🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

372k+ 🇪🇺 EUVD-Datenbank
1 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-10: 312 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 682 2026-06: 941 2026-07: 1327 2026-08: 1827 2026-09: 1504 2026-10: 45 9.392 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-182026-10-01
≥90 %0377
≥50 %01137
≥10 %02
<10 %300451
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 98.138 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
– OHNE BEWERTUNG
EPSS
CVE-2026-96355 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-96355: Six Impact Classes, Only One of Which Is a Defacement Problem

CVE-2026-96355: Six Impact Classes, Only One of Which Is a Defacement Problem Not every severe-sounding advisory is equally severe in practice. This one spans six distinct impact classes, and treating them as a single risk overstates some a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2026-11553 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-11553 | Tenda HG7/HG9/HG10 300001138_en_xpon /boaform/formPPPEdit encodename stack-based overflow

A vulnerability labeled as critical has been found in Tenda HG7, HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buff

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 3.8%
CVE-2026-11498 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-11498 | Tenda HG7/HG9/HG10 300001138_en_xpon Web Management Interface /boaform/voip_other_set asp_voip_OtherSet funckey_transfer stack-based overflow

A vulnerability was found in Tenda HG7, HG9 and HG10 300001138_en_xpon. It has been rated as critical. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. P

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-103248 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-103248 | n8n-io n8n up to 1.123.79/2.39.5/2.40.0 Supabase node injection (WID-SEC-2026-3393)

A vulnerability marked as critical has been reported in n8n-io n8n up to 1.123.79/2.39.5/2.40.0. This vulnerability affects unknown code of the component Supabase node. This manipulation causes injection. This vulnerability is handled as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-103247 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-103247 | n8n-io n8n up to 1.123.79 access control (WID-SEC-2026-3393)

A vulnerability identified as critical has been detected in n8n-io n8n up to 1.123.79. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls. This vulnerability is traded as CVE-2026-103247

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-103246 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-103246 | n8n-io n8n up to 2.39.5/2.40.0 Agent privileges management (WID-SEC-2026-3393)

A vulnerability was found in n8n-io n8n up to 2.39.5/2.40.0. It has been rated as problematic. Affected is an unknown function of the component Agent. Performing a manipulation results in improper privilege management. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
EPSS
CVE-2026-103764 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Mooncake Mass Disclosure — CVSS 9.8 Arbitrary Memory Read/Write in KV Cache Transfer Engine

A crafted TCP packet to Mooncake&#039;s transfer data port is enough to read and write arbitrary process memory — no authentication required. CVE-2026-103764 (CVSS 9.8) is an untrusted pointer dereference in ServerSession::readHeader. The r

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-104480 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-104480 | Discord libdave up to 1.1.x MLS Welcome Message improper authorization (EUVD-2026-91159)

A vulnerability classified as critical has been found in Discord libdave up to 1.1.x. The impacted element is an unknown function of the component MLS Welcome Message. The manipulation leads to improper authorization. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-21140 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-21140 | Samsung Devices access control (EUVD-2026-91157)

A vulnerability classified as problematic was found in Samsung Devices. This affects an unknown function. The manipulation results in improper access controls. This vulnerability is known as CVE-2026-21140. Attacking locally is a requiremen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-104053 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-104053 | itsourcecode Pet Shop Management System 1.0 admin_reservefilter.php filter sql injection (EUVD-2026-91156)

A vulnerability described as critical has been identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-104052 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-104052 | itsourcecode Pet Shop Management System 1.0 admin_reject_completed.php id sql injection (EUVD-2026-91158)

A vulnerability marked as critical has been reported in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injecti

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-104054 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-104054 | calcom cal.diy up to 6.2.0 PBAC Permission Engine BookingAccessService.ts doesUserIdHaveAccessToBooking authorization (Issue 29802 / EUVD-2026-91160)

A vulnerability classified as critical has been found in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-104120 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-104120 | modelcontextprotocol mcp-server-fetch/mcp-server-everything up to 2026.6.4 Fetch Tool server.py fetch_url url/path server-side request forgery (Issue 4492 / EUVD-2026-91161)

A vulnerability, which was classified as critical, has been found in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 85.2%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut CVE-2026-81578 and CVE-2026-82078: A Two-Flaw Chain That Ran at Agent Speed

PaperCut CVE-2026-81578 and CVE-2026-82078: A Two-Flaw Chain That Ran at Agent Speed The two entries and the deadline CISA added CVE-2026-81578 and CVE-2026-82078 to the Known Exploited Vulnerabilities catalog on 2026-08-31, both with a fed

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-9364 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-9364 | Rockwell Automation FactoryTalk Analytics LogixAI information expsure

A vulnerability identified as very critical has been detected in Rockwell Automation FactoryTalk Analytics LogixAI. This affects an unknown function. Performing a manipulation results in exposure of sensitive system information to an unauth

