🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

370k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
1 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 33 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 682 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 1327 9.209 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Linux Microsoft Adobe Apple Google Oracle Corporation
● Linux ● Microsoft ● Adobe ● Apple ● Google ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-152026-09-28
≥90 %0299
≥50 %0958
≥10 %03
<10 %300250
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 97.685 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
EPSS
CVE-2026-86950 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)

Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.2%
CVE-2025-13339 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-13339 | Hippoo Mobile App for WooCommerce Plugin up to 1.7.1 on WordPress template_redirect path traversal (EUVD-2025-202393)

A vulnerability classified as problematic was found in Hippoo Mobile App for WooCommerce Plugin up to 1.7.1 on WordPress. The impacted element is the function template_redirect. The manipulation results in path traversal. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 0.7%
CVE-2025-61809 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-61809 | Adobe ColdFusion up to 2021.22/2023.16/2025.4 Security Feature input validation (apsb25-105 / Nessus ID 278173)

A vulnerability identified as critical has been detected in Adobe ColdFusion up to 2021.22/2023.16/2025.4. This vulnerability affects unknown code of the component Security Feature. Performing a manipulation results in improper input valida

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.1%
CVE-2025-64897 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-64897 | Adobe ColdFusion up to 2021.22/2023.16/2025.4 access control (apsb25-105)

A vulnerability was found in Adobe ColdFusion up to 2021.22/2023.16/2025.4 and classified as critical. This impacts an unknown function. Executing a manipulation can lead to improper access controls. This vulnerability is tracked as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 10.5%
CVE-2025-61808 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-61808 | Adobe ColdFusion up to 2021.22/2023.16/2025.4 unrestricted upload (apsb25-105 / Nessus ID 278173)

A vulnerability classified as critical was found in Adobe ColdFusion up to 2021.22/2023.16/2025.4. Impacted is an unknown function. The manipulation results in unrestricted upload. This vulnerability was named CVE-2025-61808. The attack may

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-86950 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

IT Security News Hourly Summary 2026-09-29 01h : 3 posts

3 posts published in the last hour 22:31Apple Emergency Patch for iOS 26/macOS26/macOS15 (CVE-2026-86950), (Mon, Sep 28th) 22:01Exclusive: ShinyHunters Says FBI Data Won’t Be Leaked When Ultimatum Ends 22:00IT Security News Hourly Summary 2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2025-64896 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-64896 | Adobe Creative Cloud Desktop up to 6.4.0.361 File temp file (apsb25-120)

A vulnerability categorized as problematic has been discovered in Adobe Creative Cloud Desktop up to 6.4.0.361. Impacted is an unknown function of the component File Handler. Executing a manipulation can lead to creation of temporary file i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 8.4%
CVE-2025-64447 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Fortinet

CVE-2025-64447 | Fortinet FortiWeb up to 8.0.1 HTTP cookie validation (FG-IR-25-945)

A vulnerability classified as critical was found in Fortinet FortiWeb up to 7.0.11/7.2.11/7.4.10/7.6.5/8.0.1. The affected element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to cookies without va

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2025-64899 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-64899 | Adobe Acrobat Reader up to 25.001.20982 File Parser out-of-bounds (apsb25-119)

A vulnerability classified as critical has been found in Adobe Acrobat Reader up to 20.005.30793/20.005.30803/24.001.30264/24.001.30273/25.001.20982. The impacted element is an unknown function of the component File Parser. This manipulatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2025-64787 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-64787 | Adobe Acrobat Reader up to 25.001.20982 Security Feature signature verification (apsb25-119)

A vulnerability labeled as problematic has been found in Adobe Acrobat Reader up to 20.005.30793/20.005.30803/24.001.30264/24.001.30273/25.001.20982. Affected by this issue is some unknown functionality of the component Security Feature. Su

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2025-64785 💻 Lokal 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-64785 | Adobe Acrobat Reader up to 25.001.20982 untrusted search path (apsb25-119)

A vulnerability categorized as problematic has been discovered in Adobe Acrobat Reader up to 20.005.30793/20.005.30803/24.001.30264/24.001.30273/25.001.20982. Affected is an unknown function. The manipulation results in untrusted search pat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2025-64786 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

CVE-2025-64786 | Adobe Acrobat Reader up to 25.001.20982 Security Feature signature verification (apsb25-119)

