Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-20 | 2026-10-04 |
|---|---|---|
| ≥90 % | 489 | 361 |
| ≥50 % | 1477 | 1099 |
| ≥10 % | 0 | 2 |
| <10 % | 0 | 505 |
CVE-2025-12926 | SourceCodester Farm Management System 1.0 /review.php pid sql injection (EUVD-2025-38734 / CNNVD-202511-976)
A vulnerability classified as critical has been found in SourceCodester Farm Management System 1.0. The affected element is an unknown function of the file /review.php. This manipulation of the argument pid causes sql injection. This vulner
CVE-2025-12925 | rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224 UserDicController.java getAll/addDic/getAllDic/deleteDic authorization (Issue 199 / EUVD-2025-38727)
A vulnerability described as critical has been identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserD
CVE-2025-12431 | Google Chrome up to 141.0.7390.122 Extensions authentication bypass (Nessus ID 272077 / WID-SEC-2025-2445)
A vulnerability was found in Google Chrome. It has been rated as critical. Affected by this issue is some unknown functionality of the component Extensions. Performing a manipulation results in authentication bypass using alternate channel.
CVE-2025-12430 | Google Chrome up to 141.0.7390.122 Media round.about authentication spoofing (Nessus ID 272077 / WID-SEC-2025-2445)
A vulnerability was found in Google Chrome and classified as critical. This impacts an unknown function of the file round.about of the component Media. The manipulation results in authentication bypass by spoofing. This vulnerability was na
CVE-2025-12429 | Google Chrome up to 141.0.7390.122 V8 Remote Code Execution (Nessus ID 272077 / WID-SEC-2025-2445)
A vulnerability marked as critical has been reported in Google Chrome. Impacted is an unknown function of the component V8. This manipulation causes Remote Code Execution. This vulnerability is registered as CVE-2025-12429. Remote exploitat
CVE-2025-12428 | Google Chrome up to 141.0.7390.122 V8 type confusion (Nessus ID 272077 / WID-SEC-2025-2445)
A vulnerability has been found in Google Chrome and classified as critical. This affects an unknown function of the component V8. The manipulation leads to type confusion. This vulnerability is uniquely identified as CVE-2025-12428. The att
CVE-2026-93756 | Smash Balloon Social Post Feed Plugin up to 4.13.0 on WordPress Admin Builder Preview/AJAX addon-functions.php cross site scripting (EUVD-2026-91253)
A vulnerability was found in Smash Balloon Social Post Feed Plugin up to 4.13.0 on WordPress and classified as problematic. This vulnerability affects unknown code of the file admin/addon-functions.php of the component Admin Builder Preview
CVE-2026-96647 | Webilia Listdom Plugin up to 6.1.1 on WordPress AJAX lsd[remark] cross site scripting (EUVD-2026-91255)
A vulnerability labeled as problematic has been found in Webilia Listdom Plugin up to 6.1.1 on WordPress. This impacts an unknown function of the component AJAX Handler. Such manipulation of the argument lsd[remark] leads to cross site scri
CVE-2026-95670 | mihdan No External Links Plugin up to 5.2.0 on WordPress cross site scripting (EUVD-2026-91254)
A vulnerability has been found in mihdan No External Links Plugin up to 5.2.0 on WordPress and classified as problematic. Impacted is an unknown function. Performing a manipulation results in cross site scripting. This vulnerability is cata
CVE-2026-97338 | codename065 Download Manager Plugin up to 3.3.70 on WordPress shortcode display name cross site scripting (EUVD-2026-91257)
A vulnerability described as problematic has been identified in codename065 Download Manager Plugin up to 3.3.70 on WordPress. Affected by this vulnerability is an unknown functionality of the component shortcode Handler. Executing a manipu
CVE-2026-94432 | Latepoint Appointment Booking Plugin up to 5.7.1 on WordPress PayPal Connect Controller create_order_for_transaction invoice_id resource injection (EUVD-2026-91258)
A vulnerability was found in Latepoint Appointment Booking Plugin up to 5.7.1 on WordPress. It has been rated as critical. The affected element is the function OsPaypalConnectController::create_order_for_transaction of the component PayPal
CVE-2026-97637 | parorrey JSON API Auth Plugin up to 3.1.2 on WordPress Auth Controller Auth.php wp_generate_auth_cookie insecure improper authentication (EUVD-2026-91259)
A vulnerability identified as critical has been detected in parorrey JSON API Auth Plugin up to 3.1.2 on WordPress. Affected by this vulnerability is the function wp_generate_auth_cookie of the file Auth.php of the component Auth Controller
CVE-2026-105145 | Weaviate Verba up to 2.1.3 generate_stream Endpoint util.py get_environment information disclosure (EUVD-2026-92090)
A vulnerability was found in Weaviate Verba up to 2.1.3. It has been classified as problematic. Affected by this vulnerability is the function get_environment of the file goldenverba/components/util.py of the component generate_stream Endpo
CVE-2026-97307 | Stylemixmes Cost Calculator Builder Plugin up to 4.0.17 on WordPress information disclosure (EUVD-2026-92091)
A vulnerability was found in Stylemixmes Cost Calculator Builder Plugin up to 4.0.17 on WordPress. It has been classified as problematic. Affected by this issue is some unknown functionality. This manipulation causes information disclosure.
