Meistinteragiert
Sicherheitslücken (CVE)
vor 3 Std.
Live Threat Intelligence Feed
Kategorie #10
Sicherheitslücken (CVE)
ENISA EUVD & CISA KEV Vulnerability Database. Dokumentierte CVEs, Severity Heatmaps, NIS-2 Relevant Advisories und Vendor Patch Bulletins.
Meistinteragiert
Sicherheitslücken (CVE)
vor 20 Std.
Angriffe auf FortiMail-Zero-Day-Lücke beobachtet | heise online
Meistinteragiert
Sicherheitslücken (CVE)
vor 21 Std.
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
Meistinteragiert
Sicherheitslücken (CVE)
vor 1 Tag
Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation
Meistinteragiert
Sicherheitslücken (CVE)
vor 54 Min.
CVE-2025-62672 | boyns rplay up to 3.3.2 librplay/rplay.c RPLAY_DATA allocation of resources (EUVD-2025-35001 / Nessus ID 271680)
Meistinteragiert
Sicherheitslücken (CVE)
vor 54 Min.
CVE-2024-31573 | xmlunit-core prior 2.10.0 XSLT Stylesheet Parser resource transfer (EUVD-2024-1578 / Nessus ID 271645)
EILMELDUNGEN LIVE
1/10
Unix & Linux ServerSecurity: Zwei Probleme in gawk (Red Hat)(03.10.2026 um 01:04 Uhr)
•Linux Tipps & HardeningSecurity: Überschreiben von Dateien in buildstream (Fedora)(03.10.2026 um 08:35 Uhr)
•Linux Tipps & HardeningSecurity: Überschreiben von Dateien in wordpress (Fedora)(03.10.2026 um 08:35 Uhr)
•Linux Tipps & HardeningSecurity: Ausführen beliebiger Kommandos in fetchmail (Fedora)(03.10.2026 um 08:36 Uhr)
•Linux Tipps & HardeningSecurity: Mehrere Probleme in cockpit-files (Fedora)(03.10.2026 um 08:36 Uhr)
•Linux Tipps & HardeningSecurity: Mehrere Probleme in cockpit-machines (Fedora)(03.10.2026 um 08:36 Uhr)
•Linux Tipps & HardeningSecurity: Zwei Probleme in docker-distribution (Fedora)(03.10.2026 um 08:36 Uhr)
•Linux Tipps & HardeningSecurity: Ausführen beliebiger Kommandos in xdg-dbus-proxy (Fedora)(03.10.2026 um 08:40 Uhr)
•Linux Tipps & HardeningSecurity: Mehrere Probleme in hplip (Fedora)(03.10.2026 um 08:42 Uhr)
•Sicherheitslücken (CVE)CVE-2025-62672 | boyns rplay up to 3.3.2 librplay/rplay.c RPLAY_DATA allocation of resources (EUVD-2025-35001 / Nessus ID 271680)(03.10.2026 um 07:04 Uhr)
•Unix & Linux ServerSecurity: Zwei Probleme in gawk (Red Hat)(03.10.2026 um 01:04 Uhr)
•Linux Tipps & HardeningSecurity: Überschreiben von Dateien in buildstream (Fedora)(03.10.2026 um 08:35 Uhr)
•Linux Tipps & HardeningSecurity: Überschreiben von Dateien in wordpress (Fedora)(03.10.2026 um 08:35 Uhr)
•Linux Tipps & HardeningSecurity: Ausführen beliebiger Kommandos in fetchmail (Fedora)(03.10.2026 um 08:36 Uhr)
•Linux Tipps & HardeningSecurity: Mehrere Probleme in cockpit-files (Fedora)(03.10.2026 um 08:36 Uhr)
•Linux Tipps & HardeningSecurity: Mehrere Probleme in cockpit-machines (Fedora)(03.10.2026 um 08:36 Uhr)
•Linux Tipps & HardeningSecurity: Zwei Probleme in docker-distribution (Fedora)(03.10.2026 um 08:36 Uhr)
•Linux Tipps & HardeningSecurity: Ausführen beliebiger Kommandos in xdg-dbus-proxy (Fedora)(03.10.2026 um 08:40 Uhr)
•Linux Tipps & HardeningSecurity: Mehrere Probleme in hplip (Fedora)(03.10.2026 um 08:42 Uhr)
•Sicherheitslücken (CVE)CVE-2025-62672 | boyns rplay up to 3.3.2 librplay/rplay.c RPLAY_DATA allocation of resources (EUVD-2025-35001 / Nessus ID 271680)(03.10.2026 um 07:04 Uhr)
