Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 851 bis 900 von 36300

  1. CVE-2026-16536 Mittel
    Score 32 CVSS 5.3 EPSS 0.19%

    Simple Google Calendar Outlook Events Widget (WordPress-Plugin): Server-Side Request Forgery

  2. CVE-2026-16548 Mittel
    Score 32 CVSS 5.4 EPSS 0.36%

    WordPress-Plugin Chat Widget: Fehlende Validierung beim Datei-Upload

  3. CVE-2026-14192 Mittel
    Score 32 CVSS 5.4 EPSS 0.13%

    HUMANIST Digital Human Resources: Gespeichertes Cross-Site-Scripting

  4. CVE-2026-14202 Mittel
    Score 32 CVSS 5.3 EPSS 0.20%

    HUMANIST Digital Human Resources: Beobachtbare Antwortdiskrepanz ermöglicht Account-Footprinting

  5. CVE-2026-14219 Mittel
    Score 32 CVSS 5.4 EPSS 0.12%

    HUMANIST Digital Human Resources: Offene Weiterleitung ermöglicht Phishing

  6. CVE-2026-15337 Mittel
    Score 32 CVSS 5.3 EPSS 0.52%

    Django: Denial-of-Service in check_for_language() durch viele Sprachcodes

  7. CVE-2026-47622 Mittel
    Score 32 CVSS 5.3 EPSS 0.24%

    NVIDIA Dynamo (Linux): Offenlegung sensibler Informationen in Fehlermeldungen

  8. CVE-2026-70481 Mittel
    Score 32 CVSS 5.4 EPSS 0.30%

    Open WebUI: Fehlende Autorisierungsprüfung bei Channel-Nachrichten

  9. CVE-2026-70487 Mittel
    Score 32 CVSS 5.3 EPSS 0.25%

    Open WebUI: Ungefilterte client-seitige Knowledge-Attachments in Modell-Metadaten

  10. CVE-2026-70588 Mittel
    Score 30 CVSS 5 EPSS 0.26%

    Ghost: Cross-Site-Scripting über den Universal-Import in Ghost Admin

  11. CVE-2026-14824 Mittel
    Score 29 CVSS 4.8 EPSS 0.17%

    Quiz and Survey Master (QSM) WordPress Plugin: Fehlendes Escaping einer Frageneinstellung

  12. CVE-2026-15233 Mittel
    Score 29 CVSS 4.8 EPSS 0.14%

    Nested Pages WordPress Plugin: Fehlendes Escaping von Post-Titeln

  13. CVE-2026-70589 Mittel
    Score 29 CVSS 4.8 EPSS 0.17%

    Ghost CMS: Fehlende Validierung erlaubt Einlösen inaktiver Abo-Angebote

  14. CVE-2026-70590 Mittel
    Score 29 CVSS 4.8 EPSS 0.19%

    Ghost Admin API: Leck gehashter Passwörter durch Staff-Nutzer

  15. CVE-2026-16296 Mittel
    Score 28 CVSS 4.7 EPSS 0.19%

    WordPress-Plugin Clearfy Cache: Offene Weiterleitung im Redirect-Handler

  16. CVE-2026-17614 Mittel
    Score 26 CVSS 4.4 EPSS 0.85%

    WildFly Domain Mode – Path Traversal in LocalFileRepository

  17. CVE-2026-12698 Mittel
    Score 26 CVSS 4.3 EPSS 0.18%

    wpForo Forum (WordPress-Plugin): Fehlende Beschränkung setzbarer Profilfelder

  18. CVE-2026-16035 Mittel
    Score 26 CVSS 4.3 EPSS 0.19%

    miniOrange 2FA (WordPress-Plugin): Fehlende Bindung des OTP-Empfängers an den registrierenden Nutzer

  19. CVE-2026-16056 Mittel
    Score 26 CVSS 4.3 EPSS 0.16%

    Contest Gallery WordPress-Plugin: Fehlende Rechte-/Nonce-Prüfung erlaubt Lesen sensibler Daten

  20. CVE-2026-16295 Mittel
    Score 26 CVSS 4.3 EPSS 0.16%

    Clearfy Cache WordPress Plugin: Fehlende Berechtigungsprüfung im Admin-Bereich

  21. CVE-2026-16546 Mittel
    Score 26 CVSS 4.3 EPSS 0.15%

    Wired Impact Volunteer Management WordPress-Plugin: Fehlende Autorisierungsprüfung bei RSVP-Entfernung

  22. CVE-2026-47487 Mittel
    Score 26 CVSS 4.4 EPSS 0.16%

    NVIDIA Triton Inference Server (Linux): Pfadmanipulation über den Modellnamen

  23. CVE-2026-70484 Mittel
    Score 26 CVSS 4.3 EPSS 0.27%

    Open WebUI: Client-gesteuertes Flag in Legacy-Chat-Completions umgeht Vertrauensprüfung