CVE-2026-105146 | Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910 Admin Medal Moderation mod.php modmedalsubmit delete sql injection (EUVD-2026-92092)
A vulnerability was found in Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910. It has been declared as critical. Affected by this issue is the function modmedalsubmit of the file upload/source/app/admin/child/medals/mod.php of the
CVE-2026-100829 | Mozilla Firefox up to 153.3/156 DOM Security privileges management (WID-SEC-2026-3654)
A vulnerability was found in Mozilla Firefox up to 153.3/156. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component DOM Security. This manipulation causes improper privilege manageme
CVE-2026-100828 | Mozilla Firefox up to 153.3/156 Bookmarks/History privileges management (WID-SEC-2026-3654)
A vulnerability was found in Mozilla Firefox up to 153.3/156 and classified as critical. Affected is an unknown function of the component Bookmarks/History. The manipulation results in improper privilege management. This vulnerability is id
CVE-2026-100826 | Mozilla Firefox up to 153.3/156 StorageManager denial of service (WID-SEC-2026-3654)
A vulnerability was found in Mozilla Firefox up to 153.3/156. It has been declared as problematic. The impacted element is an unknown function of the component StorageManager. The manipulation results in denial of service. This vulnerabilit
CVE-2026-100825 | Mozilla Firefox up to 153.3/156 JIT use after free (WID-SEC-2026-3654)
A vulnerability was found in Mozilla Firefox up to 153.3/156. It has been classified as critical. The affected element is an unknown function of the component JIT. The manipulation leads to use after free. This vulnerability is referenced a
CVE-2026-100823 | Mozilla Firefox up to 156 Downloads data authenticity (WID-SEC-2026-3654)
A vulnerability identified as critical has been detected in Mozilla Firefox up to 156. Affected is an unknown function of the component Downloads. Performing a manipulation results in insufficient verification of data authenticity. This vul
CVE-2026-100822 | Mozilla Firefox up to 153.3/156 Networking HTTP data authenticity (WID-SEC-2026-3654)
A vulnerability was found in Mozilla Firefox up to 153.3/156 and classified as critical. Impacted is an unknown function of the component Networking HTTP. Executing a manipulation can lead to insufficient verification of data authenticity.