•
Cybersecurity News & Diskussionsportal
⚡ tsecurity.de Intelligence
Sicherheitslücken (CVE) (442755)
Sicherheitslücken (CVE)
- 🏠 Home
- ›
- Sicherheitslücken (CVE) (Seite 6)
Spezifische Bereiche: Alle Sicherheitslücken (CVE) (442.755) Proof of Concept (PoC) ↗ Video Analysen ↗
LIVE …
442.755 Meldungen
442.755 Meldungen
Ansicht
Persönlich
Cyber Threat Intelligence & Forensik
ATT&CK-Taktiken über die sichtbaren Meldungen dieser Kategorie
MITRE ATT&CK HEATMAP 1 von 15 Meldungen kartiert
Live TTP Radar (Klick filtert Ansicht)
Initial Access 1
MITRE ATT&CK Matrix Navigator
Enterprise-Matrix · nur belegte Techniken
T1190TA0001 · Initial Access
Exploit Public-Facing Application
Mitigation: M1042 Network Segmentation & WAF Rule Enforcement
Quelle: Kontext-Klassifikation des Artikeltextes
Reconnaissance
–
Resource Development
–
Initial Access
Execution
–
Persistence
–
Privilege Escalation
–
Defense Evasion
–
Credential Access
–
Discovery
–
Lateral Movement
–
Collection
–
Command and Control
–
Exfiltration
–
Impact
–
Nur belegte ATT&CK-Techniken werden kartiert — Taktiken ohne Beleg bleiben unausgefüllt.Enterprise Matrix v14.1
Gestern
OpenAI fires safety researchers for mishandling sensitive information.
TA0040 · T1486
CVE-2025-57942 | andy_moyle Emergency Password Reset Plugin up to 9.0 on WordPress cross-site request forgery
CVE-2025-57937 | etruel WPeMatico RSS Feed Fetcher Plugin up to 2.8.10 on WordPress information expsure
CVE-2025-58011 | Alex Content Mask Plugin up to 1.8.5.2 on WordPress server-side request forgery
VulDB UpdatesCVE-2025-57995 | Detheme Kit for Elementor Plugin up to 2.1.10 on WordPress authorizationvor 14 Std.VulDB UpdatesCVE-2025-58008 | xnau webdesign Participants Database Plugin up to 2.7.6.3 on WordPress cross site scriptingvor 14 Std.VulDB UpdatesCVE-2025-58021 | douglaskarr List Child Pages Shortcode Plugin up to 1.3.1 on WordPress allows cross site scriptingvor 14 Std.VulDB UpdatesCVE-2025-57979 | Russell Jamieson AuthorSure Plugin up to 2.3 on WordPress cross site scriptingvor 14 Std.VulDB UpdatesCVE-2025-57964 | photonicgnostic Library Bookshelves Plugin up to 5.11 on WordPress cross site scriptingvor 14 Std.VulDB UpdatesCVE-2025-57963 | Zoho Subscriptions Zoho Billing Plugin up to 4.1 on WordPress cross site scriptingvor 14 Std.VulDB UpdatesCVE-2025-57933 | piotnetdotcom Piotnet Forms Plugin up to 1.0.30 on WordPress cross-site request forgeryvor 14 Std.VulDB UpdatesCVE-2025-57929 | kanwei_doublethedonation Double the Donation Plugin up to 2.0.0 on WordPress cross site scriptingvor 14 Std.VulDB UpdatesCVE-2025-57910 | AnyClip Video Platform AnyClip Luminous Studio Plugin up to 1.3.3 on WordPress cross site scriptingvor 14 Std.VulDB UpdatesCVE-2025-57906 | Epeken All Kurir Plugin up to 2.0.2 on WordPress cross site scriptingvor 14 Std.VulDB UpdatesCVE-2025-57899 | AresIT WP Compress Plugin up to 6.50.54 on WordPress authorizationvor 14 Std.VulDB UpdatesCVE-2025-53458 | davaxi Goracash Plugin up to 1.1 on WordPress cross site scriptingvor 14 Std.VulDB UpdatesCVE-2025-57935 | Ricky Dawn Bot Block Plugin up to 2.6 on WordPress cross site scriptingvor 14 Std.
