🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

372k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
1 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-10: 285 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 682 2026-06: 941 2026-07: 1327 2026-08: 1827 2026-09: 1509 2026-10: 82 9.407 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-202026-10-04
≥90 %489361
≥50 %14771099
≥10 %02
<10 %0505
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 98.236 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-12926 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-12926 | SourceCodester Farm Management System 1.0 /review.php pid sql injection (EUVD-2025-38734 / CNNVD-202511-976)

A vulnerability classified as critical has been found in SourceCodester Farm Management System 1.0. The affected element is an unknown function of the file /review.php. This manipulation of the argument pid causes sql injection. This vulner

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-12925 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-12925 | rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224 UserDicController.java getAll/addDic/getAllDic/deleteDic authorization (Issue 199 / EUVD-2025-38727)

A vulnerability described as critical has been identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserD

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-12431 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-12431 | Google Chrome up to 141.0.7390.122 Extensions authentication bypass (Nessus ID 272077 / WID-SEC-2025-2445)

A vulnerability was found in Google Chrome. It has been rated as critical. Affected by this issue is some unknown functionality of the component Extensions. Performing a manipulation results in authentication bypass using alternate channel.

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-12430 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-12430 | Google Chrome up to 141.0.7390.122 Media round.about authentication spoofing (Nessus ID 272077 / WID-SEC-2025-2445)

A vulnerability was found in Google Chrome and classified as critical. This impacts an unknown function of the file round.about of the component Media. The manipulation results in authentication bypass by spoofing. This vulnerability was na

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-12429 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-12429 | Google Chrome up to 141.0.7390.122 V8 Remote Code Execution (Nessus ID 272077 / WID-SEC-2025-2445)

A vulnerability marked as critical has been reported in Google Chrome. Impacted is an unknown function of the component V8. This manipulation causes Remote Code Execution. This vulnerability is registered as CVE-2025-12429. Remote exploitat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 6.6%
CVE-2025-12428 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-12428 | Google Chrome up to 141.0.7390.122 V8 type confusion (Nessus ID 272077 / WID-SEC-2025-2445)

A vulnerability has been found in Google Chrome and classified as critical. This affects an unknown function of the component V8. The manipulation leads to type confusion. This vulnerability is uniquely identified as CVE-2025-12428. The att

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-93756 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
WordPress

CVE-2026-93756 | Smash Balloon Social Post Feed Plugin up to 4.13.0 on WordPress Admin Builder Preview/AJAX addon-functions.php cross site scripting (EUVD-2026-91253)

A vulnerability was found in Smash Balloon Social Post Feed Plugin up to 4.13.0 on WordPress and classified as problematic. This vulnerability affects unknown code of the file admin/addon-functions.php of the component Admin Builder Preview

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-96647 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-96647 | Webilia Listdom Plugin up to 6.1.1 on WordPress AJAX lsd[remark] cross site scripting (EUVD-2026-91255)

A vulnerability labeled as problematic has been found in Webilia Listdom Plugin up to 6.1.1 on WordPress. This impacts an unknown function of the component AJAX Handler. Such manipulation of the argument lsd[remark] leads to cross site scri

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-95670 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-95670 | mihdan No External Links Plugin up to 5.2.0 on WordPress cross site scripting (EUVD-2026-91254)

A vulnerability has been found in mihdan No External Links Plugin up to 5.2.0 on WordPress and classified as problematic. Impacted is an unknown function. Performing a manipulation results in cross site scripting. This vulnerability is cata

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-97338 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-97338 | codename065 Download Manager Plugin up to 3.3.70 on WordPress shortcode display name cross site scripting (EUVD-2026-91257)

A vulnerability described as problematic has been identified in codename065 Download Manager Plugin up to 3.3.70 on WordPress. Affected by this vulnerability is an unknown functionality of the component shortcode Handler. Executing a manipu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-94432 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-94432 | Latepoint Appointment Booking Plugin up to 5.7.1 on WordPress PayPal Connect Controller create_order_for_transaction invoice_id resource injection (EUVD-2026-91258)

A vulnerability was found in Latepoint Appointment Booking Plugin up to 5.7.1 on WordPress. It has been rated as critical. The affected element is the function OsPaypalConnectController::create_order_for_transaction of the component PayPal

