Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 551 bis 600 von 36300
- CVE-2026-16143 HochScore 43 CVSS 7.2 EPSS 0.24%
VikRentItems – Stored Cross-Site Scripting im WordPress-Plugin
- CVE-2026-16605 HochScore 43 CVSS 7.2 EPSS 0.32%
MultiVendorX (WordPress) – Fehlende Eigentümerprüfung in der REST-API
- CVE-2026-54416 HochScore 43 CVSS 7.2 EPSS 0.34%
Pluck CMS – unvollständige Blacklist beim Datei-Upload in der Admin-Dateiverwaltung
- CVE-2026-6020 HochScore 43 CVSS 7.2 EPSS 0.54%
ShopLentor – Ausführung beliebiger Funktionen über REST-API
- CVE-2026-71211 HochScore 43 CVSS 7.1 EPSS 0.25%
MLflow AI Gateway – fehlende Validierung von auth_config.api_base beim Erstellen von Gateway-Secrets
- CVE-2026-7693 HochScore 43 CVSS 7.2 EPSS 2.23%
WordPress-Plugin Backup Migration: OS-Command-Injection über file-Parameter
- CVE-2026-71232 HochScore 43 CVSS 7.2 EPSS 0.30%
Blacklist-Bypass im Template-Editor von MacCMS10 ermöglicht Codeausführung
- CVE-2026-71245 HochScore 43 CVSS 7.1 EPSS 0.20%
Mautic AjaxController: Unzureichende Eingabebereinigung des field-Parameters in getLeadIdsByFieldValueAction
- CVE-2026-18933 HochScore 43 CVSS 7.2 EPSS 0.28%
wp-downloadmanager (WordPress) – Admin-privilegierter Upload beliebiger Dateien
- CVE-2026-71269 HochScore 43 CVSS 7.2 EPSS 0.46%
Node-RED Local-Filesystem-Library: Schwachstelle in getLibraryEntry()/saveLibraryEntry()
- CVE-2026-71284 HochScore 43 CVSS 7.2 EPSS 0.46%
Fledge: Kommandoaufbau aus Tar-Dateinamen im Backup-Restore-Upload-Handler
- CVE-2026-71292 HochScore 43 CVSS 7.2 EPSS 0.32%
Subrion CMS: Unzureichende Prüfung des Sortierparameters im Admin-Grid
- CVE-2026-17506 HochScore 43 CVSS 7.2 EPSS 0.23%
Independent Analytics WordPress-Plugin: Stored Cross-Site Scripting über 404-Tracking-Parameter
- CVE-2026-17630 HochScore 43 CVSS 7.2 EPSS 0.42%
IBM Langflow OSS: Codeausführung durch unzureichende Konfigurationsvalidierung
- CVE-2026-70608 HochScore 43 CVSS 7.2
Electron – Sandbox-Bypass über iframe ohne allow-popups
- CVE-2026-17625 HochScore 43 CVSS 7.2 EPSS 0.81%
IBM Langflow OSS: Schwachstelle für authentifizierte Angreifer mit erhöhten Rechten
- CVE-2026-70448 HochScore 43 CVSS 7.1
Jenkins Ivy Report Plugin 1.2 und früher: XXE bei der Verarbeitung von Ivy-Reports
- CVE-2026-9081 HochScore 43 CVSS 7.1 EPSS 0.17%
IBM Langflow: SSRF in validate_model_provider_key() für Ollama-Provider
- CVE-2026-9130 HochScore 43 CVSS 7.1 EPSS 0.19%
IBM Langflow OSS: Autorisierungsumgehung in MemoryComponent durch Session-ID-Kollision
- CVE-2026-55747 MittelScore 41 CVSS 6.8 EPSS 0.26%
PocketFlow Coding-Agent Cookbook: Pfad-Traversal durch fehlende Containment-Prüfung in _path()
- CVE-2026-70611 MittelScore 41 CVSS 6.9
Electron: DevTools-Reveal-in-Dateimanager-Aktion vor Version 39.8.9/40.9.2/41.2.1/42.0.0-beta.3
- CVE-2026-71313 MittelScore 41 CVSS 6.9 EPSS 0.25%
rclone: Schwachstelle im Local-Backend durch fehlerhafte Konfigurationsprüfung (v1.51.0–1.75.0)
- CVE-2026-66344 MittelScore 40 CVSS 6.7 EPSS 0.12%
NetKids iMark – Uncontrolled Search Path Element Vulnerability
- CVE-2026-66839 MittelScore 40 CVSS 6.7 EPSS 0.14%
NetKids iMark – Unquoted Search Path (CWE-428)
- CVE-2026-70602 MittelScore 40 CVSS 6.6
Electron: Unzureichend eingeschränkte Erweiterungs-APIs für Tabs und Skripte
- CVE-2026-11421 MittelScore 39 CVSS 6.5 EPSS 0.33%
