Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 651 bis 700 von 36300
- CVE-2026-71318 MittelScore 29 CVSS 4.8 EPSS 0.21%
Nuxt: Manipulierbare Auswahl dynamischer Komponenten über /__nuxt_island/-Endpunkt
- CVE-2026-18856 MittelScore 28 CVSS 4.7 EPSS 0.23%
Rhymix CMS bis 2.1.33 – Schwachstelle in procImporterAdminCheckXmlFile
- CVE-2026-15452 MittelScore 28 CVSS 4.7 EPSS 0.24%
Smash Balloon Social Photo Feed – Easy Social Feeds: Reflected XSS via REQUEST_URI
- CVE-2026-18903 MittelScore 26 CVSS 4.3 EPSS 0.36%
yeqifu warehouse – Schwachstelle in Controller-Datei
- CVE-2026-16613 MittelScore 26 CVSS 4.3 EPSS 0.13%
WordPress-Plugin GDPR Cookie Compliance – fehlende Ursprungsprüfung beim Cookie-Ablauf (CVE-2026-16613)
- CVE-2026-17515 MittelScore 26 CVSS 4.3 EPSS 0.11%
WordPress-Plugin MLSImport – fehlende Autorisierungs- und CSRF-Prüfung (CVE-2026-17515)
- CVE-2026-5108 MittelScore 26 CVSS 4.4 EPSS 0.24%
WordPress-Plugin Super Progressive Web Apps: Stored XSS über offline_message_txt-Einstellung
- CVE-2026-5116 MittelScore 26 CVSS 4.4 EPSS 0.30%
Contact Form 7 – Dynamic Text Extension (WordPress) – Stored XSS durch unzureichendes Output-Escaping
- CVE-2026-55996 MittelScore 26 CVSS 4.3 EPSS 0.15%
Rancher – Denial-of-Service in mehreren TLS-Listenern
- CVE-2026-7105 MittelScore 26 CVSS 4.3 EPSS 0.20%
Xpro Addons – Fehlende Berechtigungsprüfung ermöglicht Datenerstellung
- CVE-2026-71250 MittelScore 26 CVSS 4.3 EPSS 0.22%
Firefly III – SSRF über Webhook-URL-Validierung (127.0.0.0/8-Ausnahme)
- CVE-2026-71246 MittelScore 26 CVSS 4.3 EPSS 0.16%
Pixelfed – Unzureichende URL-Validierung in der Remote-Suche (SearchController)
- CVE-2026-70596 MittelScore 26 CVSS 4.3
Ghost CMS: Input-Validierungsschwachstelle im Feld feature_image_caption
- CVE-2026-20308 MittelScore 26 CVSS 4.3 EPSS 0.32%
Cisco IOS XE: Weitere Denial-of-Service-Schwachstelle in der Web-Management-Oberfläche
- CVE-2026-70427 MittelScore 26 CVSS 4.3
Jenkins 2.575 und früher / LTS 2.568.1 und früher: Unsichere Symlink-Verarbeitung beim Entpacken von .tar-Archiven
- CVE-2026-70428 MittelScore 26 CVSS 4.3
Jenkins: Unzureichende Erkennung von Pfadtraversierung in Datei-Parameternamen
- CVE-2026-70442 MittelScore 26 CVSS 4.3
Jenkins Google Chat Notification Plugin: Fehlender Kontext beim Credentials-Lookup
- CVE-2026-70443 MittelScore 26 CVSS 4.3
Jenkins Horreum Plugin: Fehlerhafter Kontext beim Credentials-Lookup
- CVE-2026-70444 MittelScore 26 CVSS 4.3
Jenkins Violation Comments to GitLab Plugin 2.62.0 und früher: Enumeration von Credential-IDs durch fehlende Berechtigungsprüfung
- CVE-2026-70446 MittelScore 26 CVSS 4.3
Jenkins CodeSonar Plugin: Fehlende Berechtigungsprüfung ermöglicht Enumeration von Credential-IDs
- CVE-2026-70447 MittelScore 26 CVSS 4.3
Jenkins AWS CodeBuild Plugin: Fehlende Berechtigungsprüfung ermöglicht Enumeration von Credential-IDs
- CVE-2026-70595 MittelScore 24 CVSS 4 EPSS 0.18%
Ghost CMS: Validierungsfehler bei Webmentions ermöglicht eingeschränkte HTTP-Anfragen (CVE-2026-70595)
- CVE-2026-12730 NiedrigScore 23 CVSS 3.8 EPSS 0.17%
IBM Business Automation Workflow: Schwachstelle in mehreren Versionen
- CVE-2026-70598 NiedrigScore 23 CVSS 3.9
Electron: Offenlegung von Offscreen-Rendering-Frame-Daten
- CVE-2026-16993 NiedrigScore 22 CVSS 3.7 EPSS 0.17%
