Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 851 bis 900 von 36300
- CVE-2026-16536 MittelScore 32 CVSS 5.3 EPSS 0.19%
Simple Google Calendar Outlook Events Widget (WordPress-Plugin): Server-Side Request Forgery
- CVE-2026-16548 MittelScore 32 CVSS 5.4 EPSS 0.36%
WordPress-Plugin Chat Widget: Fehlende Validierung beim Datei-Upload
- CVE-2026-14192 MittelScore 32 CVSS 5.4 EPSS 0.13%
HUMANIST Digital Human Resources: Gespeichertes Cross-Site-Scripting
- CVE-2026-14202 MittelScore 32 CVSS 5.3 EPSS 0.20%
HUMANIST Digital Human Resources: Beobachtbare Antwortdiskrepanz ermöglicht Account-Footprinting
- CVE-2026-14219 MittelScore 32 CVSS 5.4 EPSS 0.12%
HUMANIST Digital Human Resources: Offene Weiterleitung ermöglicht Phishing
- CVE-2026-15337 MittelScore 32 CVSS 5.3 EPSS 0.52%
Django: Denial-of-Service in check_for_language() durch viele Sprachcodes
- CVE-2026-47622 MittelScore 32 CVSS 5.3 EPSS 0.24%
NVIDIA Dynamo (Linux): Offenlegung sensibler Informationen in Fehlermeldungen
- CVE-2026-70481 MittelScore 32 CVSS 5.4 EPSS 0.30%
Open WebUI: Fehlende Autorisierungsprüfung bei Channel-Nachrichten
- CVE-2026-70487 MittelScore 32 CVSS 5.3 EPSS 0.25%
Open WebUI: Ungefilterte client-seitige Knowledge-Attachments in Modell-Metadaten
- CVE-2026-70588 MittelScore 30 CVSS 5 EPSS 0.26%
Ghost: Cross-Site-Scripting über den Universal-Import in Ghost Admin
- CVE-2026-14824 MittelScore 29 CVSS 4.8 EPSS 0.17%
Quiz and Survey Master (QSM) WordPress Plugin: Fehlendes Escaping einer Frageneinstellung
- CVE-2026-15233 MittelScore 29 CVSS 4.8 EPSS 0.14%
Nested Pages WordPress Plugin: Fehlendes Escaping von Post-Titeln
- CVE-2026-70589 MittelScore 29 CVSS 4.8 EPSS 0.17%
Ghost CMS: Fehlende Validierung erlaubt Einlösen inaktiver Abo-Angebote
- CVE-2026-70590 MittelScore 29 CVSS 4.8 EPSS 0.19%
Ghost Admin API: Leck gehashter Passwörter durch Staff-Nutzer
- CVE-2026-16296 MittelScore 28 CVSS 4.7 EPSS 0.19%
WordPress-Plugin Clearfy Cache: Offene Weiterleitung im Redirect-Handler
- CVE-2026-17614 MittelScore 26 CVSS 4.4 EPSS 0.85%
WildFly Domain Mode – Path Traversal in LocalFileRepository
- CVE-2026-12698 MittelScore 26 CVSS 4.3 EPSS 0.18%
wpForo Forum (WordPress-Plugin): Fehlende Beschränkung setzbarer Profilfelder
- CVE-2026-16035 MittelScore 26 CVSS 4.3 EPSS 0.19%
miniOrange 2FA (WordPress-Plugin): Fehlende Bindung des OTP-Empfängers an den registrierenden Nutzer
- CVE-2026-16056 MittelScore 26 CVSS 4.3 EPSS 0.16%
Contest Gallery WordPress-Plugin: Fehlende Rechte-/Nonce-Prüfung erlaubt Lesen sensibler Daten
- CVE-2026-16295 MittelScore 26 CVSS 4.3 EPSS 0.16%
Clearfy Cache WordPress Plugin: Fehlende Berechtigungsprüfung im Admin-Bereich
- CVE-2026-16546 MittelScore 26 CVSS 4.3 EPSS 0.15%
Wired Impact Volunteer Management WordPress-Plugin: Fehlende Autorisierungsprüfung bei RSVP-Entfernung
- CVE-2026-47487 MittelScore 26 CVSS 4.4 EPSS 0.16%
NVIDIA Triton Inference Server (Linux): Pfadmanipulation über den Modellnamen
- CVE-2026-70484 MittelScore 26 CVSS 4.3 EPSS 0.27%
Open WebUI: Client-gesteuertes Flag in Legacy-Chat-Completions umgeht Vertrauensprüfung
- CVE-2026-70488 MittelScore 26 CVSS 4.3 EPSS 0.21%
Open WebUI: Fehlende Autorisierungsprüfung im Sync-Cleanup-Endpunkt
- CVE-2026-18819 MittelScore 26 CVSS 4.3 EPSS 0.16%
