Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 601 bis 650 von 36300

  1. CVE-2026-70439 Mittel
    Score 39 CVSS 6.5

    Jenkins XML Job to Job DSL Plugin: Fehlende Berechtigungsprüfung ermöglicht Aufruf der Konvertierungsfunktion

  2. CVE-2026-7646 Mittel
    Score 39 CVSS 6.5 EPSS 0.29%

    IBM Langflow OSS: Path Traversal ermöglicht Zugriff auf beliebige Server-Dateien

  3. CVE-2026-7657 Mittel
    Score 39 CVSS 6.5 EPSS 0.20%

    IBM Langflow OSS: Server-Side Request Forgery durch unzureichenden Schutz

  4. CVE-2026-7658 Mittel
    Score 39 CVSS 6.5 EPSS 0.35%

    IBM Langflow OSS 1.0.0–1.10.3: Path Traversal über das Username-Feld

  5. CVE-2026-18896 Mittel
    Score 38 CVSS 6.3 EPSS 0.19%

    Student-Registration-System: Argumentmanipulation in changepass.php (CVE-2026-18896)

  6. CVE-2026-6972 Mittel
    Score 38 CVSS 6.4 EPSS 0.20%

    SKT Skill Bar (WordPress) – Stored XSS über das chart_size-Attribut des skillwrapper-Shortcodes

  7. CVE-2026-7441 Mittel
    Score 38 CVSS 6.4 EPSS 0.20%

    WordPress-Plugin Simple Yearly Archive – Stored Cross-Site Scripting über Shortcode-Attribut

  8. CVE-2026-70597 Mittel
    Score 38 CVSS 6.3

    Electron: Schwachstelle bei der macOS-Berechtigungsprüfung

  9. CVE-2026-20311 Mittel
    Score 38 CVSS 6.3 EPSS 0.16%

    Cisco IOS XE: Denial of Service über Web-Management-Oberfläche

  10. CVE-2026-71311 Mittel
    Score 38 CVSS 6.4 EPSS 0.24%

    rclone: Nicht standardmässiges FTP-Dateinamens-Encoding vor Version 1.75.0

  11. CVE-2026-8790 Mittel
    Score 37 CVSS 6.1 EPSS 0.22%

    Football Pool – Reflected Cross-Site Scripting im WordPress-Plugin

  12. CVE-2026-16583 Mittel
    Score 37 CVSS 6.1 EPSS 0.18%

    Orbit Fox (WordPress) – Fehlende Bereinigung hochgeladener SVG-Dateien

  13. CVE-2026-17505 Mittel
    Score 37 CVSS 6.1 EPSS 0.80%

    TranslatePress – Reflected Cross-Site Scripting über Parameter s

  14. CVE-2026-17532 Mittel
    Score 37 CVSS 6.1 EPSS 0.35%

    WordPress-Plugin Seraphinite Accelerator: Reflected XSS über seraph_accel_prep-Parameter

  15. CVE-2026-71249 Mittel
    Score 37 CVSS 6.1 EPSS 0.15%

    299Ko: Reflected Cross-Site-Scripting im öffentlichen Kontaktformular

  16. CVE-2026-71293 Mittel
    Score 37 CVSS 6.2 EPSS 0.21%

    Statamic CMS: Offenlegung von Zwei-Faktor-Recovery-Codes über AugmentedUser

  17. CVE-2026-53992 Mittel
    Score 37 CVSS 6.1

    ProjectSend r2029: Reflektiertes Cross-Site-Scripting in thumbnails-regenerate.php

  18. CVE-2026-70603 Mittel
    Score 36 CVSS 6

    Electron: shell.openPath() weist unzulässige Pfade nicht zurück

  19. CVE-2026-70599 Mittel
    Score 35 CVSS 5.9

    Electron: Fehlerhafte Berechtigungsprüfung bei Serial-Port- und Medienzugriffen

  20. CVE-2026-70605 Mittel
    Score 35 CVSS 5.9 EPSS 0.20%

    Electron: Schwachstelle bei HTTP-Redirects in net.fetch() (CVE-2026-70605)

  21. CVE-2026-70606 Mittel
    Score 35 CVSS 5.9

    Electron: Schwachstelle bei benutzerdefinierten Protokoll-Handlern

  22. CVE-2026-10547 Mittel
    Score 35 CVSS 5.9 EPSS 0.20%

    IBM Langflow OSS: Fehlende Ownership-Prüfung im veralteten Vertices-Build-Endpunkt

  23. CVE-2026-71310 Mittel
    Score 35 CVSS 5.9 EPSS 0.37%

    rclone: Fehlerhafte Verarbeitung von HTTP-CONNECT-Anfragen im gemeinsamen Proxy-Helper (vor Version 1.75.0)

  24. CVE-2026-20289 Mittel
    Score 34 CVSS 5.7 EPSS 0.19%

    Cisco RoomOS: Offenlegung sensibler Informationen im Logging-Subsystem

  25. CVE-2026-70609 Mittel
    Score 34 CVSS 5.7

    Electron: Schwachstelle über die mode-Option von webContents.openDevTools()

