Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 801 bis 850 von 36300

  1. CVE-2026-18770 Hoch
    Score 44 CVSS 7.3 EPSS 0.30%

    VibeSurf – Schwachstelle im Python Validation Handler (Datei /code)

  2. CVE-2026-18788 Hoch
    Score 44 CVSS 7.3 EPSS 0.38%

    Trippo ResponsiveFilemanager – Schwachstelle in dialog.php

  3. CVE-2026-60007 Hoch
    Score 44 CVSS 7.4 EPSS 0.45%

    Eclipse Milo: Unterscheidbare Fehlermeldungen bei Username-Token-Verarbeitung

  4. CVE-2026-14818 Hoch
    Score 43 CVSS 7.2 EPSS 0.36%

    Zyxel ATP/USG FLEX – Path Traversal in CLI-Konfigurationsbefehl

  5. CVE-2026-11368 Hoch
    Score 43 CVSS 7.1 EPSS 0.18%

    Bluetooth Host ATT Layer TX Buffer Channel Association Vulnerability

  6. CVE-2026-18811 Hoch
    Score 43 CVSS 7.2 EPSS 2.26%

    H3C NX15: Kommandoinjektion über die Funktion Add in /api/esps

  7. CVE-2026-18812 Hoch
    Score 43 CVSS 7.2 EPSS 2.26%

    H3C NX15: Command Injection über den Parameter workMode in esps.ipv6.wan

  8. CVE-2026-70485 Hoch
    Score 43 CVSS 7.1 EPSS 0.22%

    Open WebUI: Unzureichende Prüfung global routingfähiger Ziel-URLs

  9. CVE-2026-14872 Mittel
    Score 41 CVSS 6.8 EPSS 0.22%

    Database for Contact Form 7, WPforms, Elementor forms (WordPress-Plugin): SQL-Injection

  10. CVE-2026-14939 Mittel
    Score 41 CVSS 6.8 EPSS 0.23%

    Visualizer WordPress-Plugin: Serverseitiger Abruf nicht eingeschränkter URLs (SSRF-Risiko)

  11. CVE-2026-16069 Mittel
    Score 41 CVSS 6.8 EPSS 0.23%

    WordPress-Plugin Brizy: Gespeichertes XSS über Fokuspunkt-Koordinaten

  12. CVE-2026-16293 Mittel
    Score 41 CVSS 6.8 EPSS 0.23%

    PowerPress Podcasting WordPress-Plugin: Fehlende Sanitisierung von Podcast-Episode-Einstellungen

  13. CVE-2026-24076 Mittel
    Score 40 CVSS 6.7 EPSS 0.07%

    Qualcomm: Speicherkorruption bei der Verarbeitung von Registrierungswerten mit falschem Typ

  14. CVE-2026-47619 Mittel
    Score 40 CVSS 6.6 EPSS 0.36%

    NVIDIA Dynamo (Linux): Schwachstelle in Beispielen und Rezepten kann Systemausfall verursachen

  15. CVE-2026-48121 Mittel
    Score 40 CVSS 6.7

    @langchain/langgraph-checkpoint-mongodb: NoSQL-Injection über Checkpoint-Kennungen

  16. CVE-2026-70593 Mittel
    Score 40 CVSS 6.6 EPSS 0.29%

    Ghost CMS: Pfad-Traversal in Custom Themes ermöglicht Schreibzugriff ausserhalb des Upload-Verzeichnisses

  17. CVE-2026-70594 Mittel
    Score 40 CVSS 6.7 EPSS 0.16%

    Ghost Admin: fehlende Session-Invalidierung ermöglicht Session-Fixation

  18. CVE-2026-66312 Mittel
    Score 39 CVSS 6.5 EPSS 1.00%

    Microsoft Edge (Chromium-based): Buffer Over-Read ermöglicht Codeausführung über das Netzwerk

  19. CVE-2026-66314 Mittel
    Score 39 CVSS 6.5 EPSS 0.72%

    Microsoft Edge (Chromium-based): Race Condition (TOCTOU) ermöglicht Offenlegung von Informationen über das Netzwerk

  20. CVE-2026-66326 Mittel
    Score 39 CVSS 6.5 EPSS 0.65%

    Microsoft Edge (Chromium-based): Fehlende Autorisierung ermöglicht Codeausführung

  21. CVE-2026-8508 Mittel
    Score 39 CVSS 6.5 EPSS 0.70%

    Zyxel WAX650S: Unzureichende Authentifizierung in social_login.cgi erlaubt Umgehung des Captive-Portal-Logins

  22. CVE-2026-24077 Mittel
    Score 39 CVSS 6.5 EPSS 0.11%

    Qualcomm: Offenlegung von Informationen bei fehlerhaft formatierten Längenfeldern beim WLAN-Kanalwechsel

  23. CVE-2026-24078 Mittel
    Score 39 CVSS 6.5 EPSS 0.10%

    Qualcomm: Informationsoffenlegung bei fehlgeschlagener IPSec-Verhandlung während NG-eCall SIP-Signaling

  24. CVE-2026-14816 Mittel
    Score 39 CVSS 6.5 EPSS 0.25%

    GDPR Framework by Data443 WordPress-Plugin: Unzureichende Prüfung bei Cookie-Consent und Privacy-Requests