DHL Shipping Germany for WooCommerce – Ungeschützter Zugriff auf Versandlabel-Verzeichnis
- CVE-2025-15677 NiedrigScore 21 CVSS 3.5 EPSS 0.17%
GeoDirectory (WordPress-Plugin): Stored XSS über die Place-Category-Einstellung
- CVE-2026-70600 NiedrigScore 19 CVSS 3.1 EPSS 0.14%
Electron: Fehlerhafte Positionierung des nativen Autofill-Popups
- CVE-2026-18907 MittelScore 0 EPSS 0.24%
com.talpa.hibrowser (Android) – Path Traversal beim Datei-Download
- CVE-2026-55707 MittelScore 0 EPSS 0.49%
OpenStack Neutron – fehlende Eigentümerprüfung beim Subnetpool-Onboarding
- CVE-2026-71190 MittelScore 0 EPSS 0.47%
OpenStack Swift – Denial of Service durch anfällige Regex im Proxy-Server (ReDoS)
- CVE-2026-71191 MittelScore 0 EPSS 0.25%
OpenStack Swift S3API – Fehlende Signaturprüfung bei Presigned URLs
- CVE-2026-71192 MittelScore 0 EPSS 0.25%
OpenStack Swift – Fehlende Sanitisierung von Swift-Control-Headern in der S3API-Middleware
- CVE-2026-16746 MittelScore 0 EPSS 0.22%
MultiVendorX – Fehlende Eigentümerprüfung im REST-API-Endpunkt erlaubt Zugriff auf fremde Shops
- CVE-2026-16940 MittelScore 0 EPSS 0.40%
Custom Fields (WordPress) – Löschen beliebiger Dateien durch fehlende Pfadvalidierung
- CVE-2026-16981 MittelScore 0 EPSS 0.19%
DHL Shipping Germany for WooCommerce – Fehlende Autorisierungsprüfung beim Versandlabel-Download
- CVE-2026-66276 MittelScore 0 EPSS 0.29%
Apache-Software – Denial of Service durch fehlerhafte Range-Verarbeitung bei Disposition-Frames
- CVE-2026-68077 MittelScore 0 EPSS 0.17%
Denial of Service durch fehlerhafte Range-Verarbeitung (CVE-2026-68077)
- CVE-2026-70375 MittelScore 0 EPSS 0.98%
HashBrown CMS – OS Command Injection im Git-Deployer (GitDeployer.pullRepo)
- CVE-2026-64573 MittelScore 0 EPSS 0.16%
Linux-Kernel: NVM-Tag-Length-Underflow im Bluetooth-QCA-TLV-Parser
- CVE-2026-64577 MittelScore 0 EPSS 0.54%
Linux Kernel – GTP: fehlende Prüfung des skb_pull_data()-Rückgabewerts in gtp1u_send_echo_resp()
- CVE-2026-14304 MittelScore 0 EPSS 0.15%
Eclipse Accessibility Tools Framework (ACTF): Schwachstelle in miChecker bis Version 3.1.0
- CVE-2026-14574 MittelScore 0 EPSS 0.15%
Prototype Pollution in PreferenceUtils.merge von Eclipse Theia
- CVE-2026-48911 MittelScore 0 EPSS 0.17%
Apache Answer: Unzureichende Prüfung der Datenauthentizität bei externer Login-E-Mail-Bindung
- CVE-2026-48912 MittelScore 0 EPSS 0.18%
Apache Answer: Fehlende Eigentümerprüfung in der Avatar-Bereinigung
- CVE-2026-10716 MittelScore 0 EPSS 0.31%
Directus: Authentifizierte SQL-Injection im Collection-Erstellungsprozess bei PostgreSQL/PostGIS
- CVE-2026-17556 MittelScore 0 EPSS 0.46%
GitHub Enterprise Server: Pfadtraversierung ermöglicht Löschen beliebiger Dateien
- CVE-2026-66885 MittelScore 0 EPSS 0.20%
Livebook: Cross-Site Request Forgery ermöglicht Authentifizierung fremder Sitzungen unter Angreifer-Identität
- CVE-2026-68746 MittelScore 0 EPSS 0.37%
Livebook: Unsicheres Fail-Open-Verhalten bei der Identitätsprüfung
- CVE-2026-70429 MittelScore 0 EPSS 0.17%
Jenkins 2.575 und früher / LTS 2.568.1 und früher: Inkonsistente Gross-/Kleinschreibung bei Benutzer- und Gruppennamen
- CVE-2026-70430 MittelScore 0 EPSS 0.17%
Jenkins: Fehlende Typbeschränkung bei der Projekt-Namensstrategie-Konfiguration
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.