CVE-2026-100821 | Mozilla Firefox up to 115.41/140.16/153.3/156 Panning/Zooming isolation (WID-SEC-2026-3654)
A vulnerability, which was classified as critical, was found in Mozilla Firefox up to 115.41/140.16/153.3/156. This vulnerability affects unknown code of the component Panning/Zooming. Such manipulation leads to improper isolation or compar
CVE-2026-100820 | Mozilla Firefox up to 140.16/153.3/156 Address Bar privileges management (WID-SEC-2026-3654)
A vulnerability classified as critical was found in Mozilla Firefox up to 140.16/153.3/156. Affected by this issue is some unknown functionality of the component Address Bar. The manipulation results in improper privilege management. This v
Citrix Netscaler aktualisieren! Zero-Day verursacht Crashes und Codeausführung
Sicherheitsforscher und Administratoren melden massenhafte Spontanreboots betroffener Geräte. Updates sind nun verfügbar und sollten schnell aufgespielt werden. Weiterlesen
CVE-2026-100817 | Mozilla Firefox up to 156 WebAssembly Remote Code Execution (WID-SEC-2026-3654)
A vulnerability described as critical has been identified in Mozilla Firefox up to 156. Affected is an unknown function of the component WebAssembly. Executing a manipulation can lead to Remote Code Execution. This vulnerability appears as
CVE-2026-100816 | Mozilla Firefox up to 153.3/156 Networking isolation (WID-SEC-2026-3654)
A vulnerability marked as critical has been reported in Mozilla Firefox up to 153.3/156. This impacts an unknown function of the component Networking Component. Performing a manipulation results in improper isolation or compartmentalization
CVE-2026-100815 | Mozilla Firefox up to 153.3/156 CSS Parsing/Computation use after free (WID-SEC-2026-3654)
A vulnerability labeled as critical has been found in Mozilla Firefox up to 153.3/156. This affects an unknown function of the component CSS Parsing/Computation. Such manipulation leads to use after free. This vulnerability is documented as
CVE-2026-100814 | Mozilla Firefox up to 153.3/156 JIT out-of-bounds (WID-SEC-2026-3654)
A vulnerability identified as critical has been detected in Mozilla Firefox up to 153.3/156. The impacted element is an unknown function of the component JIT. This manipulation causes out-of-bounds read. This vulnerability is registered as
CVE-2026-100813 | Mozilla Firefox up to 156 JIT memory corruption (WID-SEC-2026-3654)
A vulnerability categorized as critical has been discovered in Mozilla Firefox up to 156. The affected element is an unknown function of the component JIT. The manipulation results in memory corruption. This vulnerability is cataloged as CV
CVE-2026-100811 | Mozilla Firefox up to 140.16/153.3/156 DOM Core/HTML use after free (WID-SEC-2026-3654)
A vulnerability was found in Mozilla Firefox up to 140.16/153.3/156. It has been declared as critical. This issue affects some unknown processing of the component DOM Core/HTML Component. Executing a manipulation can lead to use after free.
CVE-2026-100810 | Mozilla Firefox up to 156 DevTools Remote Code Execution (WID-SEC-2026-3654)
A vulnerability was found in Mozilla Firefox up to 156 and classified as critical. This affects an unknown part of the component DevTools. Such manipulation leads to Remote Code Execution. This vulnerability is referenced as CVE-2026-100810
CVE-2026-100809 | Mozilla Firefox up to 153.3/156 DevTools cross-domain policy (WID-SEC-2026-3654)
A vulnerability has been found in Mozilla Firefox up to 153.3/156 and classified as problematic. Affected by this issue is some unknown functionality of the component DevTools. This manipulation causes permissive cross-domain policy with un
CVE-2026-100808 | Mozilla Firefox up to 153.3/156 Service Workers unnecessary privileges (WID-SEC-2026-3654)
A vulnerability has been found in Mozilla Firefox up to 153.3/156 and classified as critical. This impacts an unknown function of the component Service Workers. The manipulation leads to execution with unnecessary privileges. This vulnerabi
CVE-2025-64781 | Japan Total System GroupSession Free Edition External Page insecure default initialization of resource
A vulnerability described as problematic has been identified in Japan Total System GroupSession Free Edition, GroupSession byCloud and GroupSession ZION. This affects an unknown part of the component External Page. The manipulation results