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.6%
CVE-2026-97637 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-97637 | parorrey JSON API Auth Plugin up to 3.1.2 on WordPress Auth Controller Auth.php wp_generate_auth_cookie insecure improper authentication (EUVD-2026-91259)

A vulnerability identified as critical has been detected in parorrey JSON API Auth Plugin up to 3.1.2 on WordPress. Affected by this vulnerability is the function wp_generate_auth_cookie of the file Auth.php of the component Auth Controller

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-105145 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-105145 | Weaviate Verba up to 2.1.3 generate_stream Endpoint util.py get_environment information disclosure (EUVD-2026-92090)

A vulnerability was found in Weaviate Verba up to 2.1.3. It has been classified as problematic. Affected by this vulnerability is the function get_environment of the file goldenverba/components/util.py of the component generate_stream Endpo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-97307 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-97307 | Stylemixmes Cost Calculator Builder Plugin up to 4.0.17 on WordPress information disclosure (EUVD-2026-92091)

A vulnerability was found in Stylemixmes Cost Calculator Builder Plugin up to 4.0.17 on WordPress. It has been classified as problematic. Affected by this issue is some unknown functionality. This manipulation causes information disclosure.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-105146 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-105146 | Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910 Admin Medal Moderation mod.php modmedalsubmit delete sql injection (EUVD-2026-92092)

A vulnerability was found in Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910. It has been declared as critical. Affected by this issue is the function modmedalsubmit of the file upload/source/app/admin/child/medals/mod.php of the

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100829 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100829 | Mozilla Firefox up to 153.3/156 DOM Security privileges management (WID-SEC-2026-3654)

A vulnerability was found in Mozilla Firefox up to 153.3/156. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component DOM Security. This manipulation causes improper privilege manageme

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100828 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100828 | Mozilla Firefox up to 153.3/156 Bookmarks/History privileges management (WID-SEC-2026-3654)

A vulnerability was found in Mozilla Firefox up to 153.3/156 and classified as critical. Affected is an unknown function of the component Bookmarks/History. The manipulation results in improper privilege management. This vulnerability is id

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100826 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100826 | Mozilla Firefox up to 153.3/156 StorageManager denial of service (WID-SEC-2026-3654)

A vulnerability was found in Mozilla Firefox up to 153.3/156. It has been declared as problematic. The impacted element is an unknown function of the component StorageManager. The manipulation results in denial of service. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100825 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100825 | Mozilla Firefox up to 153.3/156 JIT use after free (WID-SEC-2026-3654)

A vulnerability was found in Mozilla Firefox up to 153.3/156. It has been classified as critical. The affected element is an unknown function of the component JIT. The manipulation leads to use after free. This vulnerability is referenced a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100823 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100823 | Mozilla Firefox up to 156 Downloads data authenticity (WID-SEC-2026-3654)

A vulnerability identified as critical has been detected in Mozilla Firefox up to 156. Affected is an unknown function of the component Downloads. Performing a manipulation results in insufficient verification of data authenticity. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100822 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100822 | Mozilla Firefox up to 153.3/156 Networking HTTP data authenticity (WID-SEC-2026-3654)

A vulnerability was found in Mozilla Firefox up to 153.3/156 and classified as critical. Impacted is an unknown function of the component Networking HTTP. Executing a manipulation can lead to insufficient verification of data authenticity.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100821 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100821 | Mozilla Firefox up to 115.41/140.16/153.3/156 Panning/Zooming isolation (WID-SEC-2026-3654)

A vulnerability, which was classified as critical, was found in Mozilla Firefox up to 115.41/140.16/153.3/156. This vulnerability affects unknown code of the component Panning/Zooming. Such manipulation leads to improper isolation or compar

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100820 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100820 | Mozilla Firefox up to 140.16/153.3/156 Address Bar privileges management (WID-SEC-2026-3654)

A vulnerability classified as critical was found in Mozilla Firefox up to 140.16/153.3/156. Affected by this issue is some unknown functionality of the component Address Bar. The manipulation results in improper privilege management. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Citrix Netscaler aktualisieren! Zero-Day verursacht Crashes und Codeausführung