CVE-2025-57972 | WPFactory Helpdesk Support Ticket System for WooCommerce Plugin authorization
CVE-2025-57968 | e4jvikwp VikRestaurants Table Reservations and Take-Away Plugin cross site scripting
CVE-2025-10798 | code-projects Hostel Management System 1.0 index.php?view=view id sql injection
🛡️ CVE-2025-10798 TA0001 · T1190
CVE-2022-45505 | Tenda Tenda W30E 1.0.1.25 /goform/exeCommand cmdinput stack-based overflow (EUVD-2022-48371)
VulDB UpdatesCVE-2022-45501 | Tenda W6-S 1.0.0.4 /goform/wifiSSIDset wl_radio stack-based overflow (EUVD-2022-48367)vor 15 Std.VulDB UpdatesCVE-2022-45503 | Tenda W6-S 1.0.0.4 /goform/setAutoPing linkEn stack-based overflow (EUVD-2022-48369)vor 15 Std.VulDB UpdatesCVE-2022-45499 | Tenda W6-S 1.0.0.4 /goform/WifiMacFilterGet wl_radio stack-based overflow (EUVD-2022-48365)vor 15 Std.
CVE-2026-63572 | Legion of the Bouncy Castle bc-csharp up to 2.6.x Pkcs12 Keystore Loading Pkcs12Store.Load allocation of resources (WID-SEC-2026-3713)
VulDB UpdatesCVE-2026-63570 | Bouncy Castle bc-csharp up to 2.6.x Certificate Chain Building Pkcs12Store.GetCertificateChain infinite loop (WID-SEC-2026-3713)vor 15 Std.VulDB UpdatesCVE-2026-63571 | Legion of the Bouncy Castle bc-csharp up to 2.6.x Attribute Certificate Path Validator PkixAttrCertPathValidator/PkixAttrCertPathBuilder data authenticity (WID-SEC-2026-3713)vor 15 Std.VulDB UpdatesCVE-2026-63568 | Legion of the Bouncy Castle bc-csharp up to 2.6.x CMP/CRMF Password-Based MAC Verifier PKMacBuilder allocation of resources (WID-SEC-2026-3713)vor 15 Std.VulDB UpdatesCVE-2026-63567 | Legion of the Bouncy Castle bc-csharp up to 2.6.x Block Cipher Mode IesEngine.DecryptBlock information exposure (WID-SEC-2026-3713)vor 15 Std.
CVE-2022-29968 | Linux Kernel up to 5.17.5 kiocb fs/io_uring.c io_rw_init_file initialization
CVE-2025-59801 | Artifex GhostXPS up to 10.5.x xpstiff.c xps_unpredict_tiff samplesperpixel stack-based overflow (EUVD-2025-30397 / Nessus ID 265891)
A Vulnerability in Fortinet FortiMail Could Allow for Arbitrary Code Execution
🛡️ Security Fix TA0001 · T1566 Cloud & IT-Enterprise IT Nachrichten 75%
️ Threat Hunter Status-Update verfassen
Community Stream News-Deck Sicherheitslücken (CVE) 📖 0 · ⏭ 0 · 🗳️ 0
Karten werden geladen …
Hoch = in der Vorschau lesen · Rechts = vor · Links/Runter = zurück · Enter/Karte tippen = Vorschau · V = Voting
KI-ZUSAMMENFASSUNG · AI SUMMARY
Sicherheitslücken (CVE) · 15 Artikel analysiert · Ca. 16 Min. Lesezeit gespart
1. Übergreifende Bedrohungslage & Fokus
Erhöhte Bedrohungslage durch aktive Schwachstellen: CVE-2025-57942, CVE-2025-57937, CVE-2025-58011, CVE-2025-57972, CVE-2025-57968, CVE-2025-10798. Im Fokus stehen „OpenAI fires safety researchers for mishandling sensitive information.“, „CVE-2025-57942 | andy_moyle Emergency Password Reset Plugin up to 9.0 on WordPress cross-site request forgery“, „CVE-2025-57937 | etruel WPeMatico RSS Feed Fetcher Plugin up to 2.8.10 on WordPress information expsure“.