  24. CVE-2026-70488 Mittel
    Score 26 CVSS 4.3 EPSS 0.21%

    Open WebUI: Fehlende Autorisierungsprüfung im Sync-Cleanup-Endpunkt

  25. CVE-2026-18819 Mittel
    Score 26 CVSS 4.3 EPSS 0.16%

    RackTables: Cross-Site-Request-Forgery (CSRF) in unbekanntem Code (bis Version 0.22.0)

  26. CVE-2026-70480 Mittel
    Score 25 CVSS 4.1 EPSS 0.19%

    Open WebUI: Cross-Site-Scripting über Vega- und Vega-Lite-Codeblöcke im Chat

  27. CVE-2026-70591 Mittel
    Score 25 CVSS 4.1 EPSS 0.23%

    Ghost CMS: Server-Side Request Forgery beim Abruf von Admin-Bildern

  28. CVE-2026-16791 Niedrig
    Score 23 CVSS 3.9 EPSS 0.09%

    Lenovo XClarity Essentials OneCLI (Linux): Temporäre Dateien ermöglichen Überschreiben lokaler Dateien

  29. CVE-2026-18569 Niedrig
    Score 22 CVSS 3.7 EPSS 0.16%

    Red Hat Build of Keycloak – Schwachstelle im Backchannel-Logout-Endpunkt

  30. CVE-2026-11366 Niedrig
    Score 22 CVSS 3.7 EPSS 0.19%

    WordPress-Plugin MonsterInsights: Unzureichende Signaturprüfung bei unauthentifizierter AJAX-Aktion

  31. CVE-2026-16068 Niedrig
    Score 21 CVSS 3.5 EPSS 0.14%

    Brizy WordPress Plugin: Unzureichende Zugriffskontrolle bei globalen Design-Daten

  32. CVE-2026-70483 Niedrig
    Score 19 CVSS 3.1 EPSS 0.24%

    Open WebUI: Race Condition beim Löschen von Chats (DELETE /api/v1/chats/{id})

  33. CVE-2026-16070 Niedrig
    Score 16 CVSS 2.7 EPSS 0.17%

    Brizy (WordPress-Plugin): Fehlende Autorisierungsprüfung beim Ändern des Template-Typs

  34. CVE-2026-18739 Niedrig
    Score 15 CVSS 2.5 EPSS 0.10%

    popt: Off-by-One-Schwachstelle in poptStuffArgs

  35. CVE-2026-11835 Mittel
    Score 0 EPSS 0.08%

    Caliptra Core ROM: TOCTOU-Schwachstelle in UpdateResetFlow::run()

  36. CVE-2026-16881 Mittel
    Score 0 EPSS 0.26%

    CVE-2026-16881 – Code-Injection in der LINE-Android-App

  37. CVE-2026-64561 Mittel
    Score 0 EPSS 0.35%

    Linux-Kernel-KVM: Fehlerhafte Reihenfolge bei der Prüfung veralteter Page Faults

  38. CVE-2026-64562 Mittel
    Score 0 EPSS 0.12%

    Linux-Kernel KVM/nVMX: Shadow-VMCS-Zugriff nach VMCLEAR

  39. CVE-2026-64563 Mittel
    Score 0 EPSS 0.12%

    Linux-Kernel: Stale Iterator in rhashtable_walk_start_check bei Table-Restart

  40. CVE-2026-10050 Mittel
    Score 0 EPSS 0.41%

    Eclipse Jetty: ISO-8859-1-Kodierung bei Digest-Authentifizierung

  41. CVE-2026-13229 Mittel
    Score 0 EPSS 0.25%

    Zammad: unautorisiertes Klonen von Ticket-Artikel-Anhängen

  42. CVE-2026-15314 Mittel
    Score 0 EPSS 0.50%

    TP-Link Tapo P110 v1: unsachgemässe Grenzwertprüfung bei authentifizierten HTTP-Requests

  43. CVE-2026-47682 Mittel
    Score 0 EPSS 0.30%

    CVAT 1.6.0–2.64.0: Schwachstelle bei verknüpftem Cloud-Storage für Angreifer mit Schreibzugriff

  44. CVE-2026-47763 Mittel
    Score 0 EPSS 0.15%

    pdm: Fehlender Symlink-Schutz beim Schreiben lokaler Konfigurationsdateien

  45. CVE-2026-47764 Mittel
    Score 0 EPSS 0.15%

    pdm: Path Traversal über InstallDestination.write_to_fs()

  46. CVE-2026-47781 Mittel
    Score 0 EPSS 0.13%

    PDM: automatisches Laden projektlokaler Plugins aus .pdm-plugins bei der Initialisierung

  47. CVE-2026-58067 Mittel
    Score 0

    Veeam Service Provider Console: nicht authentifizierter Denial of Service durch Speichererschöpfung

  48. CVE-2026-58071 Mittel
    Score 0

    Veeam Service Provider Console: Unauthentifizierter Zugriff auf proxied Appliance-API als Portal-Administrator

  49. CVE-2026-58072 Mittel
    Score 0

    Veeam Service Provider Console: Arbiträrer Dateizugriff ermöglicht Remotecodeausführung

  50. CVE-2026-58073 Mittel
    Score 0

    Veeam Service Provider Console: unauthentifizierte Impersonation verwalteter Agenten

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.