Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-18 | 2026-10-01 |
|---|---|---|
| ≥90 % | 0 | 377 |
| ≥50 % | 0 | 1137 |
| ≥10 % | 0 | 2 |
| <10 % | 300 | 451 |
CVE-2026-96355: Six Impact Classes, Only One of Which Is a Defacement Problem
CVE-2026-96355: Six Impact Classes, Only One of Which Is a Defacement Problem Not every severe-sounding advisory is equally severe in practice. This one spans six distinct impact classes, and treating them as a single risk overstates some a
CVE-2026-11553 | Tenda HG7/HG9/HG10 300001138_en_xpon /boaform/formPPPEdit encodename stack-based overflow
A vulnerability labeled as critical has been found in Tenda HG7, HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buff
CVE-2026-11498 | Tenda HG7/HG9/HG10 300001138_en_xpon Web Management Interface /boaform/voip_other_set asp_voip_OtherSet funckey_transfer stack-based overflow
A vulnerability was found in Tenda HG7, HG9 and HG10 300001138_en_xpon. It has been rated as critical. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. P
CVE-2026-103248 | n8n-io n8n up to 1.123.79/2.39.5/2.40.0 Supabase node injection (WID-SEC-2026-3393)
A vulnerability marked as critical has been reported in n8n-io n8n up to 1.123.79/2.39.5/2.40.0. This vulnerability affects unknown code of the component Supabase node. This manipulation causes injection. This vulnerability is handled as CV
CVE-2026-103247 | n8n-io n8n up to 1.123.79 access control (WID-SEC-2026-3393)
A vulnerability identified as critical has been detected in n8n-io n8n up to 1.123.79. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls. This vulnerability is traded as CVE-2026-103247
CVE-2026-103246 | n8n-io n8n up to 2.39.5/2.40.0 Agent privileges management (WID-SEC-2026-3393)
A vulnerability was found in n8n-io n8n up to 2.39.5/2.40.0. It has been rated as problematic. Affected is an unknown function of the component Agent. Performing a manipulation results in improper privilege management. This vulnerability is
Mooncake Mass Disclosure — CVSS 9.8 Arbitrary Memory Read/Write in KV Cache Transfer Engine
A crafted TCP packet to Mooncake's transfer data port is enough to read and write arbitrary process memory — no authentication required. CVE-2026-103764 (CVSS 9.8) is an untrusted pointer dereference in ServerSession::readHeader. The r
CVE-2026-104480 | Discord libdave up to 1.1.x MLS Welcome Message improper authorization (EUVD-2026-91159)
A vulnerability classified as critical has been found in Discord libdave up to 1.1.x. The impacted element is an unknown function of the component MLS Welcome Message. The manipulation leads to improper authorization. This vulnerability is
CVE-2026-21140 | Samsung Devices access control (EUVD-2026-91157)
A vulnerability classified as problematic was found in Samsung Devices. This affects an unknown function. The manipulation results in improper access controls. This vulnerability is known as CVE-2026-21140. Attacking locally is a requiremen
CVE-2026-104053 | itsourcecode Pet Shop Management System 1.0 admin_reservefilter.php filter sql injection (EUVD-2026-91156)
A vulnerability described as critical has been identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql
CVE-2026-104052 | itsourcecode Pet Shop Management System 1.0 admin_reject_completed.php id sql injection (EUVD-2026-91158)
A vulnerability marked as critical has been reported in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injecti
CVE-2026-104054 | calcom cal.diy up to 6.2.0 PBAC Permission Engine BookingAccessService.ts doesUserIdHaveAccessToBooking authorization (Issue 29802 / EUVD-2026-91160)
A vulnerability classified as critical has been found in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulat
CVE-2026-104120 | modelcontextprotocol mcp-server-fetch/mcp-server-everything up to 2026.6.4 Fetch Tool server.py fetch_url url/path server-side request forgery (Issue 4492 / EUVD-2026-91161)
A vulnerability, which was classified as critical, has been found in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component
PaperCut CVE-2026-81578 and CVE-2026-82078: A Two-Flaw Chain That Ran at Agent Speed
PaperCut CVE-2026-81578 and CVE-2026-82078: A Two-Flaw Chain That Ran at Agent Speed The two entries and the deadline CISA added CVE-2026-81578 and CVE-2026-82078 to the Known Exploited Vulnerabilities catalog on 2026-08-31, both with a fed
CVE-2025-9364 | Rockwell Automation FactoryTalk Analytics LogixAI information expsure
A vulnerability identified as very critical has been detected in Rockwell Automation FactoryTalk Analytics LogixAI. This affects an unknown function. Performing a manipulation results in exposure of sensitive system information to an unauth
CVE-2025-9166 | Rockwell Automation ControlLogix 5580 35.013 Message null pointer dereference (EUVD-2025-27252)
A vulnerability was found in Rockwell Automation ControlLogix 5580 35.013 and classified as problematic. This vulnerability affects unknown code of the component Message Handler. Executing a manipulation can lead to null pointer dereference
CVE-2025-53303 | ThemeMove Core Plugin up to 1.4.2 on WordPress deserialization
A vulnerability was found in ThemeMove Core Plugin up to 1.4.2 on WordPress. It has been classified as critical. Impacted is an unknown function. The manipulation leads to deserialization. This vulnerability is referenced as CVE-2025-53303.
