🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

375k+ 🇪🇺 EUVD-Datenbank
27 🔴 Critical im Radar
1 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
116 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-11: 257 Nov 25 2025-12: 426 2026-01: 431 Jan 26 2026-02: 417 2026-03: 649 Mär 26 2026-04: 574 2026-05: 682 Mai 26 2026-06: 941 2026-07: 1327 Jul 26 2026-08: 1827 2026-09: 1513 Sep 26 2026-10: 397 9.441 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Apache Software Foundation Google IBM Linux Microsoft Oracle Corporation
● Apache ● Google ● IBM ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
TierCVEsAnteil
≥90 %7200,2 %
≥50 %3.2230,9 %
≥10 %22.1156,0 %
<10 %342.37392,9 %
368.431 CVEs mit EPSS-Score (FIRST.org) · Stand 10.10.2026
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 99.196 Einträge):
Zeitfenster:
Quelle:
🔍
● 1 Filter aktiv Alles zurücksetzen ✕
– OHNE BEWERTUNG
EPSS
CVE-2026-97396 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-97396 | Retainful Email Marketing for WooCommerce Plugin up to 1.0.10 on WordPress data cross site scripting (EUVD-2026-96280)

A vulnerability described as problematic has been identified in Retainful Email Marketing for WooCommerce Plugin up to 1.0.10 on WordPress. This affects an unknown part. Executing a manipulation of the argument data can lead to cross site s

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-96765 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-96765 | WPO365 Plugin up to 44.1 on WordPress id_token cross site scripting (EUVD-2026-96281)

A vulnerability was found in WPO365 Plugin up to 44.1 on WordPress and classified as problematic. Impacted is an unknown function. Such manipulation of the argument id_token leads to cross site scripting. This vulnerability is listed as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-104803 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-104803 | whyun WPCOM Member Plugin up to 1.7.27 on WordPress Social Login Callback weapp_new_user uuid/code improper authentication (EUVD-2026-96279)

A vulnerability marked as critical has been reported in whyun WPCOM Member Plugin up to 1.7.27 on WordPress. This impacts the function weapp_new_user of the component Social Login Callback Handler. This manipulation of the argument uuid/cod

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-96653 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-96653 | WP Directory Kit Plugin up to 1.5.9 on WordPress Profile Field update_listings_user_editor display_name sql injection (EUVD-2026-96283)

A vulnerability was found in WP Directory Kit Plugin up to 1.5.9 on WordPress. It has been rated as critical. This affects the function WdkCachedUserEditor::update_listings_user_editor of the component Profile Field. The manipulation of the

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-100178 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-100178 | WPAdverts Plugin up to 2.3.4 on WordPress adverts_location cross site scripting (EUVD-2026-96282)

A vulnerability, which was classified as problematic, was found in WPAdverts Plugin up to 2.3.4 on WordPress. This vulnerability affects unknown code. The manipulation of the argument adverts_location results in cross site scripting. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-104728 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-104728 | rubengc AutomatorWP Plugin up to 5.8.4 on WordPress authorization (EUVD-2026-96284)

A vulnerability classified as problematic has been found in rubengc AutomatorWP Plugin up to 5.8.4 on WordPress. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in authorization bypass. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-102774 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-102774 | BrainstormForce SureDash Plugin up to 1.12.1 on WordPress Post Content cross site scripting (EUVD-2026-96285)

A vulnerability classified as problematic was found in BrainstormForce SureDash Plugin up to 1.12.1 on WordPress. Affected by this issue is some unknown functionality of the component Post Content. Executing a manipulation can lead to cross

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-104759 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-104759 | WPO365 Plugin up to 44.1 on WordPress Deprecated Parser process_openidconnect_token id_token authentication replay (EUVD-2026-96286)

A vulnerability identified as critical has been detected in WPO365 Plugin up to 44.1 on WordPress. The impacted element is the function Id_Token_Service_Deprecated::process_openidconnect_token of the component Deprecated Parser. The manipul

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-102291 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-102291 | meum Kirki Plugin up to 6.3.1 on WordPress Shortcode Execution replace_content display_name command injection (EUVD-2026-96287)