Sicherheitsforscher und Administratoren melden massenhafte Spontanreboots betroffener Geräte. Updates sind nun verfügbar und sollten schnell aufgespielt werden. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100817 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100817 | Mozilla Firefox up to 156 WebAssembly Remote Code Execution (WID-SEC-2026-3654)

A vulnerability described as critical has been identified in Mozilla Firefox up to 156. Affected is an unknown function of the component WebAssembly. Executing a manipulation can lead to Remote Code Execution. This vulnerability appears as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100816 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100816 | Mozilla Firefox up to 153.3/156 Networking isolation (WID-SEC-2026-3654)

A vulnerability marked as critical has been reported in Mozilla Firefox up to 153.3/156. This impacts an unknown function of the component Networking Component. Performing a manipulation results in improper isolation or compartmentalization

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100815 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100815 | Mozilla Firefox up to 153.3/156 CSS Parsing/Computation use after free (WID-SEC-2026-3654)

A vulnerability labeled as critical has been found in Mozilla Firefox up to 153.3/156. This affects an unknown function of the component CSS Parsing/Computation. Such manipulation leads to use after free. This vulnerability is documented as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-100814 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100814 | Mozilla Firefox up to 153.3/156 JIT out-of-bounds (WID-SEC-2026-3654)

A vulnerability identified as critical has been detected in Mozilla Firefox up to 153.3/156. The impacted element is an unknown function of the component JIT. This manipulation causes out-of-bounds read. This vulnerability is registered as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100813 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100813 | Mozilla Firefox up to 156 JIT memory corruption (WID-SEC-2026-3654)

A vulnerability categorized as critical has been discovered in Mozilla Firefox up to 156. The affected element is an unknown function of the component JIT. The manipulation results in memory corruption. This vulnerability is cataloged as CV

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-100811 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100811 | Mozilla Firefox up to 140.16/153.3/156 DOM Core/HTML use after free (WID-SEC-2026-3654)

A vulnerability was found in Mozilla Firefox up to 140.16/153.3/156. It has been declared as critical. This issue affects some unknown processing of the component DOM Core/HTML Component. Executing a manipulation can lead to use after free.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-100810 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100810 | Mozilla Firefox up to 156 DevTools Remote Code Execution (WID-SEC-2026-3654)

A vulnerability was found in Mozilla Firefox up to 156 and classified as critical. This affects an unknown part of the component DevTools. Such manipulation leads to Remote Code Execution. This vulnerability is referenced as CVE-2026-100810

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100809 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100809 | Mozilla Firefox up to 153.3/156 DevTools cross-domain policy (WID-SEC-2026-3654)

A vulnerability has been found in Mozilla Firefox up to 153.3/156 and classified as problematic. Affected by this issue is some unknown functionality of the component DevTools. This manipulation causes permissive cross-domain policy with un

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100808 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100808 | Mozilla Firefox up to 153.3/156 Service Workers unnecessary privileges (WID-SEC-2026-3654)

A vulnerability has been found in Mozilla Firefox up to 153.3/156 and classified as critical. This impacts an unknown function of the component Service Workers. The manipulation leads to execution with unnecessary privileges. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-64781 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-64781 | Japan Total System GroupSession Free Edition External Page insecure default initialization of resource

A vulnerability described as problematic has been identified in Japan Total System GroupSession Free Edition, GroupSession byCloud and GroupSession ZION. This affects an unknown part of the component External Page. The manipulation results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2024-58300 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-58300 | Siklu MultiHaul TG 1.x Network Request missing authentication (Exploit 51932 / EDB-51932)

A vulnerability was found in Siklu MultiHaul TG 1.x. It has been declared as critical. This affects an unknown function of the component Network Request Handler. Executing a manipulation can lead to missing authentication. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 1%
CVE-2024-58298 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-58298 | BMC Compuware iStrobe Web 20.13 JSP Endpoint fileName unrestricted upload (Exploit 51991 / EDB-51991)

