Live-Feed 1649 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
24362
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
322
Ransomware-Bezug
4903
Kritisch
Zeige 4951 bis 5000 von 24362
- CVE-2026-38061 KritischScore 59 CVSS 9.8 EPSS 1.05%
Tenda 5G03: Command Injection in action_set_volume
- CVE-2026-38062 KritischScore 59 CVSS 9.8 EPSS 1.05%
Tenda 5G03: Command-Injection über den Parameter ratMode
- CVE-2026-38063 KritischScore 59 CVSS 9.8 EPSS 1.05%
Tenda 5G03: Command Injection über den Parameter ia
- CVE-2026-38064 KritischScore 59 CVSS 9.8 EPSS 1.05%
Tenda 5G03: Command Injection über den Parameter dialNumber
- CVE-2026-38065 KritischScore 59 CVSS 9.8 EPSS 1.34%
Tenda 5G03: Command Injection über den Parameter ims_apn
- CVE-2026-38329 KritischScore 59 CVSS 9.8 EPSS 0.63%
Bludit CMS vor 3.18.4: Remote Code Execution über das API-Plugin
- CVE-2026-38812 KritischScore 59 CVSS 9.8 EPSS 0.39%
RuoYi 4.8.2: SQL-Injection über den Endpunkt /tool/gen/createTable
- CVE-2026-39006 KritischScore 59 CVSS 9.8 EPSS 0.52%
SNMP4J-Agent: Code-Ausführung über snmp4jCfgStoragePath
- CVE-2026-39196 KritischScore 59 CVSS 9.8 EPSS 0.32%
Datadog Vector v0.54.0: SQL-Injection in KeyPartitioner::partition
- CVE-2026-39583 KritischScore 59 CVSS 9.8 EPSS 0.36%
Datalogics Ecommerce Delivery: Unauthentifizierte Rechteausweitung
- CVE-2026-39591 KritischScore 59 CVSS 9.9 EPSS 0.46%
WP-BusinessDirectory: beliebiger Datei-Upload durch Abonnenten (<= 4.0.0)
- CVE-2026-48114 KritischScore 59 CVSS 9.8 EPSS 0.37%
Metacat: Nicht authentifizierte SQL-Injection im /harvesterRegistration-Endpunkt
- CVE-2026-49085 KritischScore 59 CVSS 9.8 EPSS 0.48%
WP Insightly: Nicht authentifizierte PHP Object Injection (<= 1.1.4)
- CVE-2026-49104 KritischScore 59 CVSS 9.8 EPSS 0.48%
Integration for Keap/Infusionsoft und Formular-Plugins: Unauthentifizierte PHP Object Injection
- CVE-2026-49105 KritischScore 59 CVSS 9.8 EPSS 0.48%
WP Zendesk für Contact Form 7, WPForms, Elementor, Formidable und Ninja Forms: PHP Object Injection
- CVE-2026-49106 KritischScore 59 CVSS 9.8 EPSS 0.38%
Integration for Contact Form 7 and Constant Contact: unauthentifizierte PHP Object Injection
- CVE-2026-49109 KritischScore 59 CVSS 9.8 EPSS 0.38%
Integration for Salesforce and Contact Form 7: Unauthentifizierte PHP Object Injection
- CVE-2026-49763 KritischScore 59 CVSS 9.8 EPSS 0.38%
Integration for Contact Form 7 HubSpot: Nicht authentifizierte PHP Object Injection
- CVE-2026-49764 KritischScore 59 CVSS 9.8 EPSS 0.40%
RegistrationMagic: Unauthentifizierte Umgehung der Authentifizierung
- CVE-2026-49765 KritischScore 59 CVSS 9.8 EPSS 0.38%
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms bis 1.1.8: unauthentifizierte PHP Object Injection
- CVE-2026-49766 KritischScore 59 CVSS 9.9 EPSS 0.51%
WP User Manager – Arbitrary File Deletion durch Subscriber
- CVE-2026-49768 KritischScore 59 CVSS 9.8 EPSS 0.38%
Happyforms: Unauthentifizierte PHP Object Injection
- CVE-2026-49769 KritischScore 59 CVSS 9.8 EPSS 0.38%
wpForo Forum: Unauthentifizierte PHP Object Injection
- CVE-2026-49770 KritischScore 59 CVSS 9.8 EPSS 0.38%
WP Travel Engine: unauthentifizierte PHP Object Injection
