🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

375k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-11: 257 Nov 25 2025-12: 426 2026-01: 431 Jan 26 2026-02: 417 2026-03: 649 Mär 26 2026-04: 574 2026-05: 682 Mai 26 2026-06: 941 2026-07: 1327 Jul 26 2026-08: 1827 2026-09: 1513 Sep 26 2026-10: 399 9.443 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Apache Software Foundation Google IBM Linux Microsoft Oracle Corporation
● Apache ● Google ● IBM ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
TierCVEsAnteil
≥90 %7200,2 %
≥50 %3.2230,9 %
≥10 %22.1156,0 %
<10 %342.37392,9 %
368.431 CVEs mit EPSS-Score (FIRST.org) · Stand 10.10.2026
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 99.196 Einträge):
Zeitfenster:
Quelle:
Schwachstellen-Kategorie (CWE):
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
– OHNE BEWERTUNG
EPSS
CVE-2026-107181 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Telegram Desktop 7.2.9 corrige CVE-2026-107181 de robo de cuenta

Un clic en un link dentro de un chat de grupo bastaba para que un atacante leyera cualquier archivo del equipo de la víctima y, con él, robara la sesión activa de su cuenta. El hallazgo, publicado por el investigador detrás del blog beaksec

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-98382 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-98382 | Linux Kernel up to 7.3-rc4 BPF drivers/net/veth.c __bpf_offload_dev_match null pointer dereference (EUVD-2026-95537 / WID-SEC-2026-3822)

A vulnerability was found in Linux Kernel up to 6.6.157/6.12.111/6.18.54/7.2.8/7.3-rc4. It has been classified as very critical. This issue affects the function __bpf_offload_dev_match of the file drivers/net/veth.c of the component BPF. Pe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-98381 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-98381 | Linux Kernel up to 7.3-rc4 veth drivers/net/veth.c veth_set_channels xdp_prog memory corruption (EUVD-2026-95536 / WID-SEC-2026-3822)

A vulnerability was found in Linux Kernel up to 7.3-rc4 and classified as very critical. This vulnerability affects the function veth_set_channels of the file drivers/net/veth.c of the component veth. Such manipulation of the argument xdp_p

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-98379 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-98379 | Linux Kernel up to 7.3-rc4 ip6t_rpfilter ip6t_rpfilter.c rpfilter_mt null pointer dereference (EUVD-2026-95534 / WID-SEC-2026-3822)

A vulnerability identified as critical has been detected in Linux Kernel up to 7.3-rc4. This affects the function rpfilter_mt of the file net/ipv6/netfilter/ip6t_rpfilter.c of the component ip6t_rpfilter. This manipulation causes null point

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-98378 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-98378 | Linux Kernel up to 7.3-rc4 Link Iterator kernel/bpf/syscall.c bpf_link_put use after free (EUVD-2026-95533 / WID-SEC-2026-3822)

A vulnerability was found in Linux Kernel up to 7.3-rc4. It has been declared as very critical. Impacted is the function bpf_link_put of the file kernel/bpf/syscall.c of the component Link Iterator. Executing a manipulation can lead to use

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-98377 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-98377 | Linux Kernel up to 6.12.111/6.18.54/7.2.8/7.3-rc4 vlan __vlan_insert_inner_tag information disclosure (EUVD-2026-95532 / WID-SEC-2026-3822)

A vulnerability has been found in Linux Kernel up to 6.12.111/6.18.54/7.2.8/7.3-rc4 and classified as problematic. This affects the function __vlan_insert_inner_tag of the component vlan. This manipulation causes information disclosure. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-106155 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-106155 | Progress Telerik Report Server up to 10.3.24.1112 Shared Reporting Engine cross site scripting (WID-SEC-2026-3823)

A vulnerability described as problematic has been identified in Progress Telerik Report Server up to 10.3.24.1112. This affects an unknown function of the component Shared Reporting Engine. Such manipulation leads to cross site scripting. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-97791 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-97791 | Apache CXF up to 3.6.12/4.1.8/4.2.3 STSTokenValidator information disclosure (WID-SEC-2026-3824)