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-9166 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-9166 | Rockwell Automation ControlLogix 5580 35.013 Message null pointer dereference (EUVD-2025-27252)

A vulnerability was found in Rockwell Automation ControlLogix 5580 35.013 and classified as problematic. This vulnerability affects unknown code of the component Message Handler. Executing a manipulation can lead to null pointer dereference

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-53303 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-53303 | ThemeMove Core Plugin up to 1.4.2 on WordPress deserialization

A vulnerability was found in ThemeMove Core Plugin up to 1.4.2 on WordPress. It has been classified as critical. Impacted is an unknown function. The manipulation leads to deserialization. This vulnerability is referenced as CVE-2025-53303.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-49692 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2025-49692 | Microsoft Azure Connected Machine Agent access control (WID-SEC-2025-2004)

A vulnerability was found in Microsoft Azure Connected Machine Agent. It has been classified as critical. This affects an unknown part. The manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-40642 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-40642 | WebWork Parameter /search q/engine cross site scripting

A vulnerability classified as problematic was found in WebWork. Impacted is an unknown function of the file /search of the component Parameter Handler. The manipulation of the argument q/engine results in cross site scripting. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-96362 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-96362: What the September 2026 Drupal Contributed Module Batch Means for Site Operators

CVE-2026-96362: What the September 2026 Drupal Contributed Module Batch Means for Site Operators Vulnerability overview CERT-BUND advisory WID-SEC-2026-3554, published on 23 September 2026 and rated high risk, covers a batch of vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-9853 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9853 | Optio Dentistry Plugin up to 2.2 on WordPress Shortcode optio-lightbox cross site scripting

A vulnerability identified as problematic has been detected in Optio Dentistry Plugin up to 2.2 on WordPress. This affects the function optio-lightbox of the component Shortcode Handler. Performing a manipulation results in cross site scrip

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-8359 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-8359 | AdForest Plugin up to 6.0.9 on WordPress authentication bypass

A vulnerability, which was classified as critical, has been found in AdForest Plugin up to 6.0.9 on WordPress. Impacted is an unknown function. This manipulation causes authentication bypass using alternate channel. This vulnerability is re

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-10091 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10091 | Jinher OA up to 1.2 XML ?Type=add xml external entity reference (EUVD-2025-27120)

A vulnerability identified as problematic has been detected in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-10079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10079 | PHPGurukul Small CRM 4.0 /get-quote.php contact sql injection (EUVD-2025-27104)

A vulnerability was found in PHPGurukul Small CRM 4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /get-quote.php. Executing a manipulation of the argument Contact can lead to sql inject

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-10073 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10073 | Portabilis i-Educar up to 2.10 /module/Api/turma improper authorization (EUVD-2025-27100)

A vulnerability described as problematic has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Api/turma. Executing a manipulation can lead to improper authorization. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-10068 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2025-10068 | itsourcecode Online Discussion Forum 1.0 add_views.php id sql injection (EUVD-2025-27095)

A vulnerability labeled as critical has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin/admin_forum/add_views.php. Executing a manipulation of the argument ID can lead to sql injec

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-10067 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10067 | itsourcecode POS Point of Sale System 1.0 empty_table.php scripts cross site scripting (EUVD-2025-27094)

A vulnerability identified as problematic has been detected in itsourcecode POS Point of Sale System 1.0. The impacted element is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/empty_table.php. Per

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-10063 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10063 | itsourcecode POS Point of Sale System 1.0 deferred_table.php scripts cross site scripting (EUVD-2025-27089)

A vulnerability was found in itsourcecode POS Point of Sale System 1.0. It has been classified as problematic. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/deferred_table.php.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58874 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58874 | josepsitjar StoryMap Plugin up to 2.1 on WordPress cross site scripting

A vulnerability was found in josepsitjar StoryMap Plugin up to 2.1 on WordPress. It has been declared as problematic. Affected by this issue is some unknown functionality. The manipulation results in cross site scripting. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58873 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58873 | pusheco Pushe Web Push Notification Plugin up to 0.5.0 on WordPress cross site scripting

A vulnerability identified as problematic has been detected in pusheco Pushe Web Push Notification Plugin up to 0.5.0 on WordPress. This issue affects some unknown processing. Performing a manipulation results in cross site scripting. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-58852 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58852 | Mark O'Donnell MSTW League Manager Plugin up to 2.10 on WordPress cross-site request forgery

A vulnerability described as problematic has been identified in Mark O&#039;Donnell MSTW League Manager Plugin up to 2.10 on WordPress. This affects an unknown part. Executing a manipulation can lead to cross-site request forgery. This vuln

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-58841 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58841 | John Luetke Media Author Plugin up to 1.0.4 on WordPress privileges assignment