A vulnerability identified as problematic has been detected in Adobe Acrobat Reader up to 20.005.30793/20.005.30803/24.001.30264/24.001.30273/25.001.20982. Affected by this vulnerability is an unknown functionality of the component Security

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2025-64661 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2025-64661 | Microsoft Windows up to Server 2025 Shell race condition (EUVD-2025-202207)

A vulnerability has been found in Microsoft Windows and classified as critical. The affected element is an unknown function of the component Shell. The manipulation leads to race condition. This vulnerability is traded as CVE-2025-64661. An

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 0.3%
CVE-2025-64471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Fortinet

CVE-2025-64471 | Fortinet FortiWeb up to 8.0.1 password hash instead of password for authentication (FG-IR-25-984)

A vulnerability described as problematic has been identified in Fortinet FortiWeb up to 7.0.11/7.2.11/7.4.10/7.6.4/8.0.1. The impacted element is an unknown function. Executing a manipulation can lead to use of password hash instead of pass

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS
CVE-2026-86950 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

Apple Emergency Patch for iOS 26/macOS26/macOS15 (CVE-2026-86950), (Mon, Sep 28th)

Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2025-62455 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2025-62455 | Microsoft Windows up to Server 2019 Message Queuing input validation (EUVD-2025-202231)

A vulnerability was found in Microsoft Windows. It has been classified as critical. Affected is an unknown function of the component Message Queuing. This manipulation causes improper input validation. The identification of this vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 2.5%
CVE-2025-62221 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2025-62221 | Microsoft Windows up to Server 2025 Cloud Files Mini Filter Driver use after free (EUVD-2025-202200)

A vulnerability has been found in Microsoft Windows and classified as critical. This affects an unknown function of the component Cloud Files Mini Filter Driver. The manipulation leads to use after free. This vulnerability is uniquely ident

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
EPSS 0.3%
CVE-2025-64156 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Fortinet

CVE-2025-64156 | Fortinet FortiVoice up to 7.2.1 sql injection (FG-IR-25-362 / EUVD-2025-202278)

A vulnerability marked as critical has been reported in Fortinet FortiVoice up to 7.2.1. The affected element is an unknown function. Performing a manipulation results in sql injection. This vulnerability is identified as CVE-2025-64156. Th

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2025-60024 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Fortinet

CVE-2025-60024 | Fortinet FortiVoice up to 7.0.7/7.2.2 path traversal (FG-IR-25-812)

A vulnerability was found in Fortinet FortiVoice up to 7.0.7/7.2.2. It has been classified as critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in path traversal. This vulnerability is k

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.7%
CVE-2025-14188 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-14188 | UGREEN DH2100+ up to 5.3.0.251125 nas_svr /v1/file/backup/create handler_file_backup_create path command injection (EUVD-2025-201598 / CNNVD-202512-827)

A vulnerability was found in UGREEN DH2100+ up to 5.3.0.251125. It has been rated as critical. This impacts the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. The manipulation of the argumen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1.1%
CVE-2025-14136 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-14136 | Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 up to 1.2.07.001 mod_form.so clientsname_0 stack-based overflow (EUVD-2025-201548)

A vulnerability categorized as critical has been discovered in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function RE2000v2Repeater_get_w

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.6%
CVE-2025-14187 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-14187 | UGREEN DH2100+ up to 5.3.0.251125 nas_svr /v1/file/backup/create handler_file_backup_create path buffer overflow (EUVD-2025-201596 / CNNVD-202512-829)

A vulnerability was found in UGREEN DH2100+ up to 5.3.0.251125. It has been declared as critical. This affects the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. Executing a manipulation of

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.9%
CVE-2025-14133 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-14133 | Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 up to 1.2.07.001 mod_form.so AP_get_wireless_clientlist_setClientsName clientsname_0 stack-based overflow (EUVD-2025-201546)

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been classified as critical. Affected by this vulnerability is the function AP_get_wirele

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.9%
CVE-2025-14135 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-14135 | Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 up to 1.2.07.001 mod_form.so AP_get_wired_clientlist_setClientsName clientsname_0 stack-based overflow (EUVD-2025-201547)

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been rated as critical. This affects the function AP_get_wired_clientlist_setClientsName

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2023-53750 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2023-53750 | Linux Kernel up to 6.3.12/6.4.3 pinctrl num_configs out-of-bounds (EUVD-2023-60078 / WID-SEC-2025-2756)