A vulnerability, which was classified as problematic, was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. This affects the function STSTokenValidator. The manipulation results in information disclosure. This vulnerability is known as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-106145 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-106145 | Progress Telerik Report Server up to 10.3.24.1112 Service Agent SignalR Hub privileges management (WID-SEC-2026-3823)

A vulnerability labeled as critical has been found in Progress Telerik Report Server up to 10.3.24.1112. The affected element is an unknown function of the component Service Agent SignalR Hub. The manipulation results in improper privilege

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-97468 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-97468 | Apache CXF up to 3.6.12/4.1.8/4.2.3 Security Token Service Cache STSTokenValidator.hashCode improper authentication (WID-SEC-2026-3824)

A vulnerability was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. It has been rated as critical. This affects the function STSTokenValidator.hashCode of the component Security Token Service Cache. The manipulation leads to improper authenti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-86463 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-86463 | Apache CXF up to 3.6.12/4.1.8/4.2.3 Query Parser resource consumption (WID-SEC-2026-3824)

A vulnerability classified as problematic has been found in Apache CXF up to 3.6.12/4.1.8/4.2.3. Impacted is an unknown function of the component Query Parser. Performing a manipulation results in resource consumption. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-79650 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-79650 | Apache CXF up to 3.6.12/4.1.8/4.2.3 OIDC relying-party component state redirect (WID-SEC-2026-3824)

A vulnerability was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component OIDC relying-party component. Performing a manipulation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-78384 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-78384 | Apache CXF up to 3.6.12/4.1.8/4.2.3 Compression Utils CompressionUtils.inflate resource consumption (WID-SEC-2026-3824)

A vulnerability was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. It has been declared as problematic. Affected by this issue is the function CompressionUtils.inflate of the component Compression Utils. Executing a manipulation can lead to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-73179 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-73179 | Apache CXF up to 3.6.12/4.1.8/4.2.3 JPA OAuth2 Authorization Code Grant Provider race condition (WID-SEC-2026-3824)

A vulnerability classified as problematic was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. The affected element is an unknown function of the component JPA OAuth2 Authorization Code Grant Provider. Executing a manipulation can lead to race

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-108039 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-108039 | Apache CXF up to 3.6.12/4.1.8/4.2.3 StaxUtils denial of service (WID-SEC-2026-3824)

A vulnerability has been found in Apache CXF up to 3.6.12/4.1.8/4.2.3 and classified as problematic. This impacts an unknown function of the component StaxUtils. This manipulation causes denial of service. This vulnerability is handled as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-107938 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-107938 | Apache CXF up to 3.6.12/4.1.8/4.2.3 cxf-rt-transports-http-netty-client certificate validation (WID-SEC-2026-3824)

A vulnerability described as problematic has been identified in Apache CXF up to 3.6.12/4.1.8/4.2.3. This issue affects some unknown processing of the component cxf-rt-transports-http-netty-client. Such manipulation leads to improper certif

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-107937 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-107937 | Apache CXF up to 3.6.12/4.1.8/4.2.3 Parser denial of service (WID-SEC-2026-3824)

A vulnerability was found in Apache CXF up to 3.6.12/4.1.8/4.2.3 and classified as problematic. Affected is an unknown function of the component Parser. Such manipulation leads to denial of service. This vulnerability is uniquely identified

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-100227 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-100227 | Apache CXF up to 3.6.12/4.1.8/4.2.3 JAX-RS XML Signature Interceptors data authenticity (WID-SEC-2026-3824)

A vulnerability, which was classified as critical, has been found in Apache CXF up to 3.6.12/4.1.8/4.2.3. The impacted element is the function XmlSigInHandler/XmlSigInInterceptor/XmlSecInInterceptor of the component JAX-RS XML Signature Int

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-98375 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-98375 | Linux Kernel up to 7.3-rc6 netfront handle_incoming_queue information disclosure (EUVD-2026-95525 / WID-SEC-2026-3826)

A vulnerability was found in Linux Kernel up to 7.3-rc6. It has been rated as problematic. This vulnerability affects the function handle_incoming_queue of the component netfront. Performing a manipulation results in information disclosure.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-106438 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-106438 | MongoDB up to 1.30.12/2.5.5 C Driver calculation (WID-SEC-2026-3830)