A vulnerability labeled as critical has been found in meum Kirki Plugin up to 6.3.1 on WordPress. This affects the function TheFrontend::replace_content of the component Shortcode Execution. The manipulation of the argument display_name res

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-97340 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-97340 | meFusion Avada up to 7.16.1 on WordPress Author Page get_markup cross site scripting (EUVD-2026-96288)

A vulnerability was found in meFusion Avada up to 7.16.1 on WordPress. It has been declared as problematic. The impacted element is the function Fusion_Social_Icon::get_markup of the component Author Page. Executing a manipulation of the ar

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-93746 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-93746 | WebToffee PDF Invoices Packing Slips Delivery Notes & Shipping Labels Plugin print_document_from_the_mail_link resource injection (EUVD-2026-96289)

A vulnerability categorized as problematic has been discovered in WebToffee PDF Invoices Packing Slips Delivery Notes &amp;amp; Shipping Labels Plugin up to 5.0.2 on WordPress. This impacts the function print_document_from_the_mail_link. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-103478 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-103478 | codename065 Premium Packages Plugin up to 7.2.6 on WordPress phone/state/taxid/email cross site scripting (EUVD-2026-96290)

A vulnerability was found in codename065 Premium Packages Plugin up to 7.2.6 on WordPress. It has been classified as problematic. The affected element is an unknown function. Performing a manipulation of the argument phone/state/taxid/email

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-93951 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-93951 | Bracketweb Zeinet Plugin up to 1.0.0 on WordPress cross site scripting (EUVD-2026-96291)

A vulnerability classified as problematic has been found in Bracketweb Zeinet Plugin up to 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability is uniquely identifie

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-107325 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-107325 | MongoDB Go Driver up to 1.17.10/2.9.1 bson.RawArray.Validate out-of-bounds (EUVD-2026-95170 / WID-SEC-2026-3830)

A vulnerability was found in MongoDB Go Driver up to 1.17.10/2.9.1 and classified as critical. Impacted is the function bson.RawArray.Validate. Executing a manipulation can lead to out-of-bounds read. This vulnerability is tracked as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-107324 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-107324 | MongoDB Go Driver up to 1.1.x/2.8.x BSON Value-Length integer overflow (EUVD-2026-95165 / WID-SEC-2026-3830)

A vulnerability has been found in MongoDB Go Driver up to 1.1.x/2.8.x and classified as critical. This issue affects some unknown processing of the component BSON Value-Length Handler. Performing a manipulation results in integer overflow.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-106431 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-106431 | MongoDB C Driver up to 1.30.12/2.5.5 BSON Bulk Writer off-by-one (WID-SEC-2026-3830)

A vulnerability was found in MongoDB C Driver up to 1.30.12/2.5.5 and classified as problematic. This affects an unknown part of the component BSON Bulk Writer. Such manipulation leads to off-by-one. This vulnerability is listed as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-106436 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-106436 | MongoDB PHP Driver up to 1.21.10/2.1.10/2.5.3 BSON Encoder return value (WID-SEC-2026-3830)

A vulnerability categorized as critical has been discovered in MongoDB PHP Driver up to 1.21.10/2.1.10/2.5.3. This impacts an unknown function of the component BSON Encoder. Such manipulation leads to unchecked return value. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-106434 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-106434 | MongoDB libmongocrypt up to 1.20.4 Explicit Decryption missing encryption (WID-SEC-2026-3830)

A vulnerability described as problematic has been identified in MongoDB libmongocrypt up to 1.20.4. Affected is an unknown function of the component Explicit Decryption Component. Executing a manipulation can lead to missing encryption of s

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-106433 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-106433 | MongoDB libmongocrypt up to 1.20.4 state issue (WID-SEC-2026-3830)

A vulnerability classified as critical has been found in MongoDB libmongocrypt up to 1.20.4. Affected by this vulnerability is an unknown functionality. The manipulation leads to state issue. This vulnerability is uniquely identified as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-106430 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-106430 | MongoDB C++ Driver up to 4.6.0 Collection API missing initialization (WID-SEC-2026-3830)

