🛡️ tsecurity.de
Zur Startseite 🔖 Lesezeichen
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

🟢 SSE Realtime Synchronisiert ⚡ REST API (JSON) 📡 RSS Feed
354k+ 🇪🇺 EUVD-Datenbank
6 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
8 🧪 PoC verfügbar
19 ✨ Neu (< 48 Std.)
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Linux 17
Frauscher Sensortechnik 8
Generic Security 6
Microsoft 6
joomlaeventmanager.net 5
wagtail 5
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.562 Einträge):
EPSS-Exploit-Wahrscheinlichkeit:
Quelle:
🔍
HIGH 7.5 🔥 EPSS 23.6%
Generic Security
CVE-2020-26241 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Black Hat Asia 2026 | LLM-Empowered Differential Testing for the Ethereum Infrastructure

YouTube VideoSecuring over $380 billion in digital assets, the Ethereum ecosystem relies entirely on clients to bridge users and the blockchain network. However, this infrastructure remains perilously fragile: the infamous CVE-2020-26241, a

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 23.6%
Generic Security
CVE-2020-26241 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Black Hat Asia 2026 | LLM-Empowered Differential Testing for the Ethereum Infrastructure

YouTube VideoSecuring over $380 billion in digital assets, the Ethereum ecosystem relies entirely on clients to bridge users and the blockchain network. However, this infrastructure remains perilously fragile: the infamous CVE-2020-26241, a

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 30.3%
Linux
CVE-2026-80590 💻 Lokal 🔓 Keine Authentifizierung nötig

Eight stable kernels with fix for a single vulnerability

Greg Kroah-Hartman has announced the release of the 7.2.2, 7.1.12, 6.18.48, 6.12.107, 6.6.155, 6.1.186, 5.15.219, and 5.10.268 stable kernels. Each of these contains a single fix for a vulnerability (CVE-2026-80590) that allows marking IPv4

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 30.3%
Linux
CVE-2026-80590 💻 Lokal 🔓 Keine Authentifizierung nötig

Eight stable kernels with fix for a single vulnerability

Greg Kroah-Hartman has announced the release of the 7.2.2, 7.1.12, 6.18.48, 6.12.107, 6.6.155, 6.1.186, 5.15.219, and 5.10.268 stable kernels. Each of these contains a single fix for a vulnerability (CVE-2026-80590) that allows marking IPv4

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Linux
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-3: Linux kernel (GCP FIPS) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Linux
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-3: Linux kernel (GCP FIPS) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Linux
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-3: Linux kernel (GCP FIPS) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 30.9%
Microsoft
CVE-2026-43071 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8644-3: Linux kernel (Azure) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - File systems infrastructure; - OCFS2 file system; - B.A.T.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 30.9%
Microsoft
CVE-2026-43071 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8644-3: Linux kernel (Azure) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - File systems infrastructure; - OCFS2 file system; - B.A.T.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 30.9%
Microsoft
CVE-2026-43071 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8644-3: Linux kernel (Azure) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - File systems infrastructure; - OCFS2 file system; - B.A.T.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 24.6%
Linux
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8661-3: Linux kernel vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Linux
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8661-3: Linux kernel vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Linux
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8661-3: Linux kernel vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Microsoft
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-4: Linux kernel (Azure CVM) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 20.1%
Microsoft
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-4: Linux kernel (Azure CVM) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 20.1%
Microsoft
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-4: Linux kernel (Azure CVM) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8643-5: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8643-5: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8643-5: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-40253 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8686-1: openCryptoki vulnerabilities

It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-40253 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8686-1: openCryptoki vulnerabilities

It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 29.6%
Linux
CVE-2026-12087 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8684-1: Perl vulnerabilities

It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 29.6%
Linux
CVE-2026-12087 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8684-1: Perl vulnerabilities

It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
🇪🇺 EUVD HIGH 7.8 🔥 EPSS 17%
wibu-systems-ag
CVE-2026-81572 💻 Lokal 🔑 Geringe Nutzerrechte nötig

CVE-2026-81572 | In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs

In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS r

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD CRITICAL 9.4 🔥 EPSS 41%
joomlaeventmanager.net
CVE-2026-77991 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig

CVE-2026-77991 | Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution.

Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 6.9 🔥 EPSS 24%
joomlaeventmanager.net
CVE-2026-77034 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-77034 | Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.

Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 5.3 🔥 EPSS 21%
joomlaeventmanager.net
CVE-2026-77990 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2026-77990 | Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events.

Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not m

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 5.1 🔥 EPSS 23%
joomlaeventmanager.net
CVE-2026-77035 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig

CVE-2026-77035 | Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.

Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 5.3 🔥 EPSS 26%
joomlaeventmanager.net
CVE-2026-77989 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-77989 | Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.

Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, l

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD HIGH 7.8 🔥 EPSS 13%
Admin By Request (ABR)
CVE-2026-78237 💻 Lokal 🔑 Geringe Nutzerrechte nötig

CVE-2026-78237 | Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective after the ABR session ended.

Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective after the ABR session ended.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 76.5%
Generic Security
CVE-2026-42167 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 76.5%
Generic Security
CVE-2026-42167 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.9%
Linux
CVE-2026-43804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

DSA-6463-1 webkit2gtk - security update

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.9%
Linux
CVE-2026-43804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

DSA-6463-1 webkit2gtk - security update

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
🇪🇺 EUVD HIGH 7.3 🔥 EPSS 20%
🧪 PoC wagtail
CVE-2026-54263 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2026-54263 | Wagtail: Reflected XSS in dynamic image URL generator view

Wagtail: Reflected XSS in dynamic image URL generator view

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 4.3 🔥 EPSS 16%
🧪 PoC wagtail
CVE-2026-54262 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2026-54262 | Wagtail: Pages translations can be created without page permissions when using simple_translation

Wagtail: Pages translations can be created without page permissions when using simple_translation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 6.5 🔥 EPSS 20%
🧪 PoC wagtail
CVE-2026-54261 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2026-54261 | Wagtail: Improper permission handling in image preview

Wagtail: Improper permission handling in image preview

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 4.3 🔥 EPSS 22%
🧪 PoC wagtail
CVE-2026-54260 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2026-54260 | Wagtail: Denial of service via unbounded filter specs in the image preview

Wagtail: Denial of service via unbounded filter specs in the image preview

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 4.3 🔥 EPSS 16%
🧪 PoC wagtail
CVE-2026-54259 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2026-54259 | Wagtail: Improper restriction handling on Documents and Images chosen endpoints

Wagtail: Improper restriction handling on Documents and Images chosen endpoints

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD CRITICAL 9.1 🔥 EPSS 39%
🧪 PoC dgraph-io
CVE-2026-54061 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-54061 | Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD HIGH 7.8 🔥 EPSS 17%
Generic Security
CVE-2026-18917 💻 Lokal 🔑 Geringe Nutzerrechte nötig

CVE-2026-18917 | A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Sub

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 6.9 🔥 EPSS 16%
yootheme.com
CVE-2026-76610 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-76610 | Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users.

Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 5.3 🔥 EPSS 23%
Generic Security
CVE-2026-77014 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-77014 | A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than IN

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 5.3 🔥 EPSS 20%
Frauscher Sensortechnik
CVE-2026-14953 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2026-14953 | A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD HIGH 8.7 🔥 EPSS 49%
Frauscher Sensortechnik
CVE-2026-14952 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-14952 | An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose d

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD HIGH 8.6 🔥 EPSS 16%
Frauscher Sensortechnik
CVE-2026-14951 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2026-14951 | An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD CRITICAL 9.2 🔥 EPSS 55%
Frauscher Sensortechnik
CVE-2026-14950 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-14950 | An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD HIGH 8.5 🔥 EPSS 26%
Frauscher Sensortechnik
CVE-2026-14949 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2026-14949 | A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD HIGH 8.7 🔥 EPSS 39%
Frauscher Sensortechnik
CVE-2026-14948 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2026-14948 | A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD HIGH 8.6 🔥 EPSS 94%
Frauscher Sensortechnik
CVE-2026-14947 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig

CVE-2026-14947 | A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD HIGH 8.6 🔥 EPSS 52%
Frauscher Sensortechnik
CVE-2026-14946 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig

CVE-2026-14946 | A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD HIGH 8.6 🔥 EPSS 23%
icagenda.com
CVE-2026-75948 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2026-75948 | Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.

Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD HIGH 8.6 🔥 EPSS 26%
phoca.cz
CVE-2026-76564 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-76564 | Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7

Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 5.3 🔥 EPSS 26%
phoca.cz
CVE-2026-76569 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-76569 | Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4

Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 5.3 🔥 EPSS 26%
phoca.cz
CVE-2026-76565 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-76565 | Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD HIGH 8.6 🔥 EPSS 80%
🧪 PoC vsDesk
CVE-2025-14601 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig

CVE-2025-14601 | An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose sensitive data, or potentially achieve full server compromise. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.

An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD HIGH 7.1 🔥 EPSS 23%
Octopus Deploy
CVE-2026-14163 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2026-14163 | In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text.

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 5.3 🔥 EPSS 28%
🧪 PoC vsDesk
CVE-2025-14602 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

CVE-2025-14602 | The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.

The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacke

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD MEDIUM 5.1 🔥 EPSS 26%
ThinkingReed inc.
CVE-2026-71368 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-71368 | F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.

F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🇪🇺 EUVD CRITICAL 9.8 🔥 EPSS 34%
Unknown
CVE-2026-75860 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-75860 | The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.

The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPre

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.