A vulnerability classified as critical was found in Linux Kernel up to 6.3.12/6.4.3. The impacted element is the function num_configs of the component pinctrl. Executing a manipulation can lead to out-of-bounds read. This vulnerability is h

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 2%
CVE-2023-53749 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2023-53749 | Linux Kernel up to 6.2.15 clear_page_64.S clear_user_rep_good memory corruption (EUVD-2023-60079 / WID-SEC-2025-2756)

It seems this issue is a false-positive. Please confirm the sources provided and consider disregarding this entry. Weiterlesen

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.1%
CVE-2023-53748 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2023-53748 | Linux Kernel up to 6.1.29/6.3.3 queue_setup out-of-bounds (EUVD-2023-60080 / Nessus ID 297090)

A vulnerability classified as critical has been found in Linux Kernel up to 6.1.29/6.3.3. The affected element is the function queue_setup. Performing a manipulation results in out-of-bounds read. This vulnerability is known as CVE-2023-537

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.1%
CVE-2023-53747 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2023-53747 | Linux Kernel up to 6.3.3 vc_screen.c vcs_write use after free (EUVD-2023-60081 / Nessus ID 277787)

A vulnerability marked as critical has been reported in Linux Kernel up to 6.3.3. This impacts the function vcs_write of the file drivers/tty/vt/vc_screen.c. Performing a manipulation results in use after free. This vulnerability is known a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2023-53746 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2023-53746 | Linux Kernel up to 6.2.9 vfio_ap null pointer dereference (EUVD-2023-60082 / WID-SEC-2025-2756)

A vulnerability labeled as critical has been found in Linux Kernel up to 5.4.239/5.10.176/5.15.105/6.1.22/6.2.9. This affects the function vfio_ap. Such manipulation leads to null pointer dereference. This vulnerability is traded as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2023-53745 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2023-53745 | Linux Kernel up to 6.2.4 uml_parse_vector_ifspec return value (EUVD-2023-60083 / WID-SEC-2025-2756)

A vulnerability was found in Linux Kernel up to 6.2.4. It has been rated as critical. Impacted is the function uml_parse_vector_ifspec. The manipulation leads to unchecked return value. This vulnerability is documented as CVE-2023-53745. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2023-53744 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2023-53744 | Linux Kernel up to 6.3.1 soc wkup_m3_ipc_get reference count (EUVD-2023-60084 / WID-SEC-2025-2756)

A vulnerability was found in Linux Kernel up to 5.10.179/5.15.110/6.1.27/6.2.14/6.3.1. It has been classified as critical. This vulnerability affects the function wkup_m3_ipc_get of the component soc. Performing a manipulation results in im

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2023-53743 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2023-53743 | Linux Kernel up to 6.1.52/6.4.15/6.5.2 PCI release_resource privilege escalation (EUVD-2023-60085 / Nessus ID 277782)

A vulnerability classified as critical was found in Linux Kernel up to 6.1.52/6.4.15/6.5.2. This impacts the function release_resource of the component PCI. Executing a manipulation can lead to privilege escalation. The identification of th

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2022-50630 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2022-50630 | Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2 mm handle_userfault use after free (Nessus ID 297090 / WID-SEC-2025-2756)

A vulnerability marked as critical has been reported in Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2. The affected element is the function handle_userfault of the component mm. This manipulation causes use after free. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2023-53742 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2023-53742 | Linux Kernel up to 6.1.27/6.2.14/6.3.1 read_instrumented_memory privilege escalation (EUVD-2023-60086 / Nessus ID 277645)

A vulnerability was found in Linux Kernel up to 6.1.27/6.2.14/6.3.1. It has been declared as problematic. Affected by this issue is the function read_instrumented_memory. Such manipulation leads to privilege escalation. This vulnerability i

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2022-50628 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2022-50628 | Linux Kernel up to 6.1.15/6.2.2 iosys_map_clear uninitialized pointer (Nessus ID 277773 / WID-SEC-2025-2756)

A vulnerability was found in Linux Kernel up to 6.1.15/6.2.2. It has been classified as critical. Affected by this vulnerability is the function iosys_map_clear. This manipulation causes uninitialized pointer. This vulnerability is register

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS
CVE-2026-86950 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