WordPress-Plugin "ERP: Complete HR, Accounting & CRM Suite" – SQL-Injection über erpadvancefilter
- CVE-2026-15941 MittelScore 39 CVSS 6.5 EPSS 0.25%
WordPress-Plugin mit Relevanssi-Integration – Admin-Search-AJAX-Handler
- CVE-2026-7753 MittelScore 39 CVSS 6.5 EPSS 0.36%
Cost Calculator Builder (WordPress) – Unautorisierter Zugriff auf sensible Daten
- CVE-2026-16968 MittelScore 39 CVSS 6.5 EPSS 0.22%
GeoDirectory (WordPress-Plugin): Fehlende Zugriffsbeschränkung im User-Search-Handler
- CVE-2026-49004 MittelScore 39 CVSS 6.5 EPSS 0.61%
PostgreSQL-Dienst auf Mobilgerät: Fehlkonfiguration und Command Injection
- CVE-2026-67554 MittelScore 39 CVSS 6.5 EPSS 0.29%
Denial of Service durch fehlerhafte Range-Verarbeitung bei Disposition-Frames
- CVE-2026-11454 MittelScore 39 CVSS 6.5 EPSS 0.40%
Groundhogg – Insecure Direct Object Reference über REST-API
- CVE-2026-11977 MittelScore 39 CVSS 6.5 EPSS 0.25%
WordPress-Plugin WP Post Author: SQL-Injection über wpma_metabox_authors_list-Parameter
- CVE-2026-15281 MittelScore 39 CVSS 6.5 EPSS 0.34%
User Access Manager (WordPress) – Second-Order-SQL-Injection über den Parameter id
- CVE-2026-7726 MittelScore 39 CVSS 6.5 EPSS 0.27%
WordPress-Plugin Layouts for WPBakery – fehlende Berechtigungsprüfung bei Template-Sync
- CVE-2026-71244 MittelScore 39 CVSS 6.5 EPSS 0.20%
Offenlegung gespeicherter Zugangsdaten über MailAccountViewSet in Paperless-ngx
- CVE-2026-71251 MittelScore 39 CVSS 6.5 EPSS 0.20%
Akaunting – unzureichende Zugriffskontrolle bei geteilter Download-Route
- CVE-2026-0516 MittelScore 39 CVSS 6.5 EPSS 0.21%
SonicOS: Manipulation des Host-Headers ermöglicht Umleitung von Firewall-Management-Nutzern
- CVE-2026-71225 MittelScore 39 CVSS 6.5 EPSS 0.32%
libkcapi: Fehlerhafte Verarbeitung grosser Eingaben bei zustandsbehafteten Blockchiffre-Modi
- CVE-2026-71247 MittelScore 39 CVSS 6.5 EPSS 0.17%
Documenso – ASSISTANT-Rolle kann fremde, noch nicht signierte Signaturfelder abschliessen
- CVE-2026-71260 MittelScore 39 CVSS 6.5 EPSS 0.23%
ESPHome web_server: Klartext-Passwortoffenlegung über text_json_()
- CVE-2026-71273 MittelScore 39 CVSS 6.5 EPSS 0.12%
OpenBK7231T: CSRF im Endpoint /cfg_wifi_set
- CVE-2026-71282 MittelScore 39 CVSS 6.5 EPSS 0.23%
ChirpStack: SQL-Injection über Geräte-Tag-Filterung im SQLite-Backend
- CVE-2026-7456 MittelScore 39 CVSS 6.5 EPSS 0.25%
WordPress-Plugin Udimi Tools: Fehlende Berechtigungsprüfung ermöglicht unautorisierte Datenänderung
- CVE-2026-16100 MittelScore 39 CVSS 6.5 EPSS 0.30%
Keycloak: Rohe Fehlermeldungen in Prometheus-Metrik-Labels bei aktivierten Metriken
- CVE-2026-49331 MittelScore 39 CVSS 6.5 EPSS 0.13%
openshift/oauth-proxy: Weiterleitung client-gesteuerter Identitäts-Header auf Bypass-Pfaden
- CVE-2026-10128 MittelScore 39 CVSS 6.5 EPSS 0.22%
IBM Langflow OSS 1.0.0–1.10.3: Auslesen beliebiger Server-Umgebungsvariablen
- CVE-2026-20288 MittelScore 39 CVSS 6.5 EPSS 0.35%
Cisco IMC: Befehlsausführung über webbasierte Management-Oberfläche
- CVE-2026-20294 MittelScore 39 CVSS 6.5 EPSS 0.13%
Cisco Catalyst SD-WAN Manager: Offenlegung sensibler Informationen im Klartext in der Web-Management-Oberfläche
- CVE-2026-63457 MittelScore 39 CVSS 6.5 EPSS 0.17%
HPE Integrated Lights-Out 6 (iLO 6) vor Version 1.78: Denial-of-Service-Schwachstelle
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.