A vulnerability was found in BMC Compuware iStrobe Web 20.13 and classified as critical. This vulnerability affects unknown code of the component JSP Endpoint. The manipulation of the argument fileName results in unrestricted upload. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2024-58296 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-58296 | PhoenixCart CE Phoenix 1.0.8.20 Administration Panel title cross site scripting (Exploit 52015 / EDB-52015)

A vulnerability was found in PhoenixCart CE Phoenix 1.0.8.20. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Administration Panel. Such manipulation of the argument Title leads to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.6%
CVE-2024-58295 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-58295 | ElkArte Forum 1.1.9 unrestricted upload (Exploit 52026 / EDB-52026)

A vulnerability marked as critical has been reported in ElkArte Forum 1.1.9. Affected by this issue is some unknown functionality. This manipulation causes unrestricted upload. This vulnerability is handled as CVE-2024-58295. The attack can

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2024-58292 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-58292 | xmbforum2 XMB Forum 1.9.12.06 Setting cross site scripting (Exploit 52044 / EDB-52044)

A vulnerability classified as problematic was found in xmbforum2 XMB Forum 1.9.12.06. This impacts an unknown function of the component Setting Handler. Executing a manipulation can lead to cross site scripting. This vulnerability is regist

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2024-58290 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-58290 | Xhibiter NFT Marketplace 1.10.2 Collections Endpoint id sql injection (Exploit 52060 / EDB-52060)

A vulnerability classified as critical was found in Xhibiter NFT Marketplace 1.10.2. This affects an unknown function of the component Collections Endpoint. Such manipulation of the argument ID leads to sql injection. This vulnerability is

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2024-58288 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2024-58288 | Genexus Protection Server 9.7.2.10 Windows Service unquoted search path (Exploit 52065 / EDB-52065)

A vulnerability, which was classified as problematic, was found in Genexus Protection Server 9.7.2.10. This vulnerability affects unknown code of the component Windows Service. Such manipulation leads to unquoted search path. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2024-42197 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-42197 | HCL Workload Scheduler prior 10.2.3 credentials storage (KB0127448)

A vulnerability has been found in HCL Workload Scheduler prior 10.2.3 and classified as problematic. Affected by this issue is some unknown functionality. This manipulation causes unprotected storage of credentials. This vulnerability appea

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-100806 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100806 | Mozilla Firefox up to 153.3/156 WebGPU uninitialized pointer (WID-SEC-2026-3654)

A vulnerability, which was classified as critical, was found in Mozilla Firefox up to 153.3/156. Affected by this vulnerability is an unknown functionality of the component WebGPU. The manipulation results in uninitialized pointer. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100805 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100805 | Mozilla Firefox up to 156 Audio/Video use after free (WID-SEC-2026-3654)

A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 156. Affected is an unknown function of the component Audio/Video. The manipulation leads to use after free. This vulnerability is uniquely identifie

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-100804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100804 | Mozilla Firefox up to 156 Preferences Backend use after free (WID-SEC-2026-3654)

A vulnerability classified as critical was found in Mozilla Firefox up to 156. This impacts an unknown function of the component Preferences Backend. Executing a manipulation can lead to use after free. This vulnerability is handled as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100803 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100803 | Mozilla Firefox up to 115.41/140.16/153.3/156 WebExtensions cross-domain policy (WID-SEC-2026-3654)

A vulnerability classified as problematic has been found in Mozilla Firefox up to 115.41/140.16/153.3/156. This affects an unknown function of the component WebExtensions. Performing a manipulation results in permissive cross-domain policy

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100802 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100802 | Mozilla Firefox up to 156 WebGPU uninitialized pointer (WID-SEC-2026-3654)

A vulnerability described as critical has been identified in Mozilla Firefox up to 156. The impacted element is an unknown function of the component WebGPU. Such manipulation leads to uninitialized pointer. This vulnerability is traded as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100801 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100801 | Mozilla Firefox up to 140.16/153.3/156 DLL Services privileges management (WID-SEC-2026-3654)

A vulnerability marked as critical has been reported in Mozilla Firefox up to 140.16/153.3/156. The affected element is an unknown function of the component DLL Services. This manipulation causes improper privilege management. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-100800 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100800 | Mozilla Firefox up to 153.3/156 Disability Access APIs use after free (WID-SEC-2026-3654)