Apple schließt CoreGraphics-Lücke: CVE-2026-86950 möglicherweise ausgenutzt

LONDON (IT BOLTWISE) – Apple hat Sicherheitsupdates für ältere iOS-, iPadOS- und macOS-Versionen veröffentlicht, um eine Schwachstelle im CoreGraphics-Komponentenbereich zu schließen. Laut Apple kann CVE-2026-86950 bei der Verarbeitung präp

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2022-50627 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2022-50627 | Linux Kernel up to 6.1.15/6.2.2 ath11k null pointer dereference (Nessus ID 277630 / WID-SEC-2025-2756)

A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.15/6.2.2. Impacted is an unknown function of the component ath11k. The manipulation results in null pointer dereference. This vulnerability is known as CVE-2022-50

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2022-50626 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2022-50626 | Linux Kernel up to 6.1.1 dvb_usb_adapter_init num_adapters_initalized reference count (Nessus ID 277776 / WID-SEC-2025-2756)

A vulnerability was found in Linux Kernel up to 6.1.1. It has been declared as critical. This issue affects the function dvb_usb_adapter_init. Executing a manipulation of the argument num_adapters_initalized can lead to improper update of r

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2022-50624 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2022-50624 | Linux Kernel up to 6.0.6 netsec_register_mdio reference count (WID-SEC-2025-2756)

A vulnerability described as critical has been identified in Linux Kernel up to 4.19.263/5.4.222/5.10.152/5.15.76/6.0.6. Affected is the function netsec_register_mdio. Executing a manipulation can lead to improper update of reference count.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2022-50625 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2022-50625 | Linux Kernel up to 6.1.1 UART Interface memory corruption (Nessus ID 277774 / WID-SEC-2025-2756)

A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.1. This affects an unknown function of the component UART Interface. Executing a manipulation can lead to memory corruption. This vulnerability is tracke

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2022-50622 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2022-50622 | Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2 ext4 ext4_fc_record_modified_inode memory leak (Nessus ID 277739 / WID-SEC-2025-2756)

A vulnerability identified as critical has been detected in Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2. The impacted element is the function ext4_fc_record_modified_inode of the component ext4. This manipulation causes memory leak. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2022-50621 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2022-50621 | Linux Kernel up to 6.0.2 dm denial of service (Nessus ID 277780 / WID-SEC-2025-2756)

A vulnerability classified as critical has been found in Linux Kernel up to 6.0.2. This affects an unknown function of the component dm. Performing a manipulation results in denial of service. This vulnerability was named CVE-2022-50621. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2022-50617 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2022-50617 | Linux Kernel up to 5.15.85/6.0.15/6.1.1 memory leak (Nessus ID 277784 / WID-SEC-2025-2756)

A vulnerability described as critical has been identified in Linux Kernel up to 5.15.85/6.0.15/6.1.1. The impacted element is an unknown function. Such manipulation leads to memory leak. This vulnerability is uniquely identified as CVE-2022

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2022-50618 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2022-50618 | Linux Kernel up to 6.1.1 mmc_add_host return value (Nessus ID 277781 / WID-SEC-2025-2756)

A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.1. Affected by this vulnerability is the function mmc_add_host. The manipulation results in unchecked return value. This vulnerability is identified as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2022-50616 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2022-50616 | Linux Kernel up to 6.0.15/6.1.1 regulator mt6370_probe allocation of resources (Nessus ID 277638 / WID-SEC-2025-2756)

A vulnerability was found in Linux Kernel up to 6.0.15/6.1.1 and classified as critical. Affected is the function mt6370_probe of the component regulator. The manipulation results in allocation of resources. This vulnerability is cataloged

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

Apple Patches Zero-Day Exploit Alongside September 2026 OS Fixes

A zero-day CoreGraphics exploit is being used in “extremely sophisticated attacks against specific targeted individuals.” Apple has patched it in iOS 26.7.1 and related updates, while OS 27.0.1 brings largely unspecified bug fixes. Weiterl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.7%
CVE-2025-66471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-66471 | urllib3 up to 2.5.x Streaming API data amplification (Nessus ID 278513 / WID-SEC-2025-2927)

A vulnerability categorized as critical has been discovered in urllib3 up to 2.5.x. This affects an unknown function of the component Streaming API. Such manipulation leads to highly compressed data. This vulnerability is documented as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2026-8927 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

USN-8487-2: curl regression

USN-8487-1 fixed vulnerabilities in curl. Unfortunately that update contained an incomplete fix for CVE-2026-8927. This update fixes the problem. Original advisory details: Andrew Nesbitt discovered that curl could reuse an existing live co