2. Betroffene Ökosysteme
Primär betroffene Hersteller & Ökosysteme: Generic Security, WordPress sowie damit verbundene Cloud- und On-Premises-Infrastrukturen.
3. Empfohlene Maßnahmen
Sicherheitsverantwortliche und Administratoren sollten die genannten Schwachstellen priorisiert analysieren, offizielle Hersteller-Patches anwenden und Monitoring-Regeln für verdächtige Zugriffe scharfschalten.
Key Takeaways der aktuellen Artikel (8)
100% Echtdaten-Synthese
1. OpenAI fires safety researchers for mishandling sensitive information.
Öffnen ↗
10
Generic Security ⏱️ ~2 Min. gespart
Bedrohung: OpenAI fires safety researchers for mishandling sensitive information.
Betrifft: Betrifft Systeme und Installationen im Generic Security-Ökosystem sowie damit verknüpfte Netzwerkdienste.
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
2. CVE-2025-57942 | andy_moyle Emergency Password Reset Plugin up to 9.0 on WordPress cross-site request forgery
Öffnen ↗
10
WordPress ⏱️ ~2 Min. gespart
Bedrohung: CVE-2025-57942 | andy_moyle Emergency Password Reset Plugin up to 9.0 on WordPress cross-site request forgery
Betrifft: Betrifft Systeme und Installationen im WordPress-Ökosystem sowie damit verknüpfte Netzwerkdienste.
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
3. CVE-2025-57937 | etruel WPeMatico RSS Feed Fetcher Plugin up to 2.8.10 on WordPress information expsure
Öffnen ↗
10
WordPress ⏱️ ~2 Min. gespart
Bedrohung: CVE-2025-57937 | etruel WPeMatico RSS Feed Fetcher Plugin up to 2.8.10 on WordPress information expsure
Betrifft: Betrifft Systeme und Installationen im WordPress-Ökosystem sowie damit verknüpfte Netzwerkdienste.
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
4. CVE-2025-58011 | Alex Content Mask Plugin up to 1.8.5.2 on WordPress server-side request forgery
Öffnen ↗
10
WordPress ⏱️ ~2 Min. gespart
Bedrohung: CVE-2025-58011 | Alex Content Mask Plugin up to 1.8.5.2 on WordPress server-side request forgery
Betrifft: Betrifft Systeme und Installationen im WordPress-Ökosystem sowie damit verknüpfte Netzwerkdienste.
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
5. CVE-2025-57972 | WPFactory Helpdesk Support Ticket System for WooCommerce Plugin authorization
Öffnen ↗
10
WordPress ⏱️ ~2 Min. gespart
Bedrohung: CVE-2025-57972 | WPFactory Helpdesk Support Ticket System for WooCommerce Plugin authorization
Betrifft: Betrifft Systeme und Installationen im WordPress-Ökosystem sowie damit verknüpfte Netzwerkdienste.
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
6. CVE-2025-57968 | e4jvikwp VikRestaurants Table Reservations and Take-Away Plugin cross site scripting
Öffnen ↗
10
Generic Security ⏱️ ~2 Min. gespart
Bedrohung: CVE-2025-57968 | e4jvikwp VikRestaurants Table Reservations and Take-Away Plugin cross site scripting
Betrifft: Betrifft Systeme und Installationen im Generic Security-Ökosystem sowie damit verknüpfte Netzwerkdienste.