CVE-2025-49692 | Microsoft Azure Connected Machine Agent access control (WID-SEC-2025-2004)
A vulnerability was found in Microsoft Azure Connected Machine Agent. It has been classified as critical. This affects an unknown part. The manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-202
CVE-2025-40642 | WebWork Parameter /search q/engine cross site scripting
A vulnerability classified as problematic was found in WebWork. Impacted is an unknown function of the file /search of the component Parameter Handler. The manipulation of the argument q/engine results in cross site scripting. This vulnerab
CVE-2026-96362: What the September 2026 Drupal Contributed Module Batch Means for Site Operators
CVE-2026-96362: What the September 2026 Drupal Contributed Module Batch Means for Site Operators Vulnerability overview CERT-BUND advisory WID-SEC-2026-3554, published on 23 September 2026 and rated high risk, covers a batch of vulnerabilit
CVE-2025-9853 | Optio Dentistry Plugin up to 2.2 on WordPress Shortcode optio-lightbox cross site scripting
A vulnerability identified as problematic has been detected in Optio Dentistry Plugin up to 2.2 on WordPress. This affects the function optio-lightbox of the component Shortcode Handler. Performing a manipulation results in cross site scrip
CVE-2025-8359 | AdForest Plugin up to 6.0.9 on WordPress authentication bypass
A vulnerability, which was classified as critical, has been found in AdForest Plugin up to 6.0.9 on WordPress. Impacted is an unknown function. This manipulation causes authentication bypass using alternate channel. This vulnerability is re
CVE-2025-10091 | Jinher OA up to 1.2 XML ?Type=add xml external entity reference (EUVD-2025-27120)
A vulnerability identified as problematic has been detected in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulatio
CVE-2025-10079 | PHPGurukul Small CRM 4.0 /get-quote.php contact sql injection (EUVD-2025-27104)
A vulnerability was found in PHPGurukul Small CRM 4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /get-quote.php. Executing a manipulation of the argument Contact can lead to sql inject
CVE-2025-10073 | Portabilis i-Educar up to 2.10 /module/Api/turma improper authorization (EUVD-2025-27100)
A vulnerability described as problematic has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Api/turma. Executing a manipulation can lead to improper authorization. This vulnerability i
CVE-2025-10068 | itsourcecode Online Discussion Forum 1.0 add_views.php id sql injection (EUVD-2025-27095)
A vulnerability labeled as critical has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin/admin_forum/add_views.php. Executing a manipulation of the argument ID can lead to sql injec
CVE-2025-10067 | itsourcecode POS Point of Sale System 1.0 empty_table.php scripts cross site scripting (EUVD-2025-27094)
A vulnerability identified as problematic has been detected in itsourcecode POS Point of Sale System 1.0. The impacted element is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/empty_table.php. Per
CVE-2025-10063 | itsourcecode POS Point of Sale System 1.0 deferred_table.php scripts cross site scripting (EUVD-2025-27089)
A vulnerability was found in itsourcecode POS Point of Sale System 1.0. It has been classified as problematic. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/deferred_table.php.
