Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 651 bis 700 von 36300

  1. CVE-2026-71318 Mittel
    Score 29 CVSS 4.8 EPSS 0.21%

    Nuxt: Manipulierbare Auswahl dynamischer Komponenten über /__nuxt_island/-Endpunkt

  2. CVE-2026-18856 Mittel
    Score 28 CVSS 4.7 EPSS 0.23%

    Rhymix CMS bis 2.1.33 – Schwachstelle in procImporterAdminCheckXmlFile

  3. CVE-2026-15452 Mittel
    Score 28 CVSS 4.7 EPSS 0.24%

    Smash Balloon Social Photo Feed – Easy Social Feeds: Reflected XSS via REQUEST_URI

  4. CVE-2026-18903 Mittel
    Score 26 CVSS 4.3 EPSS 0.36%

    yeqifu warehouse – Schwachstelle in Controller-Datei

  5. CVE-2026-16613 Mittel
    Score 26 CVSS 4.3 EPSS 0.13%

    WordPress-Plugin GDPR Cookie Compliance – fehlende Ursprungsprüfung beim Cookie-Ablauf (CVE-2026-16613)

  6. CVE-2026-17515 Mittel
    Score 26 CVSS 4.3 EPSS 0.11%

    WordPress-Plugin MLSImport – fehlende Autorisierungs- und CSRF-Prüfung (CVE-2026-17515)

  7. CVE-2026-5108 Mittel
    Score 26 CVSS 4.4 EPSS 0.24%

    WordPress-Plugin Super Progressive Web Apps: Stored XSS über offline_message_txt-Einstellung

  8. CVE-2026-5116 Mittel
    Score 26 CVSS 4.4 EPSS 0.30%

    Contact Form 7 – Dynamic Text Extension (WordPress) – Stored XSS durch unzureichendes Output-Escaping

  9. CVE-2026-55996 Mittel
    Score 26 CVSS 4.3 EPSS 0.15%

    Rancher – Denial-of-Service in mehreren TLS-Listenern

  10. CVE-2026-7105 Mittel
    Score 26 CVSS 4.3 EPSS 0.20%

    Xpro Addons – Fehlende Berechtigungsprüfung ermöglicht Datenerstellung

  11. CVE-2026-71250 Mittel
    Score 26 CVSS 4.3 EPSS 0.22%

    Firefly III – SSRF über Webhook-URL-Validierung (127.0.0.0/8-Ausnahme)

  12. CVE-2026-71246 Mittel
    Score 26 CVSS 4.3 EPSS 0.16%

    Pixelfed – Unzureichende URL-Validierung in der Remote-Suche (SearchController)

  13. CVE-2026-70596 Mittel
    Score 26 CVSS 4.3

    Ghost CMS: Input-Validierungsschwachstelle im Feld feature_image_caption

  14. CVE-2026-20308 Mittel
    Score 26 CVSS 4.3 EPSS 0.32%

    Cisco IOS XE: Weitere Denial-of-Service-Schwachstelle in der Web-Management-Oberfläche

  15. CVE-2026-70427 Mittel
    Score 26 CVSS 4.3

    Jenkins 2.575 und früher / LTS 2.568.1 und früher: Unsichere Symlink-Verarbeitung beim Entpacken von .tar-Archiven

  16. CVE-2026-70428 Mittel
    Score 26 CVSS 4.3

    Jenkins: Unzureichende Erkennung von Pfadtraversierung in Datei-Parameternamen

  17. CVE-2026-70442 Mittel
    Score 26 CVSS 4.3

    Jenkins Google Chat Notification Plugin: Fehlender Kontext beim Credentials-Lookup

  18. CVE-2026-70443 Mittel
    Score 26 CVSS 4.3

    Jenkins Horreum Plugin: Fehlerhafter Kontext beim Credentials-Lookup

  19. CVE-2026-70444 Mittel
    Score 26 CVSS 4.3

    Jenkins Violation Comments to GitLab Plugin 2.62.0 und früher: Enumeration von Credential-IDs durch fehlende Berechtigungsprüfung

  20. CVE-2026-70446 Mittel
    Score 26 CVSS 4.3

    Jenkins CodeSonar Plugin: Fehlende Berechtigungsprüfung ermöglicht Enumeration von Credential-IDs

  21. CVE-2026-70447 Mittel
    Score 26 CVSS 4.3

    Jenkins AWS CodeBuild Plugin: Fehlende Berechtigungsprüfung ermöglicht Enumeration von Credential-IDs

  22. CVE-2026-70595 Mittel
    Score 24 CVSS 4 EPSS 0.18%

    Ghost CMS: Validierungsfehler bei Webmentions ermöglicht eingeschränkte HTTP-Anfragen (CVE-2026-70595)

  23. CVE-2026-12730 Niedrig
    Score 23 CVSS 3.8 EPSS 0.17%

    IBM Business Automation Workflow: Schwachstelle in mehreren Versionen

  24. CVE-2026-70598 Niedrig
    Score 23 CVSS 3.9

    Electron: Offenlegung von Offscreen-Rendering-Frame-Daten

  25. CVE-2026-16993 Niedrig
    Score 22 CVSS 3.7 EPSS 0.17%

    DHL Shipping Germany for WooCommerce – Ungeschützter Zugriff auf Versandlabel-Verzeichnis