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
7. CVE-2025-10798 | code-projects Hostel Management System 1.0 index.php?view=view id sql injection
Öffnen ↗
10
Generic Security ⏱️ ~2 Min. gespart
Bedrohung: CVE-2025-10798 | code-projects Hostel Management System 1.0 index.php?view=view id sql injection
Betrifft: Betrifft Systeme und Installationen im Generic Security-Ökosystem sowie damit verknüpfte Netzwerkdienste.
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
8. CVE-2022-45505 | Tenda Tenda W30E 1.0.1.25 /goform/exeCommand cmdinput stack-based overflow (EUVD-2022-48371)
Öffnen ↗
10
Generic Security ⏱️ ~2 Min. gespart
Bedrohung: CVE-2022-45505 | Tenda Tenda W30E 1.0.1.25 /goform/exeCommand cmdinput stack-based overflow (EUVD-2022-48371)
Betrifft: Betrifft Systeme und Installationen im Generic Security-Ökosystem sowie damit verknüpfte Netzwerkdienste.
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
Generiert: 2026-10-03 07:58:50
CISO EXECUTIVE THREAT DOSSIER
Sicherheitslücken (CVE) · Strategisches Lagebild TLP:CLEAR
CISO EXECUTIVE THREAT DOSSIER
tsecurity.de Cyber Defense Intelligence · 03.10.2026 07:58 UTCGUARDED
Executive Summary
Lagebild für „Sicherheitslücken (CVE)": Identifizierte Bedrohungen weisen maximalen CVSS-Wert 7.5 (Heuristik) auf. Sofortige Risikominimierung empfohlen.
Identifizierte Schwachstellen
- CVE-2025-57942 CVSS 7.5
- CVE-2025-57937 CVSS 7.5
- CVE-2025-58011 CVSS 7.5
- CVE-2025-57972 CVSS 7.5
- CVE-2025-57968 CVSS 7.5
Betroffene Systeme
Linux / OpenSourceFortinet
Härtungs-Checkliste für Einsatzkräfte
- ■ 1. Perimeter & Firewalls: Exponierte Management-Ports und Weboberflächen auf Port 443/8443 sofort isolieren.
- ■ 2. Patch Management: Kritische Sicherheitsupdates für identifizierte CVEs binnen 24-48 Stunden auf Systemen einspielen.
- ■ 3. Telemetrie & EDR: Prozessausführungen (cmd.exe, powershell, bash) und unübliche Kindprozesse der Webdienste prüfen.
- ■ 4. Identity & Access: Multi-Faktor-Authentifizierung (MFA) für alle externen Zugänge (VPN, RDP, SSO) verifizieren.
- ■ 5. Offline Backups: Sicherstellen, dass unveränderliche (WORM) Datensicherungen von Kernsystemen getrennt vorgehalten werden.
TLP:CLEAR · Vertraulichkeit gewahrt
ESC
- Ansicht: Kachel-Raster 1
- Ansicht: Kompakte Liste 2
- Ansicht: Threat Feed Wall 3
- Ansicht: News-Deck Wischen 4
- CISO Threat Dossier öffnen D
- KI-Zusammenfassung (AI Summary) B
- Analyst Workbench (Gemerkt) W
↑↓ Navigieren · ↵ Ausführen
SOC Telemetry Terminal
ANALYST WORKBENCH
0 Artikel gemerkt
Keine gemerkten Artikel vorhanden.
Klicke auf an einer Nachricht, um sie hinzuzufügen.
Klicke auf an einer Nachricht, um sie hinzuzufügen.
SOC 24H SHIFT HANDOVER BRIEFING
Zeitpunkt: 03.10.2026 07:58 UTC
Analysiert
15Kritisch
0Exploits/PoC
0Prioritäten für die nächste Schicht:
- Regulärer Überwachungsbetrieb ohne unvorhergesehene Eskalationen.
GLOBAL CTI GEO-RADAR
LIVE VECTOR
DIFF:
Multi-CVE Comparative Matrix & Diff Engine
Side-by-Side Schwachstellen-Analyse · Live CTI Metriken
CTI-Metriken & Vektoren werden verglichen...
Powered by tsecurity.de
tsecurity.de Hub