CVE-2024-58300 | Siklu MultiHaul TG 1.x Network Request missing authentication (Exploit 51932 / EDB-51932)
A vulnerability was found in Siklu MultiHaul TG 1.x. It has been declared as critical. This affects an unknown function of the component Network Request Handler. Executing a manipulation can lead to missing authentication. This vulnerabilit
CVE-2024-58298 | BMC Compuware iStrobe Web 20.13 JSP Endpoint fileName unrestricted upload (Exploit 51991 / EDB-51991)
A vulnerability was found in BMC Compuware iStrobe Web 20.13 and classified as critical. This vulnerability affects unknown code of the component JSP Endpoint. The manipulation of the argument fileName results in unrestricted upload. This v
CVE-2024-58296 | PhoenixCart CE Phoenix 1.0.8.20 Administration Panel title cross site scripting (Exploit 52015 / EDB-52015)
A vulnerability was found in PhoenixCart CE Phoenix 1.0.8.20. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Administration Panel. Such manipulation of the argument Title leads to
CVE-2024-58295 | ElkArte Forum 1.1.9 unrestricted upload (Exploit 52026 / EDB-52026)
A vulnerability marked as critical has been reported in ElkArte Forum 1.1.9. Affected by this issue is some unknown functionality. This manipulation causes unrestricted upload. This vulnerability is handled as CVE-2024-58295. The attack can
CVE-2024-58292 | xmbforum2 XMB Forum 1.9.12.06 Setting cross site scripting (Exploit 52044 / EDB-52044)
A vulnerability classified as problematic was found in xmbforum2 XMB Forum 1.9.12.06. This impacts an unknown function of the component Setting Handler. Executing a manipulation can lead to cross site scripting. This vulnerability is regist
CVE-2024-58290 | Xhibiter NFT Marketplace 1.10.2 Collections Endpoint id sql injection (Exploit 52060 / EDB-52060)
A vulnerability classified as critical was found in Xhibiter NFT Marketplace 1.10.2. This affects an unknown function of the component Collections Endpoint. Such manipulation of the argument ID leads to sql injection. This vulnerability is
CVE-2024-58288 | Genexus Protection Server 9.7.2.10 Windows Service unquoted search path (Exploit 52065 / EDB-52065)
A vulnerability, which was classified as problematic, was found in Genexus Protection Server 9.7.2.10. This vulnerability affects unknown code of the component Windows Service. Such manipulation leads to unquoted search path. This vulnerabi
CVE-2024-42197 | HCL Workload Scheduler prior 10.2.3 credentials storage (KB0127448)
A vulnerability has been found in HCL Workload Scheduler prior 10.2.3 and classified as problematic. Affected by this issue is some unknown functionality. This manipulation causes unprotected storage of credentials. This vulnerability appea
CVE-2026-100806 | Mozilla Firefox up to 153.3/156 WebGPU uninitialized pointer (WID-SEC-2026-3654)
A vulnerability, which was classified as critical, was found in Mozilla Firefox up to 153.3/156. Affected by this vulnerability is an unknown functionality of the component WebGPU. The manipulation results in uninitialized pointer. This vul
CVE-2026-100805 | Mozilla Firefox up to 156 Audio/Video use after free (WID-SEC-2026-3654)
A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 156. Affected is an unknown function of the component Audio/Video. The manipulation leads to use after free. This vulnerability is uniquely identifie
CVE-2026-100804 | Mozilla Firefox up to 156 Preferences Backend use after free (WID-SEC-2026-3654)
A vulnerability classified as critical was found in Mozilla Firefox up to 156. This impacts an unknown function of the component Preferences Backend. Executing a manipulation can lead to use after free. This vulnerability is handled as CVE-
CVE-2026-100803 | Mozilla Firefox up to 115.41/140.16/153.3/156 WebExtensions cross-domain policy (WID-SEC-2026-3654)
A vulnerability classified as problematic has been found in Mozilla Firefox up to 115.41/140.16/153.3/156. This affects an unknown function of the component WebExtensions. Performing a manipulation results in permissive cross-domain policy
CVE-2026-100802 | Mozilla Firefox up to 156 WebGPU uninitialized pointer (WID-SEC-2026-3654)
A vulnerability described as critical has been identified in Mozilla Firefox up to 156. The impacted element is an unknown function of the component WebGPU. Such manipulation leads to uninitialized pointer. This vulnerability is traded as C
CVE-2026-100801 | Mozilla Firefox up to 140.16/153.3/156 DLL Services privileges management (WID-SEC-2026-3654)
