Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 601 bis 650 von 36300
- CVE-2026-70439 MittelScore 39 CVSS 6.5
Jenkins XML Job to Job DSL Plugin: Fehlende Berechtigungsprüfung ermöglicht Aufruf der Konvertierungsfunktion
- CVE-2026-7646 MittelScore 39 CVSS 6.5 EPSS 0.29%
IBM Langflow OSS: Path Traversal ermöglicht Zugriff auf beliebige Server-Dateien
- CVE-2026-7657 MittelScore 39 CVSS 6.5 EPSS 0.20%
IBM Langflow OSS: Server-Side Request Forgery durch unzureichenden Schutz
- CVE-2026-7658 MittelScore 39 CVSS 6.5 EPSS 0.35%
IBM Langflow OSS 1.0.0–1.10.3: Path Traversal über das Username-Feld
- CVE-2026-18896 MittelScore 38 CVSS 6.3 EPSS 0.19%
Student-Registration-System: Argumentmanipulation in changepass.php (CVE-2026-18896)
- CVE-2026-6972 MittelScore 38 CVSS 6.4 EPSS 0.20%
SKT Skill Bar (WordPress) – Stored XSS über das chart_size-Attribut des skillwrapper-Shortcodes
- CVE-2026-7441 MittelScore 38 CVSS 6.4 EPSS 0.20%
WordPress-Plugin Simple Yearly Archive – Stored Cross-Site Scripting über Shortcode-Attribut
- CVE-2026-70597 MittelScore 38 CVSS 6.3
Electron: Schwachstelle bei der macOS-Berechtigungsprüfung
- CVE-2026-20311 MittelScore 38 CVSS 6.3 EPSS 0.16%
Cisco IOS XE: Denial of Service über Web-Management-Oberfläche
- CVE-2026-71311 MittelScore 38 CVSS 6.4 EPSS 0.24%
rclone: Nicht standardmässiges FTP-Dateinamens-Encoding vor Version 1.75.0
- CVE-2026-8790 MittelScore 37 CVSS 6.1 EPSS 0.22%
Football Pool – Reflected Cross-Site Scripting im WordPress-Plugin
- CVE-2026-16583 MittelScore 37 CVSS 6.1 EPSS 0.18%
Orbit Fox (WordPress) – Fehlende Bereinigung hochgeladener SVG-Dateien
- CVE-2026-17505 MittelScore 37 CVSS 6.1 EPSS 0.80%
TranslatePress – Reflected Cross-Site Scripting über Parameter s
- CVE-2026-17532 MittelScore 37 CVSS 6.1 EPSS 0.35%
WordPress-Plugin Seraphinite Accelerator: Reflected XSS über seraph_accel_prep-Parameter
- CVE-2026-71249 MittelScore 37 CVSS 6.1 EPSS 0.15%
299Ko: Reflected Cross-Site-Scripting im öffentlichen Kontaktformular
- CVE-2026-71293 MittelScore 37 CVSS 6.2 EPSS 0.21%
Statamic CMS: Offenlegung von Zwei-Faktor-Recovery-Codes über AugmentedUser
- CVE-2026-53992 MittelScore 37 CVSS 6.1
ProjectSend r2029: Reflektiertes Cross-Site-Scripting in thumbnails-regenerate.php
- CVE-2026-70603 MittelScore 36 CVSS 6
Electron: shell.openPath() weist unzulässige Pfade nicht zurück
- CVE-2026-70599 MittelScore 35 CVSS 5.9
Electron: Fehlerhafte Berechtigungsprüfung bei Serial-Port- und Medienzugriffen
- CVE-2026-70605 MittelScore 35 CVSS 5.9 EPSS 0.20%
Electron: Schwachstelle bei HTTP-Redirects in net.fetch() (CVE-2026-70605)
- CVE-2026-70606 MittelScore 35 CVSS 5.9
Electron: Schwachstelle bei benutzerdefinierten Protokoll-Handlern
- CVE-2026-10547 MittelScore 35 CVSS 5.9 EPSS 0.20%
IBM Langflow OSS: Fehlende Ownership-Prüfung im veralteten Vertices-Build-Endpunkt
- CVE-2026-71310 MittelScore 35 CVSS 5.9 EPSS 0.37%
rclone: Fehlerhafte Verarbeitung von HTTP-CONNECT-Anfragen im gemeinsamen Proxy-Helper (vor Version 1.75.0)
- CVE-2026-20289 MittelScore 34 CVSS 5.7 EPSS 0.19%
Cisco RoomOS: Offenlegung sensibler Informationen im Logging-Subsystem
- CVE-2026-70609 MittelScore 34 CVSS 5.7
Electron: Schwachstelle über die mode-Option von webContents.openDevTools()
- CVE-2026-18954 MittelScore 33 CVSS 5.5 EPSS 0.11%