A vulnerability has been found in MongoDB up to 1.30.12/2.5.5 and classified as problematic. Affected by this issue is some unknown functionality of the component C Driver. This manipulation causes incorrect calculation. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-106437 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-106437 | MongoDB C Driver up to 1.30.12/2.5.5 BSON buffer-reservation API bson_reserve_buffer integer underflow (WID-SEC-2026-3830)

A vulnerability marked as critical has been reported in MongoDB C Driver up to 1.30.12/2.5.5. The affected element is the function bson_reserve_buffer of the component BSON buffer-reservation API. This manipulation causes integer underflow.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-106435 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-106435 | MongoDB Python Driver up to 4.18.2 Binary Accelerator decode buffer overflow (WID-SEC-2026-3830)

A vulnerability labeled as critical has been found in MongoDB Python Driver up to 4.18.2. The affected element is the function decode of the component Binary Accelerator. Such manipulation leads to buffer overflow. This vulnerability is doc

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-106432 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-106432 | MongoDB PHP Driver up to 1.21.10/2.1.10/2.5.3 BSON encoder heap-based overflow (WID-SEC-2026-3830)

A vulnerability identified as very critical has been detected in MongoDB PHP Driver up to 1.21.10/2.1.10/2.5.3. Affected is an unknown function of the component BSON encoder. Performing a manipulation results in heap-based buffer overflow.

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2019-8906 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2019-8906 | libmagic 5.35 readelf.c do_core_note out-of-bounds (ID 277708 / BID-107137)

A vulnerability was found in libmagic 5.35. It has been declared as critical. This affects the function do_core_note of the file readelf.c. Executing a manipulation can lead to out-of-bounds read. This vulnerability is registered as CVE-201

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 22%
CVE-2019-12086 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2019-12086 | Oracle JD Edwards EnterpriseOne Tools 9.2 Monitoring/Diagnostics SEC information disclosure (Nessus ID 236644 / ID 176941)

A vulnerability labeled as critical has been found in Oracle JD Edwards EnterpriseOne Tools 9.2. This issue affects some unknown processing of the component Monitoring/Diagnostics SEC. Executing a manipulation can lead to information disclo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 9.7%
CVE-2018-14719 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-14719 | FasterXML jackson-databind up to 2.9.6 Deserialization blaze-ds-opt/blaze-ds-core deserialization (RHSA-2019:0782 / Nessus ID 121251)

A vulnerability labeled as critical has been found in FasterXML jackson-databind up to 2.9.6. This affects the function blaze-ds-opt/blaze-ds-core of the component Deserialization. Executing a manipulation can lead to deserialization. The i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 7.1%
CVE-2018-12022 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-12022 | Oracle Clusterware 12.1.0.2.0 TFA Collector deserialization (ID 176909 / BID-107585)

A vulnerability was found in Oracle Clusterware 12.1.0.2.0. It has been classified as critical. This affects an unknown function of the component TFA Collector. This manipulation causes deserialization. This vulnerability is tracked as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 14%
CVE-2026-76460 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Why API Gateways Keep Failing Authentication: Lessons From Cisco ISE CVE-2026-76460

Why API Gateways Keep Failing Authentication: Lessons From Cisco ISE CVE-2026-76460 A maximum severity score is rare enough to draw attention, and CVE-2026-76460 earned it. The flaw in Cisco Identity Services Engine combined unauthenticated

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
– OHNE BEWERTUNG
EPSS 12.7%
CVE-2018-14718 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-14718 | Oracle JDeveloper 12.1.3.0.0/12.2.1.3.0 jackson-databind deserialization (ID 176635 / BID-106601)

A vulnerability, which was classified as critical, has been found in Oracle JDeveloper 12.1.3.0.0/12.2.1.3.0. This affects an unknown function of the component jackson-databind. This manipulation causes deserialization. This vulnerability a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-103427 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
wpinsider-1

CVE-2026-103427 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'country' parameter in all versions up to, and including, 4.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unauthenticated attackers may also exploit this

The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'country' parameter in all versions up to, and including, 4.8.4 due to insufficient input sanitization and output escaping. This makes it possib

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
EPSS
CVE-2026-3717 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
bestwpdeveloper

CVE-2026-3717 | The CV Builder – Professional Resume Builder SaaS plugin for WordPress is vulnerable to unauthorized arbitrary file upload due to a missing capability check on the 'wp_save_signature_image' function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to upload arbitrary content to the WordPress uploads directory as png files.