A vulnerability labeled as critical has been found in Mozilla Firefox up to 153.3/156. Impacted is an unknown function of the component Disability Access APIs. The manipulation results in use after free. This vulnerability is reported as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100799 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100799 | Mozilla Firefox up to 156 WebGPU uninitialized pointer (WID-SEC-2026-3654)

A vulnerability identified as critical has been detected in Mozilla Firefox up to 156. This issue affects some unknown processing of the component WebGPU. The manipulation leads to uninitialized pointer. This vulnerability is documented as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-100798 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100798 | Mozilla Firefox up to 153.3/156 Quota Manager risky encryption (WID-SEC-2026-3654)

A vulnerability, which was classified as problematic, was found in Mozilla Firefox up to 153.3/156. This affects an unknown function of the component Quota Manager. Executing a manipulation can lead to risky cryptographic algorithm. The ide

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-100797 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100797 | Mozilla Firefox up to 115.41/140.16/153.3/156 WebRender use after free (WID-SEC-2026-3654)

A vulnerability classified as critical has been found in Mozilla Firefox up to 115.41/140.16/153.3/156. Impacted is an unknown function of the component WebRender. This manipulation causes use after free. This vulnerability is handled as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-100796 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-100796 | Mozilla Firefox up to 156 WebAssembly use after free (WID-SEC-2026-3654)

A vulnerability categorized as critical has been discovered in Mozilla Firefox up to 156. This vulnerability affects unknown code of the component WebAssembly. Executing a manipulation can lead to use after free. This vulnerability is regis

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-87920 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-87920 | BoldGrid W3 Total Cache Plugin up to 2.10.6 on WordPress Output-Buffer Regex Rewrite mutate_url cross site scripting (EUVD-2026-91335)

A vulnerability marked as problematic has been reported in BoldGrid W3 Total Cache Plugin up to 2.10.6 on WordPress. This affects the function mutate_url of the component Output-Buffer Regex Rewrite. Performing a manipulation results in cro

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-85492 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-85492 | All in One SEO Plugin up to 5.0.1.1 on WordPress cross site scripting (EUVD-2026-91336)

A vulnerability, which was classified as problematic, was found in All in One SEO Plugin up to 5.0.1.1 on WordPress. This affects an unknown part. Such manipulation leads to cross site scripting. This vulnerability is referenced as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-97641 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-97641 | comesio Relevanssi Plugin up to 4.28.3 on WordPress cross site scripting (EUVD-2026-91244)

A vulnerability identified as problematic has been detected in comesio Relevanssi Plugin up to 4.28.3 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability is traded as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-12951 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-12951 | WCMP Multi Vendor Plugin up to 5.0.18 on WordPress Report Abuse report-abuse order_by sql injection (EUVD-2026-91246)

A vulnerability was found in WCMP Multi Vendor Plugin up to 5.0.18 on WordPress. It has been classified as critical. This issue affects some unknown processing of the file /multivendorx/v1/compliance/report-abuse of the component Report Abu

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-97276 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-97276 | VeronaLabs WP Statistics Plugin up to 14.16.14 on WordPress cross site scripting (EUVD-2026-92083)

A vulnerability identified as problematic has been detected in VeronaLabs WP Statistics Plugin up to 14.16.14 on WordPress. This affects an unknown part. Performing a manipulation results in cross site scripting. This vulnerability is known

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-103354 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-103354 | Liquid Web/StellarWP Gutenberg Blocks by Kadence Blocks Plugin up to 3.7.11.1 on WordPress cross site scripting (EUVD-2026-92082)

A vulnerability categorized as problematic has been discovered in Liquid Web/StellarWP Gutenberg Blocks by Kadence Blocks Plugin up to 3.7.11.1 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-105141 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-105141 | topoteretes cognee up to 1.5.4 JWT Signing Key get_api_auth_backend.py get_user_id_by_email FASTAPI_USERS_JWT_SECRET hard-coded credentials (ID 5062 / EUVD-2026-92086)

A vulnerability classified as critical was found in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
60 von ~0 Einträgen geladen Ende der Trefferliste — 60 Einträge geladen. Tipp: Filter leichtern für tieferes Blättern.