  26. CVE-2025-15677 Niedrig
    Score 21 CVSS 3.5 EPSS 0.17%

    GeoDirectory (WordPress-Plugin): Stored XSS über die Place-Category-Einstellung

  27. CVE-2026-70600 Niedrig
    Score 19 CVSS 3.1 EPSS 0.14%

    Electron: Fehlerhafte Positionierung des nativen Autofill-Popups

  28. CVE-2026-18907 Mittel
    Score 0 EPSS 0.24%

    com.talpa.hibrowser (Android) – Path Traversal beim Datei-Download

  29. CVE-2026-55707 Mittel
    Score 0 EPSS 0.49%

    OpenStack Neutron – fehlende Eigentümerprüfung beim Subnetpool-Onboarding

  30. CVE-2026-71190 Mittel
    Score 0 EPSS 0.47%

    OpenStack Swift – Denial of Service durch anfällige Regex im Proxy-Server (ReDoS)

  31. CVE-2026-71191 Mittel
    Score 0 EPSS 0.25%

    OpenStack Swift S3API – Fehlende Signaturprüfung bei Presigned URLs

  32. CVE-2026-71192 Mittel
    Score 0 EPSS 0.25%

    OpenStack Swift – Fehlende Sanitisierung von Swift-Control-Headern in der S3API-Middleware

  33. CVE-2026-16746 Mittel
    Score 0 EPSS 0.22%

    MultiVendorX – Fehlende Eigentümerprüfung im REST-API-Endpunkt erlaubt Zugriff auf fremde Shops

  34. CVE-2026-16940 Mittel
    Score 0 EPSS 0.40%

    Custom Fields (WordPress) – Löschen beliebiger Dateien durch fehlende Pfadvalidierung

  35. CVE-2026-16981 Mittel
    Score 0 EPSS 0.19%

    DHL Shipping Germany for WooCommerce – Fehlende Autorisierungsprüfung beim Versandlabel-Download

  36. CVE-2026-66276 Mittel
    Score 0 EPSS 0.29%

    Apache-Software – Denial of Service durch fehlerhafte Range-Verarbeitung bei Disposition-Frames

  37. CVE-2026-68077 Mittel
    Score 0 EPSS 0.17%

    Denial of Service durch fehlerhafte Range-Verarbeitung (CVE-2026-68077)

  38. CVE-2026-70375 Mittel
    Score 0 EPSS 0.98%

    HashBrown CMS – OS Command Injection im Git-Deployer (GitDeployer.pullRepo)

  39. CVE-2026-64573 Mittel
    Score 0 EPSS 0.16%

    Linux-Kernel: NVM-Tag-Length-Underflow im Bluetooth-QCA-TLV-Parser

  40. CVE-2026-64577 Mittel
    Score 0 EPSS 0.54%

    Linux Kernel – GTP: fehlende Prüfung des skb_pull_data()-Rückgabewerts in gtp1u_send_echo_resp()

  41. CVE-2026-14304 Mittel
    Score 0 EPSS 0.15%

    Eclipse Accessibility Tools Framework (ACTF): Schwachstelle in miChecker bis Version 3.1.0

  42. CVE-2026-14574 Mittel
    Score 0 EPSS 0.15%

    Prototype Pollution in PreferenceUtils.merge von Eclipse Theia

  43. CVE-2026-48911 Mittel
    Score 0 EPSS 0.17%

    Apache Answer: Unzureichende Prüfung der Datenauthentizität bei externer Login-E-Mail-Bindung

  44. CVE-2026-48912 Mittel
    Score 0 EPSS 0.18%

    Apache Answer: Fehlende Eigentümerprüfung in der Avatar-Bereinigung

  45. CVE-2026-10716 Mittel
    Score 0 EPSS 0.31%

    Directus: Authentifizierte SQL-Injection im Collection-Erstellungsprozess bei PostgreSQL/PostGIS

  46. CVE-2026-17556 Mittel
    Score 0 EPSS 0.46%

    GitHub Enterprise Server: Pfadtraversierung ermöglicht Löschen beliebiger Dateien

  47. CVE-2026-66885 Mittel
    Score 0 EPSS 0.20%

    Livebook: Cross-Site Request Forgery ermöglicht Authentifizierung fremder Sitzungen unter Angreifer-Identität

  48. CVE-2026-68746 Mittel
    Score 0 EPSS 0.37%

    Livebook: Unsicheres Fail-Open-Verhalten bei der Identitätsprüfung

  49. CVE-2026-70429 Mittel
    Score 0 EPSS 0.17%

    Jenkins 2.575 und früher / LTS 2.568.1 und früher: Inkonsistente Gross-/Kleinschreibung bei Benutzer- und Gruppennamen

  50. CVE-2026-70430 Mittel
    Score 0 EPSS 0.17%

    Jenkins: Fehlende Typbeschränkung bei der Projekt-Namensstrategie-Konfiguration

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.