CVE-2025-58874 | josepsitjar StoryMap Plugin up to 2.1 on WordPress cross site scripting
A vulnerability was found in josepsitjar StoryMap Plugin up to 2.1 on WordPress. It has been declared as problematic. Affected by this issue is some unknown functionality. The manipulation results in cross site scripting. This vulnerability
CVE-2025-58873 | pusheco Pushe Web Push Notification Plugin up to 0.5.0 on WordPress cross site scripting
A vulnerability identified as problematic has been detected in pusheco Pushe Web Push Notification Plugin up to 0.5.0 on WordPress. This issue affects some unknown processing. Performing a manipulation results in cross site scripting. This
CVE-2025-58852 | Mark O'Donnell MSTW League Manager Plugin up to 2.10 on WordPress cross-site request forgery
A vulnerability described as problematic has been identified in Mark O'Donnell MSTW League Manager Plugin up to 2.10 on WordPress. This affects an unknown part. Executing a manipulation can lead to cross-site request forgery. This vuln
CVE-2025-58841 | John Luetke Media Author Plugin up to 1.0.4 on WordPress privileges assignment
A vulnerability classified as problematic has been found in John Luetke Media Author Plugin up to 1.0.4 on WordPress. Impacted is an unknown function. The manipulation leads to incorrect privilege assignment. This vulnerability is documente
CVE-2025-58840 | Ibnul H. Custom Team Manager Plugin up to 2.4.2 on WordPress cross site scripting
A vulnerability marked as problematic has been reported in Ibnul H. Custom Team Manager Plugin up to 2.4.2 on WordPress. This vulnerability affects unknown code. Performing a manipulation results in cross site scripting. This vulnerability
CVE-2025-58836 | Tikolan FW Anker Plugin up to 1.2.6 on WordPress cross site scripting
A vulnerability categorized as problematic has been discovered in Tikolan FW Anker Plugin up to 1.2.6 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation results in cross site scripting. This vulnerabi
CVE-2025-58835 | calliko Bonus for Woo Plugin up to 7.4.1 on WordPress improper validation of specified quantity in input
A vulnerability, which was classified as problematic, was found in calliko Bonus for Woo Plugin up to 7.4.1 on WordPress. Affected is an unknown function. Such manipulation leads to improper validation of specified quantity in input. This v
CVE-2025-58831 | snagysandor Parallax Scrolling Enllax.js Plugin up to 0.0.6 on WordPress cross-site request forgery
A vulnerability identified as problematic has been detected in snagysandor Parallax Scrolling Enllax.js Plugin up to 0.0.6 on WordPress. Affected by this issue is some unknown functionality. This manipulation causes cross-site request forge
CVE-2025-48317 | WooCommerce Payment Gateway for Saferpay Plugin up to 0.4.9 on WordPress path traversal
A vulnerability categorized as critical has been discovered in WooCommerce Payment Gateway for Saferpay Plugin up to 0.4.9 on WordPress. This affects an unknown function. Such manipulation leads to path traversal. This vulnerability is trad
CVE-2025-10060 | MongoDB Server up to 6.0.24/7.0.21/8.0.11 operation after expiration (EUVD-2025-27035 / Nessus ID 264357)
A vulnerability identified as problematic has been detected in MongoDB Server up to 6.0.24/7.0.21/8.0.11. Affected by this issue is some unknown functionality. The manipulation leads to operation on a resource after expiration. This vulnera
CVE-2025-10013 | Portabilis i-Educar up to 2.10 /exportacao-para-o-seb access control
A vulnerability identified as critical has been detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /exportacao-para-o-seb. Performing a manipulation results in improper access controls. This vulnerabili
CVE-2026-67401 Analysis — cPanel & WHM EmailTrack SQL Injection, From Mail Account to Root
Vulnerability Overview Item Detail CVE ID CVE-2026-67401 Component cPanel &amp; WHM — EmailTrack (Email ▸ Track Delivery) Vulnerability class CWE-89 (SQL Injection) Disclosure date September 8, 2026 (cPanel advisory), CVE record publish
CVE-2026-103764 | kvcache-ai Mooncake up to 0.3.12 transfer engine readHeader addr/size null pointer dereference (EUVD-2026-91136)
A vulnerability was found in kvcache-ai Mooncake up to 0.3.12. It has been rated as critical. Affected by this issue is the function ServerSession::readHeader of the component transfer engine. The manipulation of the argument addr/size lead
CVE-2026-103765 | kvcache-ai Mooncake up to 0.3.13.post1 Metadata missing authentication (EUVD-2026-91137)
A vulnerability categorized as critical has been discovered in kvcache-ai Mooncake up to 0.3.13.post1. This affects an unknown part of the component Metadata Handler. The manipulation results in missing authentication. This vulnerability is
CVE-2026-86345 | Red Hat Directory Server/Enterprise Linux 389-ds-base cleartext transmission (EUVD-2026-91139)
A vulnerability identified as problematic has been detected in Red Hat Directory Server and Enterprise Linux. This vulnerability affects unknown code of the component 389-ds-base. This manipulation causes cleartext transmission of sensitive
CVE-2026-103766 | MacWarrior ClipBucket up to 5.5.3-#197 Ads Manager ads_manager.php AdsManager::DeleteAd delete sql injection (EUVD-2026-91138)
A vulnerability was found in MacWarrior ClipBucket up to 5.5.3-#197. It has been declared as problematic. Affected by this vulnerability is the function AdsManager::DeleteAd of the file admin_area/ads_manager.php of the component Ads Manage
