Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 801 bis 850 von 36300
- CVE-2026-18770 HochScore 44 CVSS 7.3 EPSS 0.30%
VibeSurf – Schwachstelle im Python Validation Handler (Datei /code)
- CVE-2026-18788 HochScore 44 CVSS 7.3 EPSS 0.38%
Trippo ResponsiveFilemanager – Schwachstelle in dialog.php
- CVE-2026-60007 HochScore 44 CVSS 7.4 EPSS 0.45%
Eclipse Milo: Unterscheidbare Fehlermeldungen bei Username-Token-Verarbeitung
- CVE-2026-14818 HochScore 43 CVSS 7.2 EPSS 0.36%
Zyxel ATP/USG FLEX – Path Traversal in CLI-Konfigurationsbefehl
- CVE-2026-11368 HochScore 43 CVSS 7.1 EPSS 0.18%
Bluetooth Host ATT Layer TX Buffer Channel Association Vulnerability
- CVE-2026-18811 HochScore 43 CVSS 7.2 EPSS 2.26%
H3C NX15: Kommandoinjektion über die Funktion Add in /api/esps
- CVE-2026-18812 HochScore 43 CVSS 7.2 EPSS 2.26%
H3C NX15: Command Injection über den Parameter workMode in esps.ipv6.wan
- CVE-2026-70485 HochScore 43 CVSS 7.1 EPSS 0.22%
Open WebUI: Unzureichende Prüfung global routingfähiger Ziel-URLs
- CVE-2026-14872 MittelScore 41 CVSS 6.8 EPSS 0.22%
Database for Contact Form 7, WPforms, Elementor forms (WordPress-Plugin): SQL-Injection
- CVE-2026-14939 MittelScore 41 CVSS 6.8 EPSS 0.23%
Visualizer WordPress-Plugin: Serverseitiger Abruf nicht eingeschränkter URLs (SSRF-Risiko)
- CVE-2026-16069 MittelScore 41 CVSS 6.8 EPSS 0.23%
WordPress-Plugin Brizy: Gespeichertes XSS über Fokuspunkt-Koordinaten
- CVE-2026-16293 MittelScore 41 CVSS 6.8 EPSS 0.23%
PowerPress Podcasting WordPress-Plugin: Fehlende Sanitisierung von Podcast-Episode-Einstellungen
- CVE-2026-24076 MittelScore 40 CVSS 6.7 EPSS 0.07%
Qualcomm: Speicherkorruption bei der Verarbeitung von Registrierungswerten mit falschem Typ
- CVE-2026-47619 MittelScore 40 CVSS 6.6 EPSS 0.36%
NVIDIA Dynamo (Linux): Schwachstelle in Beispielen und Rezepten kann Systemausfall verursachen
- CVE-2026-48121 MittelScore 40 CVSS 6.7
@langchain/langgraph-checkpoint-mongodb: NoSQL-Injection über Checkpoint-Kennungen
- CVE-2026-70593 MittelScore 40 CVSS 6.6 EPSS 0.29%
Ghost CMS: Pfad-Traversal in Custom Themes ermöglicht Schreibzugriff ausserhalb des Upload-Verzeichnisses
- CVE-2026-70594 MittelScore 40 CVSS 6.7 EPSS 0.16%
Ghost Admin: fehlende Session-Invalidierung ermöglicht Session-Fixation
- CVE-2026-66312 MittelScore 39 CVSS 6.5 EPSS 1.00%
Microsoft Edge (Chromium-based): Buffer Over-Read ermöglicht Codeausführung über das Netzwerk
- CVE-2026-66314 MittelScore 39 CVSS 6.5 EPSS 0.72%
Microsoft Edge (Chromium-based): Race Condition (TOCTOU) ermöglicht Offenlegung von Informationen über das Netzwerk
- CVE-2026-66326 MittelScore 39 CVSS 6.5 EPSS 0.65%
Microsoft Edge (Chromium-based): Fehlende Autorisierung ermöglicht Codeausführung
- CVE-2026-8508 MittelScore 39 CVSS 6.5 EPSS 0.70%
Zyxel WAX650S: Unzureichende Authentifizierung in social_login.cgi erlaubt Umgehung des Captive-Portal-Logins
- CVE-2026-24077 MittelScore 39 CVSS 6.5 EPSS 0.11%
Qualcomm: Offenlegung von Informationen bei fehlerhaft formatierten Längenfeldern beim WLAN-Kanalwechsel
- CVE-2026-24078 MittelScore 39 CVSS 6.5 EPSS 0.10%
Qualcomm: Informationsoffenlegung bei fehlgeschlagener IPSec-Verhandlung während NG-eCall SIP-Signaling
- CVE-2026-14816 MittelScore 39 CVSS 6.5 EPSS 0.25%
GDPR Framework by Data443 WordPress-Plugin: Unzureichende Prüfung bei Cookie-Consent und Privacy-Requests
- CVE-2026-14194 MittelScore 39 CVSS 6.5 EPSS 0.29%