The CV Builder – Professional Resume Builder SaaS plugin for WordPress is vulnerable to unauthorized arbitrary file upload due to a missing capability check on the 'wp_save_signature_image' function in all versions up to, and including, 1.3

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.2 HIGH
EPSS
CVE-2026-107742 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
10web

CVE-2026-107742 | The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 2.34.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable because a co

The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 2.34.8 due to insufficient input

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
3.7 LOW
EPSS
CVE-2026-104006 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
softaculous

CVE-2026-104006 | The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_*, comment_author_email_*' parameter. This makes it possible for unauthenticated attackers to extract the full name and email address of returning commenters pre-filled into comment form input fields and persisted as the site-wide cached page by any unauthenticated attacker

The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_*, comment_author_email_*' parameter. This makes it

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-102402 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
techlabpro1

CVE-2026-102402 | The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ttp_filter_taxonomy (meta of the attacker-chosen post)' parameter in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses

The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ttp_filter_taxonomy (meta of the attacker-chosen post)' parameter in all versions up to, and including, 6.0.2 due to insuffic

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.2 HIGH
EPSS
CVE-2026-100196 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
wp_media

CVE-2026-100196 | The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content (rendered inline into the page HTML)' parameter in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Word

The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content (rendered inline into the page HTML)' parameter in all versions up to, and including, 2.4

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-6243 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
shabti

CVE-2026-6243 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kses bypass / mutation XSS in all versions up to, and including, 3.28.36. This is due to the 'get_dynamic_values' function performing text-level find-and-replace operations on post content without HTML-aware parsing. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kses bypass / mutation XSS in all versions up to, and including, 3.28.36. This is due to the 'get_dynamic_values' function performing tex

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.1 MEDIUM
EPSS
CVE-2026-5725 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Archetyped

CVE-2026-5725 | The Favicon Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fvrt_' prefixed request parameters in all versions up to, and including, 1.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

The Favicon Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fvrt_' prefixed request parameters in all versions up to, and including, 1.2.11 due to insufficient input sanitization and output escaping. Th

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.5 MEDIUM
EPSS
CVE-2026-107712 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
murgroland

CVE-2026-107712 | The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_month' parameter in all versions up to, and including, 2.1.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries t

The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_month' parameter in all versions up to, and including, 2.1.0.1 due to insufficient escaping on the user supplied parame

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.1 HIGH
EPSS
CVE-2026-94538 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
JoomUnited

CVE-2026-94538 | The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete any file managed by WP File Download, empty the entire trash, move files between categories, and publish or unpublish arbitrary

The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it poss

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.2 HIGH
EPSS
CVE-2026-100161 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VillaTheme

CVE-2026-100161 | The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'wcpr_image_upload_id' parameter in all versions up to, and including, 1.2.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The publicly-emitted `wcpr_image_upload` nonce prin

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'wcpr_image_upload_id' parameter in all versions up to, and including, 1.2.30 due to insufficient input sanitization and o

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.1 MEDIUM
EPSS
CVE-2026-89100 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
paymentplugins

CVE-2026-89100 | The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '#response' URL Fragment in all versions up to, and including, 4.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the 'Generic Errors' setting is unc

The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '#response' URL Fragment in all versions up to, and including, 4.0.17 due to insufficient input sanitization and output esca

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.1 CRITICAL
EPSS
CVE-2026-104801 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
themeisle

CVE-2026-104801 | The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and including, 34.0.10 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The relocated file is moved b

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and including, 34.0.10 This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
4.4 MEDIUM
EPSS
CVE-2026-103897 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
dfactory

CVE-2026-103897 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the plugin's 'Comm

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This mak

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.5 MEDIUM
EPSS
CVE-2026-97348 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
gpriday

CVE-2026-97348 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The widget's normal update()/sanitize_field_input() pipeline — which would reject non-hex color values — i

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for authenticated attackers, with contributor-lev

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.2 HIGH
EPSS
CVE-2026-12626 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
ladela

CVE-2026-12626 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known gadget chain is available.