  25. CVE-2026-14194 Mittel
    Score 39 CVSS 6.5 EPSS 0.29%

    HUMANIST Digital Human Resources: Path Traversal durch unzureichende Pfadprüfung

  26. CVE-2026-14465 Mittel
    Score 39 CVSS 6.5 EPSS 0.21%

    HUMANIST Digital Human Resources: Unzureichender Sitzungsablauf ermöglicht Session Replay

  27. CVE-2026-18809 Mittel
    Score 39 CVSS 6.5 EPSS 0.21%

    Firefox für Android und Firefox Focus: Informationsoffenlegung, behoben in Firefox 153.0.3

  28. CVE-2026-47620 Mittel
    Score 39 CVSS 6.5 EPSS 0.22%

    NVIDIA Dynamo: Race Condition bei der Initialisierung des LoRA-Manager-Singletons

  29. CVE-2026-47621 Mittel
    Score 39 CVSS 6.5 EPSS 0.22%

    NVIDIA Dynamo: Race Condition bei der Initialisierung des LoRA-Manager-Singletons

  30. CVE-2026-67199 Mittel
    Score 39 CVSS 6.5

    Perspective 5.0.0: Denial of Service durch unbeschränkte Schleifen in Ausdrücken

  31. CVE-2026-70368 Mittel
    Score 39 CVSS 6.5 EPSS 0.35%

    stunnel: Stack-basierter Out-of-Bounds-Read in s_vlog bei überlangen Log-Nachrichten

  32. CVE-2026-70489 Mittel
    Score 39 CVSS 6.5 EPSS 0.29%

    Open WebUI: Fehlerhafte Zeitverankerung bei der Verarbeitung wiederkehrender Automatisierungen

  33. CVE-2026-70491 Mittel
    Score 39 CVSS 6.5 EPSS 0.26%

    Open WebUI: Fehlende Zugriffskontrolle bei /api/v1/tools-Endpunkten

  34. CVE-2026-70493 Mittel
    Score 39 CVSS 6.5 EPSS 0.30%

    Open WebUI: Pfad-Schwachstelle in der integrierten Wissenssuche

  35. CVE-2026-63248 Mittel
    Score 39 CVSS 6.5 EPSS 0.23%

    Eclipse Milo 0.6.0–1.1.4: Fehlende Zugriffsautorisierung bei OPC-UA-Server-Diagnoseknoten

  36. CVE-2026-18723 Mittel
    Score 38 CVSS 6.3 EPSS 0.20%

    CVE-2026-18723 – Matrix Synapse / Element

  37. CVE-2026-18766 Mittel
    Score 38 CVSS 6.3 EPSS 0.19%

    chetans9 core-php-admin-panel: Schwachstelle bei Datei-Verarbeitung

  38. CVE-2026-18773 Mittel
    Score 38 CVSS 6.3 EPSS 0.20%

    NousResearch hermes-agent: Schwachstelle in _check_slash_access (Quick Command Handler)

  39. CVE-2026-54020 Mittel
    Score 38 CVSS 6.3 EPSS 0.21%

    Open WebUI: Umgehung der URL-Validierung für private und Loopback-Adressen

  40. CVE-2026-70490 Mittel
    Score 38 CVSS 6.3 EPSS 0.21%

    Open WebUI: Unzureichende Authentifizierung der Terminal-WebSocket-Route

  41. CVE-2026-18818 Mittel
    Score 38 CVSS 6.3 EPSS 0.21%

    Ehco1996 django-sspanel: Schwachstelle in TicketDetailView (Support Ticket Handler)

  42. CVE-2026-65804 Mittel
    Score 37 CVSS 6.1 EPSS 0.42%

    Microsoft Edge (Chromium-based): Code-Injection ermöglicht Spoofing über das Netzwerk

  43. CVE-2026-16792 Mittel
    Score 37 CVSS 6.1 EPSS 0.07%

    Lenovo XClarity Orchestrator (LXCO): Unzureichende Zertifikatsprüfung in mehreren Microservices

  44. CVE-2026-51144 Mittel
    Score 37 CVSS 6.1 EPSS 0.19%

    Soliton Systems MailZen Management Portal v2.62/v2.63: Cross-Site-Scripting über Benutzerprofilfelder

  45. CVE-2026-10526 Mittel
    Score 35 CVSS 5.8 EPSS 0.23%

    EmbedPress WordPress Plugin: Server-Side Request Forgery über unauthentifizierte Endpunkte

  46. CVE-2026-16547 Mittel
    Score 35 CVSS 5.9 EPSS 0.27%

    REST API Log WordPress Plugin: Fehlende Zugriffskontrolle beim Log-Download

  47. CVE-2026-48154 Mittel
    Score 35 CVSS 5.9 EPSS 0.25%

    GoRest: Race Condition bei nMemorySecret2FA

  48. CVE-2026-70592 Mittel
    Score 33 CVSS 5.5 EPSS 0.30%

    Ghost CMS: Administrator kann über Datenbank-Backup-Dateinamen Dateien im Dateisystem überschreiben

  49. CVE-2026-18720 Mittel
    Score 32 CVSS 5.3 EPSS 0.29%

    kodbox – Schwachstelle in der Komponente msgWarning Plugin

  50. CVE-2026-14848 Mittel
    Score 32 CVSS 5.4 EPSS 0.17%

    WordPress-Plugin Paid Membership Subscriptions: Fehlende Eigentümerprüfung beim Abo-Wechsel

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.