Live-Feed 1649 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

24362
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
322
Ransomware-Bezug
4903
Kritisch

Zeige 4951 bis 5000 von 24362

  1. CVE-2026-38061 Kritisch
    Score 59 CVSS 9.8 EPSS 1.05%

    Tenda 5G03: Command Injection in action_set_volume

  2. CVE-2026-38062 Kritisch
    Score 59 CVSS 9.8 EPSS 1.05%

    Tenda 5G03: Command-Injection über den Parameter ratMode

  3. CVE-2026-38063 Kritisch
    Score 59 CVSS 9.8 EPSS 1.05%

    Tenda 5G03: Command Injection über den Parameter ia

  4. CVE-2026-38064 Kritisch
    Score 59 CVSS 9.8 EPSS 1.05%

    Tenda 5G03: Command Injection über den Parameter dialNumber

  5. CVE-2026-38065 Kritisch
    Score 59 CVSS 9.8 EPSS 1.34%

    Tenda 5G03: Command Injection über den Parameter ims_apn

  6. CVE-2026-38329 Kritisch
    Score 59 CVSS 9.8 EPSS 0.63%

    Bludit CMS vor 3.18.4: Remote Code Execution über das API-Plugin

  7. CVE-2026-38812 Kritisch
    Score 59 CVSS 9.8 EPSS 0.39%

    RuoYi 4.8.2: SQL-Injection über den Endpunkt /tool/gen/createTable

  8. CVE-2026-39006 Kritisch
    Score 59 CVSS 9.8 EPSS 0.52%

    SNMP4J-Agent: Code-Ausführung über snmp4jCfgStoragePath

  9. CVE-2026-39196 Kritisch
    Score 59 CVSS 9.8 EPSS 0.32%

    Datadog Vector v0.54.0: SQL-Injection in KeyPartitioner::partition

  10. CVE-2026-39583 Kritisch
    Score 59 CVSS 9.8 EPSS 0.36%

    Datalogics Ecommerce Delivery: Unauthentifizierte Rechteausweitung

  11. CVE-2026-39591 Kritisch
    Score 59 CVSS 9.9 EPSS 0.46%

    WP-BusinessDirectory: beliebiger Datei-Upload durch Abonnenten (<= 4.0.0)

  12. CVE-2026-48114 Kritisch
    Score 59 CVSS 9.8 EPSS 0.37%

    Metacat: Nicht authentifizierte SQL-Injection im /harvesterRegistration-Endpunkt

  13. CVE-2026-49085 Kritisch
    Score 59 CVSS 9.8 EPSS 0.48%

    WP Insightly: Nicht authentifizierte PHP Object Injection (<= 1.1.4)

  14. CVE-2026-49104 Kritisch
    Score 59 CVSS 9.8 EPSS 0.48%

    Integration for Keap/Infusionsoft und Formular-Plugins: Unauthentifizierte PHP Object Injection

  15. CVE-2026-49105 Kritisch
    Score 59 CVSS 9.8 EPSS 0.48%

    WP Zendesk für Contact Form 7, WPForms, Elementor, Formidable und Ninja Forms: PHP Object Injection

  16. CVE-2026-49106 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    Integration for Contact Form 7 and Constant Contact: unauthentifizierte PHP Object Injection

  17. CVE-2026-49109 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    Integration for Salesforce and Contact Form 7: Unauthentifizierte PHP Object Injection

  18. CVE-2026-49763 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    Integration for Contact Form 7 HubSpot: Nicht authentifizierte PHP Object Injection

  19. CVE-2026-49764 Kritisch
    Score 59 CVSS 9.8 EPSS 0.40%

    RegistrationMagic: Unauthentifizierte Umgehung der Authentifizierung

  20. CVE-2026-49765 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms bis 1.1.8: unauthentifizierte PHP Object Injection

  21. CVE-2026-49766 Kritisch
    Score 59 CVSS 9.9 EPSS 0.51%

    WP User Manager – Arbitrary File Deletion durch Subscriber

  22. CVE-2026-49768 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    Happyforms: Unauthentifizierte PHP Object Injection

  23. CVE-2026-49769 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    wpForo Forum: Unauthentifizierte PHP Object Injection

  24. CVE-2026-49770 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    WP Travel Engine: unauthentifizierte PHP Object Injection

  25. CVE-2026-49781 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    OttoKit: nicht authentifizierte PHP Object Injection

  26. CVE-2026-50869 Kritisch
    Score 59 CVSS 9.8 EPSS 0.72%

    Bludit 3.19.0: Directory Traversal in api/plugin.php

  27. CVE-2026-50871 Kritisch
    Score 59 CVSS 9.8 EPSS 1.57%

    kanishka-linux Reminiscence v0.3.0: OS Command Injection in der Medienarchivierung