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. This makes

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.2 HIGH
EPSS
CVE-2026-96840 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
wpxpo

CVE-2026-96840 | The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via display_name User Field in all versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress core's pre_user_display_name filter encodes &, <, and > but l

The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via display_name User Field in all versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. Thi

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-96574 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
wedevs

CVE-2026-96574 | The User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpuf_payment_method' parameter in all versions up to, and including, 4.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scri

The User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpuf_payment_method' parameter in

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.2 HIGH
EPSS
CVE-2026-95684 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
e4jvikwp

CVE-2026-95684 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachments[name]' Parameter in all versions up to, and including, 1.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachments[name]' Parameter in all versions up to, and including, 1.8.15 due to insufficient input sanitization and output esc

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.2 HIGH
EPSS
CVE-2026-96558 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
ExpressTech

CVE-2026-96558 | The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'qsm_hidden_questions' parameter in all versions up to, and including, 11.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacke

The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'qsm_hidden_questions' parameter in all versions up to, and including, 11.2.6 due to insufficie

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.4 MEDIUM
EPSS
CVE-2026-15178 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
wpmanageninja

CVE-2026-15178 | The Fluent Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.2.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Custom-level access and above, to read private form submissions, change submission statuses, permanently delete submissions, and modify global plugin settings.

The Fluent Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.2.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
3.3 LOW
EPSS
CVE-2026-108502 💻 Lokal 🔓 Keine Authentifizierung nötig
ZTE

CVE-2026-108502 | ZTE Z80 Ultra contains an information disclosure vulnerability, through which third-party applications can read relevant information by hooking system APIs.

ZTE Z80 Ultra contains an information disclosure vulnerability, through which third-party applications can read relevant information by hooking system APIs.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

DFN-CERT-2026-5584 hpack: Eine Schwachstelle ermöglicht einen Denial-of-Service-Angriff

Bücher über Cybersicherheit und Computerspiele. Bücher/04. Bücher über Staat und IT sowie Programmierung von KI. Bücher/01. Ein Buch über die ... Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
6.4 MEDIUM
EPSS
CVE-2026-17025 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
silverks

CVE-2026-17025 | The Graphene theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'Current location' and 'Author profile image URL' Profile Fields in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The Graphene theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'Current location' and 'Author profile image URL' Profile Fields in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.2 HIGH
EPSS
CVE-2026-14335 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
smub

CVE-2026-14335 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sa

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.1 MEDIUM
EPSS
CVE-2026-12054 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
codename065

CVE-2026-12054 | The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'REFERRER' parameter in all versions up to, and including, 3.3.57 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'REFERRER' parameter in all versions up to, and including, 3.3.57 due to insufficient input sanitization and output escaping. This makes it possib

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-14882 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
themefusecom

CVE-2026-14882 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'brizy-compiled-sections' parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'brizy-compiled-sections' parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping.

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
4.7 MEDIUM
EPSS
CVE-2026-103912 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
jetmonsters

CVE-2026-103912 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the '<attacker-chosen query var name matching the preset's query_var setting>' parameter in all versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the '

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.2 HIGH
EPSS
CVE-2026-93775 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
eteubert

CVE-2026-93775 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection is triggered by submitting a request to the Auphonic webhook endpoint wit

The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possi

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-14877 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
supsysticcom

CVE-2026-14877 | The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id attribute in all versions up to, and including, 1.12.03 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id attribute in all versions up to, and including, 1.12.03 due to insufficient input sanitization and output escaping. This mak

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.4 MEDIUM
EPSS
CVE-2026-103482 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
picocodes

CVE-2026-103482 | The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noptin_fields[<custom_field_merge_tag>] (e.g. first_name)' parameter in all versions up to, and including, 4.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack chain req

The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noptin_fields[] (e.g. first_name)' parameter in all versions up to, and including, 4.3.10 due to insufficient input sanitizatio

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
60 von ~0 Einträgen geladen Ende der Trefferliste — 60 Einträge geladen. Tipp: Filter leichtern für tieferes Blättern.