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 0.2%
CVE-2026-93304 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93304 | wolfSSL up to 5.9.2 ChangeCipherSpec wolfSSL_inject input validation (Nessus ID 350862)

A vulnerability identified as critical has been detected in wolfSSL up to 5.9.2. The affected element is the function wolfSSL_inject of the component ChangeCipherSpec Handler. The manipulation leads to improper input validation. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-94417 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-94417 | wolfSSL up to 5.9.2 Certificate Manager ProcessPeerCerts certificate validation (Nessus ID 350863)

A vulnerability was found in wolfSSL up to 5.9.2. It has been declared as problematic. This vulnerability affects the function ProcessPeerCerts of the component Certificate Manager. Such manipulation leads to improper certificate validation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.3%
CVE-2026-89102 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89102 | wolfSSL up to 5.9.2 OCSP Stapling wolfSSL_UseOCSPStaplingV2 certificate validation (Nessus ID 350871)

A vulnerability categorized as problematic has been discovered in wolfSSL up to 5.9.2. Impacted is the function wolfSSL_UseOCSPStaplingV2 of the component OCSP Stapling. Executing a manipulation can lead to improper certificate validation.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.6%
CVE-2026-80212 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-80212 | Resolv up to 0.3.1/0.7.1 DNS Module Resource.get_class memory leak (Nessus ID 350868)

A vulnerability classified as problematic has been found in Resolv up to 0.3.1/0.7.1. Affected is the function Resolv::DNS::Resource.get_class of the component DNS Module. This manipulation causes memory leak. This vulnerability is handled

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-89134 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89134 | wolfSSL 5.9.2 subjectCN/altNames/isCA certificate validation (Nessus ID 350872)

A vulnerability was found in wolfSSL 5.9.2 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument subjectCN/altNames/isCA results in improper certificate validation. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.2%
CVE-2026-89135 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89135 | wolfSSL up to 5.9.2 X509_verify_cert certificate validation (Nessus ID 350874)

A vulnerability has been found in wolfSSL up to 5.9.2 and classified as problematic. Affected by this vulnerability is the function X509_verify_cert. The manipulation leads to improper certificate validation. This vulnerability is documente

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2026-89136 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89136 | wolfSSL up to 5.9.2 TLS Client server_cert_type improper authentication (Nessus ID 350873)

A vulnerability was found in wolfSSL up to 5.9.2. It has been rated as critical. This issue affects some unknown processing of the component TLS Client. Performing a manipulation of the argument server_cert_type results in improper authenti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.4%
CVE-2022-45040 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-45040 | WBCE CMS 1.5.4 sections_save.php Name Section cross site scripting (EUVD-2022-47965)

A vulnerability categorized as problematic has been discovered in WBCE CMS 1.5.4. This affects an unknown function of the file /admin/pages/sections_save.php. Such manipulation of the argument Name Section leads to cross site scripting. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 1.1%
CVE-2022-45039 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45039 | WBCE CMS 1.5.4 Server Settings unrestricted upload (EUVD-2022-47964)

A vulnerability was found in WBCE CMS 1.5.4. It has been rated as critical. The impacted element is an unknown function of the component Server Settings Module. This manipulation causes unrestricted upload. This vulnerability is registered

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2022-45036 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45036 | WBCE CMS 1.5.4 Search Settings No Results cross site scripting (EUVD-2022-47961)

A vulnerability marked as problematic has been reported in WBCE CMS 1.5.4. Affected by this vulnerability is an unknown functionality of the component Search Settings Module. The manipulation of the argument No Results leads to cross site s

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 0.5%
CVE-2022-45033 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45033 | Expense Tracker 1.0 Chat Text cross site scripting (EUVD-2022-47958)

A vulnerability was found in Expense Tracker 1.0. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Chat Text Handler. Such manipulation leads to cross site scripting. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.7%
CVE-2022-45030 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45030 | rConfig 3.9.7 ajaxCompareGetCmdDates.php command sql injection (ID 171613 / EUVD-2022-47955)

A vulnerability was found in rConfig 3.9.7. It has been rated as critical. This issue affects some unknown processing in the library lib/ajaxHandlers/ajaxCompareGetCmdDates.php. Performing a manipulation of the argument command results in s

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.