A vulnerability classified as problematic has been found in John Luetke Media Author Plugin up to 1.0.4 on WordPress. Impacted is an unknown function. The manipulation leads to incorrect privilege assignment. This vulnerability is documente

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58840 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58840 | Ibnul H. Custom Team Manager Plugin up to 2.4.2 on WordPress cross site scripting

A vulnerability marked as problematic has been reported in Ibnul H. Custom Team Manager Plugin up to 2.4.2 on WordPress. This vulnerability affects unknown code. Performing a manipulation results in cross site scripting. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58836 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58836 | Tikolan FW Anker Plugin up to 1.2.6 on WordPress cross site scripting

A vulnerability categorized as problematic has been discovered in Tikolan FW Anker Plugin up to 1.2.6 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation results in cross site scripting. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-58835 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58835 | calliko Bonus for Woo Plugin up to 7.4.1 on WordPress improper validation of specified quantity in input

A vulnerability, which was classified as problematic, was found in calliko Bonus for Woo Plugin up to 7.4.1 on WordPress. Affected is an unknown function. Such manipulation leads to improper validation of specified quantity in input. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-58831 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58831 | snagysandor Parallax Scrolling Enllax.js Plugin up to 0.0.6 on WordPress cross-site request forgery

A vulnerability identified as problematic has been detected in snagysandor Parallax Scrolling Enllax.js Plugin up to 0.0.6 on WordPress. Affected by this issue is some unknown functionality. This manipulation causes cross-site request forge

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-48317 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-48317 | WooCommerce Payment Gateway for Saferpay Plugin up to 0.4.9 on WordPress path traversal

A vulnerability categorized as critical has been discovered in WooCommerce Payment Gateway for Saferpay Plugin up to 0.4.9 on WordPress. This affects an unknown function. Such manipulation leads to path traversal. This vulnerability is trad

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-10060 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10060 | MongoDB Server up to 6.0.24/7.0.21/8.0.11 operation after expiration (EUVD-2025-27035 / Nessus ID 264357)

A vulnerability identified as problematic has been detected in MongoDB Server up to 6.0.24/7.0.21/8.0.11. Affected by this issue is some unknown functionality. The manipulation leads to operation on a resource after expiration. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-10013 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10013 | Portabilis i-Educar up to 2.10 /exportacao-para-o-seb access control

A vulnerability identified as critical has been detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /exportacao-para-o-seb. Performing a manipulation results in improper access controls. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.9%
CVE-2026-67401 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-67401 Analysis — cPanel & WHM EmailTrack SQL Injection, From Mail Account to Root

Vulnerability Overview Item Detail CVE ID CVE-2026-67401 Component cPanel &amp;amp; WHM — EmailTrack (Email ▸ Track Delivery) Vulnerability class CWE-89 (SQL Injection) Disclosure date September 8, 2026 (cPanel advisory), CVE record publish

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-103764 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-103764 | kvcache-ai Mooncake up to 0.3.12 transfer engine readHeader addr/size null pointer dereference (EUVD-2026-91136)

A vulnerability was found in kvcache-ai Mooncake up to 0.3.12. It has been rated as critical. Affected by this issue is the function ServerSession::readHeader of the component transfer engine. The manipulation of the argument addr/size lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-103765 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-103765 | kvcache-ai Mooncake up to 0.3.13.post1 Metadata missing authentication (EUVD-2026-91137)

A vulnerability categorized as critical has been discovered in kvcache-ai Mooncake up to 0.3.13.post1. This affects an unknown part of the component Metadata Handler. The manipulation results in missing authentication. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-86345 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-86345 | Red Hat Directory Server/Enterprise Linux 389-ds-base cleartext transmission (EUVD-2026-91139)

A vulnerability identified as problematic has been detected in Red Hat Directory Server and Enterprise Linux. This vulnerability affects unknown code of the component 389-ds-base. This manipulation causes cleartext transmission of sensitive

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
– OHNE BEWERTUNG
EPSS
CVE-2026-103766 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-103766 | MacWarrior ClipBucket up to 5.5.3-#197 Ads Manager ads_manager.php AdsManager::DeleteAd delete sql injection (EUVD-2026-91138)

A vulnerability was found in MacWarrior ClipBucket up to 5.5.3-#197. It has been declared as problematic. Affected by this vulnerability is the function AdsManager::DeleteAd of the file admin_area/ads_manager.php of the component Ads Manage

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-8944 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-8944 | OceanWP Plugin up to 4.1.1 on WordPress Setting authorization

A vulnerability classified as problematic has been found in OceanWP Plugin up to 4.1.1 on WordPress. This impacts an unknown function of the component Setting Handler. The manipulation leads to incorrect authorization. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58830 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58830 | snagysandor Parallax Scrolling Enllax.js Plugin up to 0.0.6 on WordPress cross site scripting