- CVE-2026-49781 KritischScore 59 CVSS 9.8 EPSS 0.38%
OttoKit: nicht authentifizierte PHP Object Injection
- CVE-2026-50869 KritischScore 59 CVSS 9.8 EPSS 0.72%
Bludit 3.19.0: Directory Traversal in api/plugin.php
- CVE-2026-50871 KritischScore 59 CVSS 9.8 EPSS 1.57%
kanishka-linux Reminiscence v0.3.0: OS Command Injection in der Medienarchivierung
- CVE-2026-50872 KritischScore 59 CVSS 9.8 EPSS 0.56%
fossar selfoss: Befehlsausführung über die Loopback-Request-Verarbeitung
- CVE-2026-50873 KritischScore 59 CVSS 9.8 EPSS 0.44%
flatnotes: Beliebiger Datei-Upload in der Anhang-Verarbeitung
- CVE-2026-50880 KritischScore 59 CVSS 9.8 EPSS 0.48%
YouTransfer v1.0.6: Codeausführung über die sendmail-Transport-Integration
- CVE-2026-50890 KritischScore 59 CVSS 9.8 EPSS 0.32%
grocy 4.6.0: SQL-Injection im Parameter product-group unter /stockreports/spendings
- CVE-2026-8935 KritischScore 59 CVSS 9.8 EPSS 0.27%
WP MAPS PRO (WordPress): Unauthentifizierte AJAX-Aktion mit öffentlich einsehbarer Nonce
- CVE-2026-9691 KritischScore 59 CVSS 9.8 EPSS 0.48%
Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms: unauthentifizierte PHP Object Injection
- CVE-2026-9862 KritischScore 59 CVSS 9.8 EPSS 0.86%
Fortra Core Privileged Access Manager (BoKS): OS-Command-Injection in boks_autoregisterd
- CVE-2026-50883 KritischScore 58 CVSS 9.6 EPSS 0.37%
wastebin 3.4.1: HTML-Injection in der Highlight-Komponente
- CVE-2026-52703 KritischScore 58 CVSS 9.6 EPSS 0.44%
FastDup: unauthentifizierter Path Traversal in Versionen bis 2.7.2
- CVE-2026-39441 KritischScore 56 CVSS 9.3 EPSS 0.28%
Feed KuantoKusta for WooCommerce – Free: Unauthentifizierte SQL-Injection
- CVE-2026-39492 KritischScore 56 CVSS 9.3 EPSS 0.36%
WordPress-Plugin WP Maps: Nicht authentifizierte SQL-Injection
- CVE-2026-39493 KritischScore 56 CVSS 9.3 EPSS 0.36%
Simply Schedule Appointments: unauthentifizierte SQL-Injection bis Version 1.6.9.27
- CVE-2026-39502 KritischScore 56 CVSS 9.3 EPSS 0.28%
Form Maker by 10Web: Nicht authentifizierte SQL-Injection
- CVE-2026-39511 KritischScore 56 CVSS 9.3 EPSS 0.29%
WP Photo Album Plus: Unauthentifizierte SQL-Injection
- CVE-2026-39512 KritischScore 56 CVSS 9.3 EPSS 0.28%
GeoDirectory (WordPress): Nicht authentifizierte SQL-Injection
- CVE-2026-39519 KritischScore 56 CVSS 9.3 EPSS 0.28%
GeekyBot: Nicht authentifizierte SQL-Injection
- CVE-2026-39530 KritischScore 56 CVSS 9.3 EPSS 0.30%
SpeakOut! Email Petitions: Unauthentifizierte SQL-Injection
- CVE-2026-40771 KritischScore 56 CVSS 9.3 EPSS 0.28%
Contest Gallery: Nicht authentifizierte SQL Injection
- CVE-2026-40798 KritischScore 56 CVSS 9.3 EPSS 0.28%
wpForo Forum: Nicht authentifizierte SQL-Injection
- CVE-2026-42381 KritischScore 56 CVSS 9.3 EPSS 0.28%
Funnel Builder by FunnelKit (WordPress): Nicht authentifizierte SQL-Injection
- CVE-2026-42386 KritischScore 56 CVSS 9.3 EPSS 0.28%
Order Delivery Date for WooCommerce: Nicht authentifizierte SQL-Injection
- CVE-2026-42639 KritischScore 56 CVSS 9.3 EPSS 0.28%
GD Rating System: Unauthentifizierte SQL-Injection
- CVE-2026-42665 KritischScore 56 CVSS 9.3 EPSS 0.28%
WP Data Access: unauthentifizierte SQL-Injection in Versionen bis 5.5.70
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.