A vulnerability was found in MongoDB C++ Driver up to 4.6.0. It has been rated as critical. This affects an unknown part of the component Collection API. Performing a manipulation results in missing initialization of a variable. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-106428 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-106428 | MongoDB C Driver up to 1.30.12/2.3.x SCRAM Authentication Response Parsing out-of-bounds (WID-SEC-2026-3830)

A vulnerability classified as critical was found in MongoDB C Driver up to 1.30.12/2.3.x. This impacts an unknown function of the component SCRAM Authentication Response Parsing. Executing a manipulation can lead to out-of-bounds read. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2026-40345 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-40345 | RebeccaStevens deepmerge-ts up to 7.x stack-based overflow (WID-SEC-2026-3831)

A vulnerability categorized as problematic has been discovered in RebeccaStevens deepmerge-ts up to 7.x. This affects the function deepmerge/deepmergeCustom/deepmergeInto/deepmergeIntoCustom. The manipulation results in stack-based buffer o

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.8%
CVE-2026-88131 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-88131 | Microsoft Dataverse deserialization (EUVD-2026-95397 / WID-SEC-2026-3832)

A vulnerability classified as critical has been found in Microsoft Dataverse. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in deserialization. This vulnerability is identified as CVE-2026-881

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 12.7%
CVE-2018-14718 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-14718 | Oracle JDeveloper 12.1.3.0.0/12.2.1.3.0 jackson-databind deserialization (ID 176635 / BID-106601)

A vulnerability, which was classified as critical, has been found in Oracle JDeveloper 12.1.3.0.0/12.2.1.3.0. This affects an unknown function of the component jackson-databind. This manipulation causes deserialization. This vulnerability a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 4.3%
CVE-2018-12120 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-12120 | Node.js up to 6.14.x Debugger --debug=localhost 7pk security (Nessus ID 119511 / ID 172114)

A vulnerability described as critical has been identified in Node.js up to 6.14.x. Affected is an unknown function of the component Debugger. Executing a manipulation of the argument --debug=localhost can lead to 7pk security features. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 4.6%
CVE-2018-12116 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-12116 | Node.js up to 6.14.x/8.13.x HTTP Request request smuggling (Nessus ID 119511 / ID 172114)

A vulnerability marked as critical has been reported in Node.js up to 6.14.x/8.13.x. This impacts an unknown function of the component HTTP Request Handler. Performing a manipulation results in http request smuggling. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 4.1%
CVE-2018-1000880 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-1000880 | libarchive 3.2.0 archive_read_support_format_warc.c warc_read Archive double free (USN-3859-1 / Nessus ID 119893)

A vulnerability has been found in libarchive 3.2.0 and classified as problematic. The impacted element is the function warc_read of the file libarchive/archive_read_support_format_warc.c. The manipulation as part of Archive leads to double

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 3.4%
CVE-2018-1000879 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-1000879 | libarchive 3.3.0 libarchive/archive_acl.c archive_acl_from_text_l null pointer dereference (FEDORA-2019-0233ec0ff3 / ID 277759)

A vulnerability, which was classified as problematic, was found in libarchive 3.3.0. The affected element is the function archive_acl_from_text_l of the file libarchive/archive_acl.c. Executing a manipulation can lead to null pointer derefe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-88776 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Citrix NetScaler ADC and Gateway: eight advisories, two under active exploitation (CVE-2026-88776)

Citrix NetScaler ADC and Gateway: eight advisories, two under active exploitation (CVE-2026-88776) The Dutch national cyber security centre published NCSC-2026-0394 on 27 September 2026 with a High priority rating. The subject is a single h

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 3.4%
CVE-2018-5407 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-5407 | CPU Multi-Threading Timing information disclosure (RHSA-2019:0483 / EDB-45785)

A vulnerability described as critical has been identified in CPU. The impacted element is an unknown function of the component Multi-Threading. The manipulation as part of Timing results in information disclosure. This vulnerability is iden

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 12.2%
CVE-2018-0734 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-0734 | Oracle Enterprise Session Border Controller up to 8.3 Security key management (Nessus ID 211827 / ID 20103)

A vulnerability labeled as critical has been found in Oracle Enterprise Session Border Controller 7.5/8.0/8.1/8.2/8.3. This impacts an unknown function of the component Security. Such manipulation leads to key management error. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-83947 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-83947 | Microsoft Azure Event Grid improper authorization (EUVD-2026-95396 / WID-SEC-2026-3834)