A vulnerability, which was classified as problematic, has been found in snagysandor Parallax Scrolling Enllax.js Plugin up to 0.0.6 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58817 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58817 | DesertThemes SoftMe Plugin up to 1.1.24 on WordPress authorization

A vulnerability was found in DesertThemes SoftMe Plugin up to 1.1.24 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation results in missing authorization. This vulnerability was named CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58793 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58793 | WPBean WPB Elementor Addons Plugin up to 1.6 on WordPress cross site scripting

A vulnerability was found in WPBean WPB Elementor Addons Plugin up to 1.6 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-58788 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58788 | Saad Iqbal License Manager for WooCommerce Plugin up to 3.0.12 on WordPress sql injection

A vulnerability categorized as critical has been discovered in Saad Iqbal License Manager for WooCommerce Plugin up to 3.0.12 on WordPress. Affected is an unknown function. Executing a manipulation can lead to sql injection. This vulnerabil

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.8%
CVE-2025-55242 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2025-55242 | Microsoft Xbox Gaming Services information disclosure (EUVD-2025-26871)

A vulnerability, which was classified as problematic, was found in Microsoft Xbox Gaming Services. This impacts an unknown function. The manipulation results in information disclosure. This vulnerability is identified as CVE-2025-55242. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-32322 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2025-32322 | Google Android 13/14 MediaProjectionPermissionActivity.java onCreate permission (EUVD-2025-26852)

A vulnerability marked as critical has been reported in Google Android 13/14. Affected by this issue is the function onCreate of the file MediaProjectionPermissionActivity.java. The manipulation leads to permission issues. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-26431 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-26431 | Google Android 14 Accessibility Service AccessibilityFragment.java setupAccessibilityServices protection mechanism (EUVD-2025-26891)

A vulnerability classified as problematic was found in Google Android 14. This impacts the function setupAccessibilityServices of the file AccessibilityFragment.java of the component Accessibility Service. Executing a manipulation can lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-48533 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-48533 | Google Android 13/14/15/16 race condition

A vulnerability labeled as problematic has been found in Google Android 13/14/15/16. This affects an unknown part. Executing a manipulation can lead to race condition. The identification of this vulnerability is CVE-2025-48533. The attack c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-41052 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-41052 | appRain CMF 4.0.5 canvasjs data[Addon][layouts]/data[Addon][layouts_except] cross site scripting

A vulnerability described as problematic has been identified in appRain CMF 4.0.5. The impacted element is an unknown function of the file /apprain/developer/addons/update/canvasjs. Executing a manipulation of the argument data[Addon][layou

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-41044 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-41044 | appRain CMF 4.0.5 create data[Page][name] cross site scripting

A vulnerability was found in appRain CMF 4.0.5 and classified as problematic. Affected is an unknown function of the file /apprain/page/manage-static-pages/create. Such manipulation of the argument data[Page][name] leads to cross site scrip

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-41036 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2025-41036 | appRain CMF 4.0.5 edit cross site scripting

A vulnerability marked as problematic has been reported in appRain CMF 4.0.5. This vulnerability affects unknown code of the file /apprain/admin/account/edit. This manipulation of the argument data[Admin][description]/data[Admin][f_name]/da

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-26444 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-26444 | Google Android 13/14 VoiceInteractionManagerService.java onHandleForceStop protection mechanism (EUVD-2025-27036)

A vulnerability, which was classified as problematic, was found in Google Android 13/14. Impacted is the function onHandleForceStop of the file VoiceInteractionManagerService.java. Such manipulation leads to protection mechanism failure. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-26423 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-26423 | Google Android 13/14/15 WifiConfigurationUtil.java validateIpConfiguration memory corruption (EUVD-2025-26859)

A vulnerability was found in Google Android 13/14/15. It has been rated as critical. This issue affects the function validateIpConfiguration of the file WifiConfigurationUtil.java. Performing a manipulation results in memory corruption. Thi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-23257 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-23257 | NVIDIA DOCA with collectx-clxapidev permission assignment

A vulnerability marked as critical has been reported in NVIDIA DOCA with collectx-clxapidev. Affected is an unknown function. This manipulation causes incorrect permission assignment. This vulnerability is registered as CVE-2025-23257. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-20330 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2025-20330 | Cisco Unified Communications Manager IM and Presence Service cross site scripting (cisco-sa-imp-xss-XQgu4HSG / EUVD-2025-26616)

A vulnerability marked as problematic has been reported in Cisco Unified Communications Manager IM and Presence Service. The impacted element is an unknown function. This manipulation causes cross site scripting. This vulnerability is track

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
60 von ~0 Einträgen geladen Ende der Trefferliste — 60 Einträge geladen. Tipp: Filter leichtern für tieferes Blättern.