HUMANIST Digital Human Resources: Path Traversal durch unzureichende Pfadprüfung
- CVE-2026-14465 MittelScore 39 CVSS 6.5 EPSS 0.21%
HUMANIST Digital Human Resources: Unzureichender Sitzungsablauf ermöglicht Session Replay
- CVE-2026-18809 MittelScore 39 CVSS 6.5 EPSS 0.21%
Firefox für Android und Firefox Focus: Informationsoffenlegung, behoben in Firefox 153.0.3
- CVE-2026-47620 MittelScore 39 CVSS 6.5 EPSS 0.22%
NVIDIA Dynamo: Race Condition bei der Initialisierung des LoRA-Manager-Singletons
- CVE-2026-47621 MittelScore 39 CVSS 6.5 EPSS 0.22%
NVIDIA Dynamo: Race Condition bei der Initialisierung des LoRA-Manager-Singletons
- CVE-2026-67199 MittelScore 39 CVSS 6.5
Perspective 5.0.0: Denial of Service durch unbeschränkte Schleifen in Ausdrücken
- CVE-2026-70368 MittelScore 39 CVSS 6.5 EPSS 0.35%
stunnel: Stack-basierter Out-of-Bounds-Read in s_vlog bei überlangen Log-Nachrichten
- CVE-2026-70489 MittelScore 39 CVSS 6.5 EPSS 0.29%
Open WebUI: Fehlerhafte Zeitverankerung bei der Verarbeitung wiederkehrender Automatisierungen
- CVE-2026-70491 MittelScore 39 CVSS 6.5 EPSS 0.26%
Open WebUI: Fehlende Zugriffskontrolle bei /api/v1/tools-Endpunkten
- CVE-2026-70493 MittelScore 39 CVSS 6.5 EPSS 0.30%
Open WebUI: Pfad-Schwachstelle in der integrierten Wissenssuche
- CVE-2026-63248 MittelScore 39 CVSS 6.5 EPSS 0.23%
Eclipse Milo 0.6.0–1.1.4: Fehlende Zugriffsautorisierung bei OPC-UA-Server-Diagnoseknoten
- CVE-2026-18723 MittelScore 38 CVSS 6.3 EPSS 0.20%
CVE-2026-18723 – Matrix Synapse / Element
- CVE-2026-18766 MittelScore 38 CVSS 6.3 EPSS 0.19%
chetans9 core-php-admin-panel: Schwachstelle bei Datei-Verarbeitung
- CVE-2026-18773 MittelScore 38 CVSS 6.3 EPSS 0.20%
NousResearch hermes-agent: Schwachstelle in _check_slash_access (Quick Command Handler)
- CVE-2026-54020 MittelScore 38 CVSS 6.3 EPSS 0.21%
Open WebUI: Umgehung der URL-Validierung für private und Loopback-Adressen
- CVE-2026-70490 MittelScore 38 CVSS 6.3 EPSS 0.21%
Open WebUI: Unzureichende Authentifizierung der Terminal-WebSocket-Route
- CVE-2026-18818 MittelScore 38 CVSS 6.3 EPSS 0.21%
Ehco1996 django-sspanel: Schwachstelle in TicketDetailView (Support Ticket Handler)
- CVE-2026-65804 MittelScore 37 CVSS 6.1 EPSS 0.42%
Microsoft Edge (Chromium-based): Code-Injection ermöglicht Spoofing über das Netzwerk
- CVE-2026-16792 MittelScore 37 CVSS 6.1 EPSS 0.07%
Lenovo XClarity Orchestrator (LXCO): Unzureichende Zertifikatsprüfung in mehreren Microservices
- CVE-2026-51144 MittelScore 37 CVSS 6.1 EPSS 0.19%
Soliton Systems MailZen Management Portal v2.62/v2.63: Cross-Site-Scripting über Benutzerprofilfelder
- CVE-2026-10526 MittelScore 35 CVSS 5.8 EPSS 0.23%
EmbedPress WordPress Plugin: Server-Side Request Forgery über unauthentifizierte Endpunkte
- CVE-2026-16547 MittelScore 35 CVSS 5.9 EPSS 0.27%
REST API Log WordPress Plugin: Fehlende Zugriffskontrolle beim Log-Download
- CVE-2026-48154 MittelScore 35 CVSS 5.9 EPSS 0.25%
GoRest: Race Condition bei nMemorySecret2FA
- CVE-2026-70592 MittelScore 33 CVSS 5.5 EPSS 0.30%
Ghost CMS: Administrator kann über Datenbank-Backup-Dateinamen Dateien im Dateisystem überschreiben
- CVE-2026-18720 MittelScore 32 CVSS 5.3 EPSS 0.29%
kodbox – Schwachstelle in der Komponente msgWarning Plugin
- CVE-2026-14848 MittelScore 32 CVSS 5.4 EPSS 0.17%
WordPress-Plugin Paid Membership Subscriptions: Fehlende Eigentümerprüfung beim Abo-Wechsel
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.