RackTables: Cross-Site-Request-Forgery (CSRF) in unbekanntem Code (bis Version 0.22.0)
- CVE-2026-70480 MittelScore 25 CVSS 4.1 EPSS 0.19%
Open WebUI: Cross-Site-Scripting über Vega- und Vega-Lite-Codeblöcke im Chat
- CVE-2026-70591 MittelScore 25 CVSS 4.1 EPSS 0.23%
Ghost CMS: Server-Side Request Forgery beim Abruf von Admin-Bildern
- CVE-2026-16791 NiedrigScore 23 CVSS 3.9 EPSS 0.09%
Lenovo XClarity Essentials OneCLI (Linux): Temporäre Dateien ermöglichen Überschreiben lokaler Dateien
- CVE-2026-18569 NiedrigScore 22 CVSS 3.7 EPSS 0.16%
Red Hat Build of Keycloak – Schwachstelle im Backchannel-Logout-Endpunkt
- CVE-2026-11366 NiedrigScore 22 CVSS 3.7 EPSS 0.19%
WordPress-Plugin MonsterInsights: Unzureichende Signaturprüfung bei unauthentifizierter AJAX-Aktion
- CVE-2026-16068 NiedrigScore 21 CVSS 3.5 EPSS 0.14%
Brizy WordPress Plugin: Unzureichende Zugriffskontrolle bei globalen Design-Daten
- CVE-2026-70483 NiedrigScore 19 CVSS 3.1 EPSS 0.24%
Open WebUI: Race Condition beim Löschen von Chats (DELETE /api/v1/chats/{id})
- CVE-2026-16070 NiedrigScore 16 CVSS 2.7 EPSS 0.17%
Brizy (WordPress-Plugin): Fehlende Autorisierungsprüfung beim Ändern des Template-Typs
- CVE-2026-18739 NiedrigScore 15 CVSS 2.5 EPSS 0.10%
popt: Off-by-One-Schwachstelle in poptStuffArgs
- CVE-2026-11835 MittelScore 0 EPSS 0.08%
Caliptra Core ROM: TOCTOU-Schwachstelle in UpdateResetFlow::run()
- CVE-2026-16881 MittelScore 0 EPSS 0.26%
CVE-2026-16881 – Code-Injection in der LINE-Android-App
- CVE-2026-64561 MittelScore 0 EPSS 0.35%
Linux-Kernel-KVM: Fehlerhafte Reihenfolge bei der Prüfung veralteter Page Faults
- CVE-2026-64562 MittelScore 0 EPSS 0.12%
Linux-Kernel KVM/nVMX: Shadow-VMCS-Zugriff nach VMCLEAR
- CVE-2026-64563 MittelScore 0 EPSS 0.12%
Linux-Kernel: Stale Iterator in rhashtable_walk_start_check bei Table-Restart
- CVE-2026-10050 MittelScore 0 EPSS 0.41%
Eclipse Jetty: ISO-8859-1-Kodierung bei Digest-Authentifizierung
- CVE-2026-13229 MittelScore 0 EPSS 0.25%
Zammad: unautorisiertes Klonen von Ticket-Artikel-Anhängen
- CVE-2026-15314 MittelScore 0 EPSS 0.50%
TP-Link Tapo P110 v1: unsachgemässe Grenzwertprüfung bei authentifizierten HTTP-Requests
- CVE-2026-47682 MittelScore 0 EPSS 0.30%
CVAT 1.6.0–2.64.0: Schwachstelle bei verknüpftem Cloud-Storage für Angreifer mit Schreibzugriff
- CVE-2026-47763 MittelScore 0 EPSS 0.15%
pdm: Fehlender Symlink-Schutz beim Schreiben lokaler Konfigurationsdateien
- CVE-2026-47764 MittelScore 0 EPSS 0.15%
pdm: Path Traversal über InstallDestination.write_to_fs()
- CVE-2026-47781 MittelScore 0 EPSS 0.13%
PDM: automatisches Laden projektlokaler Plugins aus .pdm-plugins bei der Initialisierung
- CVE-2026-58067 MittelScore 0
Veeam Service Provider Console: nicht authentifizierter Denial of Service durch Speichererschöpfung
- CVE-2026-58071 MittelScore 0
Veeam Service Provider Console: Unauthentifizierter Zugriff auf proxied Appliance-API als Portal-Administrator
- CVE-2026-58072 MittelScore 0
Veeam Service Provider Console: Arbiträrer Dateizugriff ermöglicht Remotecodeausführung
- CVE-2026-58073 MittelScore 0
Veeam Service Provider Console: unauthentifizierte Impersonation verwalteter Agenten
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.