  26. CVE-2026-18954 Mittel
    Score 33 CVSS 5.5 EPSS 0.11%

    AWS Labs DocumentDB MCP Server: Fehlerhafte Autorisierung im Aggregation-Pipeline-Tool

  27. CVE-2026-18853 Mittel
    Score 32 CVSS 5.3 EPSS 0.17%

    ZomboDroid Meme Generator App 4.6830 (Android): Schwachstelle in Funktion t5.l.c

  28. CVE-2026-16942 Mittel
    Score 32 CVSS 5.4 EPSS 0.13%

    WordPress-Plugin WP Custom HTML Page – fehlende Bereinigung von HTML-Inhalten (CVE-2026-16942)

  29. CVE-2026-55998 Mittel
    Score 32 CVSS 5.3 EPSS 0.21%

    Zoho ManageEngine – fehlende Token-Validierung vor Cluster-Zugriff im Import-Endpunkt

  30. CVE-2026-71203 Mittel
    Score 32 CVSS 5.3 EPSS 0.26%

    changedetection.io – ungeschützter REST-API-Endpunkt full-spec ohne API-Key-Prüfung

  31. CVE-2026-12762 Mittel
    Score 32 CVSS 5.3 EPSS 0.24%

    IBM Cloud Pak For Business Automation: Offenlegung sensibler Informationen in Manifest-Dateien

  32. CVE-2026-16071 Mittel
    Score 32 CVSS 5.4 EPSS 0.18%

    Keycloak: Schwachstelle im LDAP-Storage-Provider bei Suchanfragen durch delegierte Administratoren

  33. CVE-2026-18531 Mittel
    Score 32 CVSS 5.3 EPSS 0.38%

    IBM Maximo Application Suite: Manipulation von Sitzungsdaten durch schwaches HMAC-Signierungsgeheimnis (CVE-2026-18531)

  34. CVE-2026-21766 Mittel
    Score 32 CVSS 5.4 EPSS 0.18%

    HCL Digital Experience: Unzureichender Schutz von Zugangsdaten im Standard-Login-Portlet

  35. CVE-2026-70440 Mittel
    Score 32 CVSS 5.4

    Jenkins Qualys Container Scanning Connector Plugin: Gespeichertes XSS durch fehlende Eingabe-Maskierung

  36. CVE-2026-70441 Mittel
    Score 32 CVSS 5.4

    Jenkins Summary Display Plugin: Gespeichertes XSS über Job-Namen

  37. CVE-2026-70607 Mittel
    Score 32 CVSS 5.3

    Electron: Unsichere Übernahme von Fenster-Optionen aus Web-Inhalten

  38. CVE-2026-70610 Mittel
    Score 32 CVSS 5.4 EPSS 0.38%

    Electron vor 39.8.9, 40.9.2, 41.2.2 und 42.0.0-beta.4: Problem beim Kopieren von Objekten über die contextBridge

  39. CVE-2026-70612 Mittel
    Score 32 CVSS 5.4

    Electron: Schwachstelle bei Anfragen zum Öffnen externer Protokoll-URLs

  40. CVE-2026-7869 Mittel
    Score 32 CVSS 5.4 EPSS 0.20%

    IBM Langflow OSS: Path Traversal in der Knowledge-Bases-API

  41. CVE-2026-18959 Mittel
    Score 32 CVSS 5.4 EPSS 0.37%

    yushine InnoShop bis 0.8.2 – Schwachstelle in FileManagerController::destroyFiles (Datei-Manager-Komponente)

  42. CVE-2026-71201 Mittel
    Score 30 CVSS 5 EPSS 0.16%

    OpenStack Ironic – Projektübergreifende Offenlegung von Portgroup-Daten

  43. CVE-2026-20028 Mittel
    Score 30 CVSS 5 EPSS 0.25%

    Cisco Terminal Service (TS) Agent: Umgehung kontobezogener Firewall-Regeln im Netzwerktreiber

  44. CVE-2026-18103 Mittel
    Score 29 CVSS 4.9 EPSS 0.40%

    dhcp-server: OMAPI-Schnittstelle ohne TSIG-Absicherung angreifbar

  45. CVE-2026-5062 Mittel
    Score 29 CVSS 4.9 EPSS 0.27%

    PrettyLinks (WordPress) – SQL Injection über Suchparameter

  46. CVE-2026-11920 Mittel
    Score 29 CVSS 4.9 EPSS 0.29%

    WordPress-Plugin JoomSport – zeitbasierte SQL-Injection über Parameter order

  47. CVE-2026-11969 Mittel
    Score 29 CVSS 4.9 EPSS 0.30%

    WP TripAdvisor Review Slider – SQL Injection über curselrevs[]

  48. CVE-2026-5651 Mittel
    Score 29 CVSS 4.9 EPSS 0.38%

    WordPress-Plugin Askeet: SQL-Injection über sql_query-Parameter in AJAX-Aktionen

  49. CVE-2026-71283 Mittel
    Score 29 CVSS 4.9 EPSS 0.29%

    Fledge Backup-Restore: tarfile.extractall() ohne Filter-Argument

  50. CVE-2026-20198 Mittel
    Score 29 CVSS 4.8 EPSS 0.21%

    Cisco Integrated Management Controller (IMC): Cross-Site-Scripting in der Web-Management-Oberfläche

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.