A vulnerability was found in Microsoft Azure Event Grid. It has been classified as problematic. The affected element is an unknown function. Performing a manipulation results in improper authorization. This vulnerability is reported as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-83943 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-83943 | Microsoft Azure API Center information disclosure (WID-SEC-2026-3834)

A vulnerability was found in Microsoft Azure API Center. It has been declared as problematic. The impacted element is an unknown function. Executing a manipulation can lead to information disclosure. This vulnerability appears as CVE-2026-8

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2026-77900 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-77900 | Microsoft Azure App Service missing authentication (WID-SEC-2026-3834)

A vulnerability described as very critical has been identified in Microsoft Azure App Service. The impacted element is an unknown function. The manipulation results in missing authentication. This vulnerability is identified as CVE-2026-779

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-69435 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69435 | Microsoft Azure SRE Agent improper authorization (WID-SEC-2026-3834)

A vulnerability classified as critical has been found in Microsoft Azure SRE Agent. This affects an unknown function. This manipulation causes improper authorization. This vulnerability is tracked as CVE-2026-69435. The attack is possible t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-107778 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-107778 | MIT Kerberos 5 up to 1.22.2 rd_cred.c make_cred_list null pointer dereference (WID-SEC-2026-3836)

A vulnerability identified as critical has been detected in MIT Kerberos 5 up to 1.22.2. Impacted is the function make_cred_list of the file rd_cred.c. This manipulation causes null pointer dereference. This vulnerability is registered as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2026-107708 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-107708 | MIT krb5 up to 1.22.2 KDC get_pac_princ_with_realm null pointer dereference (WID-SEC-2026-3836)

A vulnerability marked as problematic has been reported in MIT krb5 up to 1.22.2. The impacted element is the function get_pac_princ_with_realm of the component KDC. Performing a manipulation results in null pointer dereference. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-107385 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-107385 | MariaDB Corporation MariaDB Connector Node.js up to 3.2.4/3.3.3/3.4.6/3.5.3 Text Protocol Escaping Connection.escape sql injection (WID-SEC-2026-3838)

A vulnerability was found in MariaDB Corporation MariaDB Connector Node.js up to 3.2.4/3.3.3/3.4.6/3.5.3. It has been declared as critical. This issue affects the function Connection.escape of the component Text Protocol Escaping. Executing

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-107384 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-107384 | MariaDB Corporation MariaDB Connector Node.js up to 3.2.4/3.3.3/3.4.6/3.5.3 PermitSetMultiParamEntries key sql injection (WID-SEC-2026-3838)

A vulnerability has been found in MariaDB Corporation MariaDB Connector Node.js up to 3.2.4/3.3.3/3.4.6/3.5.3 and classified as critical. This impacts an unknown function of the component PermitSetMultiParamEntries Handler. The manipulation

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-107383 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-107383 | MariaDB Corporation MariaDB Connector Node.js up to 3.2.4/3.3.3/3.4.6/3.5.3 GeoJSON Encoder uninitialized pointer (WID-SEC-2026-3838)

A vulnerability, which was classified as problematic, was found in MariaDB Corporation MariaDB Connector Node.js up to 3.2.4/3.3.3/3.4.6/3.5.3. This affects an unknown function of the component GeoJSON Encoder. Executing a manipulation can

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-107382 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-107382 | MariaDB Connector Node.js up to 3.5.3 TLS Fingerprint Validation Ed25519PasswordAuth.hash denial of service (WID-SEC-2026-3838)

A vulnerability was found in MariaDB Connector Node.js up to 3.5.3 and classified as problematic. Affected is the function Ed25519PasswordAuth.hash of the component TLS Fingerprint Validation. The manipulation results in denial of service.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-77166 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77166 | Nextcloud Collectives up to 3.5.0 Page Emoji Update Endpoint emoji injection (WID-SEC-2026-3840)

A vulnerability has been found in Nextcloud Collectives up to 3.5.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Page Emoji Update Endpoint. This manipulation of the argument emoji cau