CVE-2025-8944 | OceanWP Plugin up to 4.1.1 on WordPress Setting authorization
A vulnerability classified as problematic has been found in OceanWP Plugin up to 4.1.1 on WordPress. This impacts an unknown function of the component Setting Handler. The manipulation leads to incorrect authorization. This vulnerability is
CVE-2025-58830 | snagysandor Parallax Scrolling Enllax.js Plugin up to 0.0.6 on WordPress cross site scripting
A vulnerability, which was classified as problematic, has been found in snagysandor Parallax Scrolling Enllax.js Plugin up to 0.0.6 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting. Th
CVE-2025-58817 | DesertThemes SoftMe Plugin up to 1.1.24 on WordPress authorization
A vulnerability was found in DesertThemes SoftMe Plugin up to 1.1.24 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation results in missing authorization. This vulnerability was named CVE
CVE-2025-58793 | WPBean WPB Elementor Addons Plugin up to 1.6 on WordPress cross site scripting
A vulnerability was found in WPBean WPB Elementor Addons Plugin up to 1.6 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripti
CVE-2025-58788 | Saad Iqbal License Manager for WooCommerce Plugin up to 3.0.12 on WordPress sql injection
A vulnerability categorized as critical has been discovered in Saad Iqbal License Manager for WooCommerce Plugin up to 3.0.12 on WordPress. Affected is an unknown function. Executing a manipulation can lead to sql injection. This vulnerabil
CVE-2025-55242 | Microsoft Xbox Gaming Services information disclosure (EUVD-2025-26871)
A vulnerability, which was classified as problematic, was found in Microsoft Xbox Gaming Services. This impacts an unknown function. The manipulation results in information disclosure. This vulnerability is identified as CVE-2025-55242. The
CVE-2025-32322 | Google Android 13/14 MediaProjectionPermissionActivity.java onCreate permission (EUVD-2025-26852)
A vulnerability marked as critical has been reported in Google Android 13/14. Affected by this issue is the function onCreate of the file MediaProjectionPermissionActivity.java. The manipulation leads to permission issues. This vulnerabilit
CVE-2025-26431 | Google Android 14 Accessibility Service AccessibilityFragment.java setupAccessibilityServices protection mechanism (EUVD-2025-26891)
A vulnerability classified as problematic was found in Google Android 14. This impacts the function setupAccessibilityServices of the file AccessibilityFragment.java of the component Accessibility Service. Executing a manipulation can lead
CVE-2025-48533 | Google Android 13/14/15/16 race condition
A vulnerability labeled as problematic has been found in Google Android 13/14/15/16. This affects an unknown part. Executing a manipulation can lead to race condition. The identification of this vulnerability is CVE-2025-48533. The attack c
CVE-2025-41052 | appRain CMF 4.0.5 canvasjs data[Addon][layouts]/data[Addon][layouts_except] cross site scripting
A vulnerability described as problematic has been identified in appRain CMF 4.0.5. The impacted element is an unknown function of the file /apprain/developer/addons/update/canvasjs. Executing a manipulation of the argument data[Addon][layou
CVE-2025-41044 | appRain CMF 4.0.5 create data[Page][name] cross site scripting
A vulnerability was found in appRain CMF 4.0.5 and classified as problematic. Affected is an unknown function of the file /apprain/page/manage-static-pages/create. Such manipulation of the argument data[Page][name] leads to cross site scrip
CVE-2025-41036 | appRain CMF 4.0.5 edit cross site scripting
A vulnerability marked as problematic has been reported in appRain CMF 4.0.5. This vulnerability affects unknown code of the file /apprain/admin/account/edit. This manipulation of the argument data[Admin][description]/data[Admin][f_name]/da
CVE-2025-26444 | Google Android 13/14 VoiceInteractionManagerService.java onHandleForceStop protection mechanism (EUVD-2025-27036)
A vulnerability, which was classified as problematic, was found in Google Android 13/14. Impacted is the function onHandleForceStop of the file VoiceInteractionManagerService.java. Such manipulation leads to protection mechanism failure. Th
CVE-2025-26423 | Google Android 13/14/15 WifiConfigurationUtil.java validateIpConfiguration memory corruption (EUVD-2025-26859)
A vulnerability was found in Google Android 13/14/15. It has been rated as critical. This issue affects the function validateIpConfiguration of the file WifiConfigurationUtil.java. Performing a manipulation results in memory corruption. Thi
CVE-2025-23257 | NVIDIA DOCA with collectx-clxapidev permission assignment
A vulnerability marked as critical has been reported in NVIDIA DOCA with collectx-clxapidev. Affected is an unknown function. This manipulation causes incorrect permission assignment. This vulnerability is registered as CVE-2025-23257. The
CVE-2025-20330 | Cisco Unified Communications Manager IM and Presence Service cross site scripting (cisco-sa-imp-xss-XQgu4HSG / EUVD-2025-26616)
A vulnerability marked as problematic has been reported in Cisco Unified Communications Manager IM and Presence Service. The impacted element is an unknown function. This manipulation causes cross site scripting. This vulnerability is track