A vulnerability marked as critical has been reported in Mozilla Firefox up to 140.16/153.3/156. The affected element is an unknown function of the component DLL Services. This manipulation causes improper privilege management. This vulnerab
CVE-2026-100800 | Mozilla Firefox up to 153.3/156 Disability Access APIs use after free (WID-SEC-2026-3654)
A vulnerability labeled as critical has been found in Mozilla Firefox up to 153.3/156. Impacted is an unknown function of the component Disability Access APIs. The manipulation results in use after free. This vulnerability is reported as CV
CVE-2026-100799 | Mozilla Firefox up to 156 WebGPU uninitialized pointer (WID-SEC-2026-3654)
A vulnerability identified as critical has been detected in Mozilla Firefox up to 156. This issue affects some unknown processing of the component WebGPU. The manipulation leads to uninitialized pointer. This vulnerability is documented as
CVE-2026-100798 | Mozilla Firefox up to 153.3/156 Quota Manager risky encryption (WID-SEC-2026-3654)
A vulnerability, which was classified as problematic, was found in Mozilla Firefox up to 153.3/156. This affects an unknown function of the component Quota Manager. Executing a manipulation can lead to risky cryptographic algorithm. The ide
CVE-2026-100797 | Mozilla Firefox up to 115.41/140.16/153.3/156 WebRender use after free (WID-SEC-2026-3654)
A vulnerability classified as critical has been found in Mozilla Firefox up to 115.41/140.16/153.3/156. Impacted is an unknown function of the component WebRender. This manipulation causes use after free. This vulnerability is handled as CV
CVE-2026-100796 | Mozilla Firefox up to 156 WebAssembly use after free (WID-SEC-2026-3654)
A vulnerability categorized as critical has been discovered in Mozilla Firefox up to 156. This vulnerability affects unknown code of the component WebAssembly. Executing a manipulation can lead to use after free. This vulnerability is regis
CVE-2026-87920 | BoldGrid W3 Total Cache Plugin up to 2.10.6 on WordPress Output-Buffer Regex Rewrite mutate_url cross site scripting (EUVD-2026-91335)
A vulnerability marked as problematic has been reported in BoldGrid W3 Total Cache Plugin up to 2.10.6 on WordPress. This affects the function mutate_url of the component Output-Buffer Regex Rewrite. Performing a manipulation results in cro
CVE-2026-85492 | All in One SEO Plugin up to 5.0.1.1 on WordPress cross site scripting (EUVD-2026-91336)
A vulnerability, which was classified as problematic, was found in All in One SEO Plugin up to 5.0.1.1 on WordPress. This affects an unknown part. Such manipulation leads to cross site scripting. This vulnerability is referenced as CVE-2026
CVE-2026-97641 | comesio Relevanssi Plugin up to 4.28.3 on WordPress cross site scripting (EUVD-2026-91244)
A vulnerability identified as problematic has been detected in comesio Relevanssi Plugin up to 4.28.3 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability is traded as CVE
CVE-2026-12951 | WCMP Multi Vendor Plugin up to 5.0.18 on WordPress Report Abuse report-abuse order_by sql injection (EUVD-2026-91246)
A vulnerability was found in WCMP Multi Vendor Plugin up to 5.0.18 on WordPress. It has been classified as critical. This issue affects some unknown processing of the file /multivendorx/v1/compliance/report-abuse of the component Report Abu
CVE-2026-97276 | VeronaLabs WP Statistics Plugin up to 14.16.14 on WordPress cross site scripting (EUVD-2026-92083)
A vulnerability identified as problematic has been detected in VeronaLabs WP Statistics Plugin up to 14.16.14 on WordPress. This affects an unknown part. Performing a manipulation results in cross site scripting. This vulnerability is known
CVE-2026-103354 | Liquid Web/StellarWP Gutenberg Blocks by Kadence Blocks Plugin up to 3.7.11.1 on WordPress cross site scripting (EUVD-2026-92082)
A vulnerability categorized as problematic has been discovered in Liquid Web/StellarWP Gutenberg Blocks by Kadence Blocks Plugin up to 3.7.11.1 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to c
CVE-2026-105141 | topoteretes cognee up to 1.5.4 JWT Signing Key get_api_auth_backend.py get_user_id_by_email FASTAPI_USERS_JWT_SECRET hard-coded credentials (ID 5062 / EUVD-2026-92086)
A vulnerability classified as critical was found in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signi