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Two AhsayCBS Zero-Day Vulnerabilities Actively Exploited to Take Over Backup Servers

Threat actors are exploiting two zero-day vulnerabilities in Ahsay Cloud Backup Server (AhsayCBS) to compromise exposed backup servers without authentication and execute commands with SYSTEM privileges. Observed intrusions have deployed web

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-18558 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
awsmin

CVE-2026-18558 | The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embeddoc' shortcode in all versions up to, and including, 2.7.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embeddoc' shortcode in all versions up to, and including, 2.7.13 due to insufficient input sanit

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.1 HIGH
EPSS
CVE-2026-104899 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
paoltaia

CVE-2026-104899 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.187 via the 'design_type' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.187 via the 'design_type' parameter parameter. This makes

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-94421 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
andy_moyle

CVE-2026-94421 | The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 5.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 5.1.2 due to insufficient input sanitization and output escaping. This makes it possible for

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-91862 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
jetmonsters

CVE-2026-91862 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-image-points' parameter in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-image-points' parameter in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. Th

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.8 HIGH
EPSS
CVE-2026-77183 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
foosales

CVE-2026-77183 | The FooSales – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.43.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with FooSales Cashier-level access and above, to change arbitrary user's email addresses, including administrators, and le

The FooSales – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.43.0. This is due to the plugin not properly validating a user's iden

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.2 HIGH
EPSS
CVE-2026-96667 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
rameez_iqbal

CVE-2026-96667 | The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The reCAPTCHA check is trivially bypassed by

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 7.3 due to insufficient input sanitizatio

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
EPSS
CVE-2026-94375 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
webtoffee

CVE-2026-94375 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to extract download exported order CSV files containing customer PII — including names, billing and shipping addresses, email addresses, phone numbers, and order contents — directly over HTTP with no authentication. This is ex

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
4.9 MEDIUM
EPSS
CVE-2026-104763 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
wpazleen

CVE-2026-104763 | The Post Export Import with Media plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.17.1 via the 'file_path' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. This requires the attacker to upload a crafted ZIP archive containing a media_metadata.json f

The Post Export Import with Media plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.17.1 via the 'file_path' parameter parameter. This makes it possible for authenticated attackers, with admin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.8 HIGH
EPSS
CVE-2026-104725 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
trainingbusinesspros

CVE-2026-104725 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter within the `process_edit()` function, which allows any authenticated user with the `edit_contacts` capability to reassign a contact record's linked WordPress user ID to any arbitrary account without requiring the `edit_us

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-103520 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
HivePress

CVE-2026-103520 | The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom text attribute (user-defined field name)' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whe

The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom text attribute (user-defined field name)' parameter in all versions up to, and including,

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.8 HIGH
EPSS
CVE-2026-83526 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Foliovision

CVE-2026-83526 | The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes attacker-supplied remote file content to the public uploads directory before any MIME or extension check, combined with a missing capability check on new player creation. This makes it possible for authenticated attackers, with

The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-16776 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
sonaar

CVE-2026-16776 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.14.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Wo

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.14.2 due to insufficient input sanitiza

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-14379 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
rubengc

CVE-2026-14379 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_id' parameter in all versions up to, and including, 7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user a

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_id' parameter in all versions up to, and including, 7.9.4 due t

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.8 HIGH
EPSS
CVE-2026-104766 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
latepoint

CVE-2026-104766 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` handler iterating over attacker-supplied `settings` parameters without an allowlist of permitted setting names or values, and `OsSettingsHelper::prepare_value()` performing no role allowlist validation before persisting the `

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` han

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
3.1 LOW
EPSS
CVE-2026-104742 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
senols

CVE-2026-104742 | The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify global site-wide semantic search settings, including vector provider, embedding provider, embeddin

The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-78068 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
jonua

CVE-2026-78068 | The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell Content in all versions up to, and including, 1.3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell Content in all versions up to, and including, 1.3.35 due to insufficient input sanitization and output escaping. This ma

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
3.1 LOW
EPSS
CVE-2026-104741 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
senols

CVE-2026-104741 | The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify global plugin indexing and vector-search configuration options (aipkit_training_general_settings a

The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
60 von ~227 Einträgen geladen