnerability is tracked as CVE-2026-20340. The attack is
CVE-2026-20360 | Cisco Nexus Dashboard up to 4.2.1 information disclosure (EUVD-2026-81127)
A vulnerability was found in Cisco Nexus Dashboard and classified as problematic. This impacts an unknown function. Executing a manipulation can lead to information disclosure. This vulnerability appears as CVE-2026-20360. The attack may be
CVE-2026-20336 | Cisco Secure Adaptive Security Appliance Software resource control (EUVD-2026-81119)
A vulnerability, which was classified as very critical, was found in Cisco Secure Adaptive Security Appliance Software, Secure Firewall Management Center and Secure Firewall Threat Defense Software. This issue affects some unknown processin
CVE-2026-20344 | Cisco Secure Firewall Management Center up to 10.0.1 Web-based Management Interface sql injection (EUVD-2026-81129)
A vulnerability has been found in Cisco Secure Firewall Management Center and classified as problematic. This affects an unknown function of the component Web-based Management Interface. Performing a manipulation results in sql injection. T
CVE-2026-20276 | Cisco IOS XR Software up to 26.2.101 Control Flow Management insufficient control flow management (EUVD-2026-70203)
A vulnerability was found in Cisco IOS XR Software. It has been classified as critical. This affects an unknown part of the component Control Flow Management. Performing a manipulation results in insufficient control flow management. This v
CVE-2026-84971 | MongoDB libmongocrypt up to 1.20.3 assertion (Nessus ID 342821 / WID-SEC-2026-3182)
A vulnerability classified as problematic was found in MongoDB libmongocrypt up to 1.20.3. Affected by this issue is some unknown functionality. The manipulation results in reachable assertion. This vulnerability is cataloged as CVE-2026-84
CVE-2026-20124 | Cisco IOS XE Software up to 17.18.2 SNMP Subsystem denial of service
A vulnerability was found in Cisco IOS XE Software. It has been rated as critical. This affects an unknown function of the component SNMP Subsystem. Performing a manipulation results in denial of service. This vulnerability is known as CVE-
CVE-2026-11803 | Autodesk Revit prior 2026.5.0/2027.2.0 PDF file out-of-bounds
A vulnerability categorized as critical has been discovered in Autodesk Revit. This vulnerability affects unknown code of the component PDF file Handler. The manipulation results in out-of-bounds read. This vulnerability is known as CVE-202
CVE-2026-20301 | Cisco IOS XE Software/IOS XMCP denial of service
A vulnerability categorized as critical has been discovered in Cisco IOS XE Software and IOS. Affected by this issue is some unknown functionality of the component XMCP. The manipulation results in denial of service. This vulnerability is k
CVE-2026-89841 | Linux Kernel up to 6.18.50/7.2.4 f2fs redirty_blocks use after free (WID-SEC-2026-3438)
A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4 and classified as very critical. The impacted element is the function redirty_blocks of the component f2fs. The manipulation results in use after free. This vulnerability is cata
CVE-2026-89840 | Linux Kernel up to 7.2.4 f2fs __clone_blkaddrs input validation (WID-SEC-2026-3438)
A vulnerability has been found in Linux Kernel up to 7.2.4 and classified as very critical. The affected element is the function __clone_blkaddrs of the component f2fs. The manipulation leads to improper input validation. This vulnerability
CVE-2026-89839 | Linux Kernel up to 6.6.156/6.12.109/6.18.50/7.2.4 f2fs f2fs_xattr_advise_set privileges management (WID-SEC-2026-3438)
A vulnerability marked as very critical has been reported in Linux Kernel up to 6.6.156/6.12.109/6.18.50/7.2.4. This vulnerability affects the function f2fs_xattr_advise_set of the component f2fs. This manipulation causes improper privilege
CVE-2026-89838 | Linux Kernel up to 7.2.4 F2FS recover_inode/recover_dentry buffer overflow (WID-SEC-2026-3438)
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 7.2.4. Impacted is the function recover_inode/recover_dentry of the component F2FS. Executing a manipulation can lead to buffer overflow. This vulnerabi
CVE-2026-89837 | Linux Kernel up to 6.18.50/7.2.4 f2fs find_in_level release of resource (WID-SEC-2026-3438)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.50/7.2.4. This affects the function find_in_level of the component f2fs. The manipulation results in missing release of resource. This vulnerability is known as C
CVE-2026-26950 | Dell SmartFabric Manager up to 2.2.0 improper authentication (EUVD-2026-81676)
A vulnerability categorized as critical has been discovered in Dell SmartFabric Manager up to 2.2.0. This issue affects some unknown processing. Executing a manipulation can lead to improper authentication. This vulnerability appears as CVE
CVE-2026-80355 | Dell OpenManage Server Administrator up to 11.1.0.2 cross-site request forgery (EUVD-2026-81578)
A vulnerability was found in Dell OpenManage Server Administrator. It has been rated as problematic. This affects an unknown part. This manipulation causes cross-site request forgery. This vulnerability is handled as CVE-2026-80355. The att
CVE-2026-28326 | SolarWinds Access Rights Manager hard-coded credentials (EUVD-2026-82317)
A vulnerability labeled as critical has been found in SolarWinds Access Rights Manager. Affected is an unknown function. Executing a manipulation can lead to hard-coded credentials. This vulnerability is registered as CVE-2026-28326. It is
CVE-2026-43815 | Apple macOS up to 14.8.7/15.7.7/26.5 afpfs buffer overflow (EUVD-2026-77899)
A vulnerability marked as very critical has been reported in Apple macOS up to 14.8.7/15.7.7/26.5. This vulnerability affects unknown code of the component afpfs. This manipulation causes buffer overflow. This vulnerability appears as CVE-2