AWS Labs DocumentDB MCP Server: Fehlerhafte Autorisierung im Aggregation-Pipeline-Tool
- CVE-2026-18853 MittelScore 32 CVSS 5.3 EPSS 0.17%
ZomboDroid Meme Generator App 4.6830 (Android): Schwachstelle in Funktion t5.l.c
- CVE-2026-16942 MittelScore 32 CVSS 5.4 EPSS 0.13%
WordPress-Plugin WP Custom HTML Page – fehlende Bereinigung von HTML-Inhalten (CVE-2026-16942)
- CVE-2026-55998 MittelScore 32 CVSS 5.3 EPSS 0.21%
Zoho ManageEngine – fehlende Token-Validierung vor Cluster-Zugriff im Import-Endpunkt
- CVE-2026-71203 MittelScore 32 CVSS 5.3 EPSS 0.26%
changedetection.io – ungeschützter REST-API-Endpunkt full-spec ohne API-Key-Prüfung
- CVE-2026-12762 MittelScore 32 CVSS 5.3 EPSS 0.24%
IBM Cloud Pak For Business Automation: Offenlegung sensibler Informationen in Manifest-Dateien
- CVE-2026-16071 MittelScore 32 CVSS 5.4 EPSS 0.18%
Keycloak: Schwachstelle im LDAP-Storage-Provider bei Suchanfragen durch delegierte Administratoren
- CVE-2026-18531 MittelScore 32 CVSS 5.3 EPSS 0.38%
IBM Maximo Application Suite: Manipulation von Sitzungsdaten durch schwaches HMAC-Signierungsgeheimnis (CVE-2026-18531)
- CVE-2026-21766 MittelScore 32 CVSS 5.4 EPSS 0.18%
HCL Digital Experience: Unzureichender Schutz von Zugangsdaten im Standard-Login-Portlet
- CVE-2026-70440 MittelScore 32 CVSS 5.4
Jenkins Qualys Container Scanning Connector Plugin: Gespeichertes XSS durch fehlende Eingabe-Maskierung
- CVE-2026-70441 MittelScore 32 CVSS 5.4
Jenkins Summary Display Plugin: Gespeichertes XSS über Job-Namen
- CVE-2026-70607 MittelScore 32 CVSS 5.3
Electron: Unsichere Übernahme von Fenster-Optionen aus Web-Inhalten
- CVE-2026-70610 MittelScore 32 CVSS 5.4 EPSS 0.38%
Electron vor 39.8.9, 40.9.2, 41.2.2 und 42.0.0-beta.4: Problem beim Kopieren von Objekten über die contextBridge
- CVE-2026-70612 MittelScore 32 CVSS 5.4
Electron: Schwachstelle bei Anfragen zum Öffnen externer Protokoll-URLs
- CVE-2026-7869 MittelScore 32 CVSS 5.4 EPSS 0.20%
IBM Langflow OSS: Path Traversal in der Knowledge-Bases-API
- CVE-2026-18959 MittelScore 32 CVSS 5.4 EPSS 0.37%
yushine InnoShop bis 0.8.2 – Schwachstelle in FileManagerController::destroyFiles (Datei-Manager-Komponente)
- CVE-2026-71201 MittelScore 30 CVSS 5 EPSS 0.16%
OpenStack Ironic – Projektübergreifende Offenlegung von Portgroup-Daten
- CVE-2026-20028 MittelScore 30 CVSS 5 EPSS 0.25%
Cisco Terminal Service (TS) Agent: Umgehung kontobezogener Firewall-Regeln im Netzwerktreiber
- CVE-2026-18103 MittelScore 29 CVSS 4.9 EPSS 0.40%
dhcp-server: OMAPI-Schnittstelle ohne TSIG-Absicherung angreifbar
- CVE-2026-5062 MittelScore 29 CVSS 4.9 EPSS 0.27%
PrettyLinks (WordPress) – SQL Injection über Suchparameter
- CVE-2026-11920 MittelScore 29 CVSS 4.9 EPSS 0.29%
WordPress-Plugin JoomSport – zeitbasierte SQL-Injection über Parameter order
- CVE-2026-11969 MittelScore 29 CVSS 4.9 EPSS 0.30%
WP TripAdvisor Review Slider – SQL Injection über curselrevs[]
- CVE-2026-5651 MittelScore 29 CVSS 4.9 EPSS 0.38%
WordPress-Plugin Askeet: SQL-Injection über sql_query-Parameter in AJAX-Aktionen
- CVE-2026-71283 MittelScore 29 CVSS 4.9 EPSS 0.29%
Fledge Backup-Restore: tarfile.extractall() ohne Filter-Argument
- CVE-2026-20198 MittelScore 29 CVSS 4.8 EPSS 0.21%
Cisco Integrated Management Controller (IMC): Cross-Site-Scripting in der Web-Management-Oberfläche
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.