  28. CVE-2026-50872 Kritisch
    Score 59 CVSS 9.8 EPSS 0.56%

    fossar selfoss: Befehlsausführung über die Loopback-Request-Verarbeitung

  29. CVE-2026-50873 Kritisch
    Score 59 CVSS 9.8 EPSS 0.44%

    flatnotes: Beliebiger Datei-Upload in der Anhang-Verarbeitung

  30. CVE-2026-50880 Kritisch
    Score 59 CVSS 9.8 EPSS 0.48%

    YouTransfer v1.0.6: Codeausführung über die sendmail-Transport-Integration

  31. CVE-2026-50890 Kritisch
    Score 59 CVSS 9.8 EPSS 0.32%

    grocy 4.6.0: SQL-Injection im Parameter product-group unter /stockreports/spendings

  32. CVE-2026-8935 Kritisch
    Score 59 CVSS 9.8 EPSS 0.27%

    WP MAPS PRO (WordPress): Unauthentifizierte AJAX-Aktion mit öffentlich einsehbarer Nonce

  33. CVE-2026-9691 Kritisch
    Score 59 CVSS 9.8 EPSS 0.48%

    Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms: unauthentifizierte PHP Object Injection

  34. CVE-2026-9862 Kritisch
    Score 59 CVSS 9.8 EPSS 0.86%

    Fortra Core Privileged Access Manager (BoKS): OS-Command-Injection in boks_autoregisterd

  35. CVE-2026-50883 Kritisch
    Score 58 CVSS 9.6 EPSS 0.37%

    wastebin 3.4.1: HTML-Injection in der Highlight-Komponente

  36. CVE-2026-52703 Kritisch
    Score 58 CVSS 9.6 EPSS 0.44%

    FastDup: unauthentifizierter Path Traversal in Versionen bis 2.7.2

  37. CVE-2026-39441 Kritisch
    Score 56 CVSS 9.3 EPSS 0.28%

    Feed KuantoKusta for WooCommerce – Free: Unauthentifizierte SQL-Injection

  38. CVE-2026-39492 Kritisch
    Score 56 CVSS 9.3 EPSS 0.36%

    WordPress-Plugin WP Maps: Nicht authentifizierte SQL-Injection

  39. CVE-2026-39493 Kritisch
    Score 56 CVSS 9.3 EPSS 0.36%

    Simply Schedule Appointments: unauthentifizierte SQL-Injection bis Version 1.6.9.27

  40. CVE-2026-39502 Kritisch
    Score 56 CVSS 9.3 EPSS 0.28%

    Form Maker by 10Web: Nicht authentifizierte SQL-Injection

  41. CVE-2026-39511 Kritisch
    Score 56 CVSS 9.3 EPSS 0.29%

    WP Photo Album Plus: Unauthentifizierte SQL-Injection

  42. CVE-2026-39512 Kritisch
    Score 56 CVSS 9.3 EPSS 0.28%

    GeoDirectory (WordPress): Nicht authentifizierte SQL-Injection

  43. CVE-2026-39519 Kritisch
    Score 56 CVSS 9.3 EPSS 0.28%

    GeekyBot: Nicht authentifizierte SQL-Injection

  44. CVE-2026-39530 Kritisch
    Score 56 CVSS 9.3 EPSS 0.30%

    SpeakOut! Email Petitions: Unauthentifizierte SQL-Injection

  45. CVE-2026-40771 Kritisch
    Score 56 CVSS 9.3 EPSS 0.28%

    Contest Gallery: Nicht authentifizierte SQL Injection

  46. CVE-2026-40798 Kritisch
    Score 56 CVSS 9.3 EPSS 0.28%

    wpForo Forum: Nicht authentifizierte SQL-Injection

  47. CVE-2026-42381 Kritisch
    Score 56 CVSS 9.3 EPSS 0.28%

    Funnel Builder by FunnelKit (WordPress): Nicht authentifizierte SQL-Injection

  48. CVE-2026-42386 Kritisch
    Score 56 CVSS 9.3 EPSS 0.28%

    Order Delivery Date for WooCommerce: Nicht authentifizierte SQL-Injection

  49. CVE-2026-42639 Kritisch
    Score 56 CVSS 9.3 EPSS 0.28%

    GD Rating System: Unauthentifizierte SQL-Injection

  50. CVE-2026-42665 Kritisch
    Score 56 CVSS 9.3 EPSS 0.28%

    WP Data Access: unauthentifizierte SQL-Injection in Versionen bis 5.5.70

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.