Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 901 bis 950 von 36300
- CVE-2026-58074 MittelScore 0
Caddy: Hochprivilegierter Nutzer kann beliebigen Code auf dem Server ausführen
- CVE-2026-64633 MittelScore 0
Remote Code Execution auf dem Agent-Host ohne Authentifizierung
- CVE-2026-66883 MittelScore 0
Erlang oidcc_plug: unsachgemässe Behandlung der Gross-/Kleinschreibung hebelt Session-Bindung im Authorize-Modul aus
- CVE-2026-66884 MittelScore 0
Erlang Ecosystem Foundation oidcc_plug: CSRF im Modul Oidcc.Plug.AuthorizationCallback
- CVE-2026-69250 MittelScore 0
Flowise: Unauthentifizierter OAuth2-Token-Refresh-Endpunkt
- CVE-2026-69251 MittelScore 0
Flowise: Record-Manager- und Agent-Memory-Nodes erlauben beliebige TypeORM-DataSource-Konfiguration
- CVE-2026-69252 MittelScore 0
Flowise: Route /api/v1/files nur durch Feature-Gate feat:files geschützt
- CVE-2026-69253 MittelScore 0 EPSS 0.31%
Flowise: Schwachstelle in den Custom-Tool-Komponenten AgentAsTool, ChatflowTool und ExecuteFlow (vor 3.1.3)
- CVE-2026-69254 MittelScore 0
Flowise: executeJavaScriptCode() übernimmt unsichere nodeVMOptions
- CVE-2026-69255 MittelScore 0
Flowise: CSVAgent extrahiert angreiferkontrollierte Daten
- CVE-2026-69256 MittelScore 0 EPSS 0.39%
Flowise: CSVAgent-Node ermöglicht Ausführung von Python-Code über pyodide
- CVE-2026-69257 MittelScore 0
Flowise: Fehlende Normalisierung von IPv4-mapped-IPv6-Adressen im HTTP-Security-Modul (vor 3.1.3)
- CVE-2026-69258 MittelScore 0 EPSS 0.38%
Flowise: Unauthentifizierter Endpunkt /api/v1/prediction akzeptiert overrideConfig
- CVE-2026-69259 MittelScore 0
Flowise: Schwachstelle im SQLite Record Manager Node
- CVE-2026-69262 MittelScore 0 EPSS 0.25%
Flowise: unzureichende Berechtigungsprüfung bei DELETE /api/v1/chatflows/:id
- CVE-2026-69263 MittelScore 0
Flowise: Unvollständige Absicherung gegen npx-Flags (Umgehung des Fixes für CVE-2025-8943, vor 3.1.3)
- CVE-2026-69264 MittelScore 0
Flowise: Code-Injection im CSVAgent über Pyodide-Template
- CVE-2026-70470 MittelScore 0
Flowise: unsichere Python-Codevalidierung in validatePythonCodeForDataFrame
- CVE-2026-70471 MittelScore 0
Flowise: $vars werden ohne Berechtigungsprüfung in die Code-Execution-Sandbox injiziert
- CVE-2026-70472 MittelScore 0 EPSS 0.25%
Flowise: Client-kontrollierter Credential-Parameter bei OpenAI-Assistants-Vector-Store-Endpunkten (vor 3.1.3)
- CVE-2026-70473 MittelScore 0
Flowise: Endpunkt /api/v1/upsert-history gibt serverweiten Verlauf preis
- CVE-2026-70474 MittelScore 0 EPSS 0.29%
Flowise: OAuth2-Credential-Endpunkte erlauben ID-basierten Zugriff ohne Eigentümerprüfung
- CVE-2026-70475 MittelScore 0
Flowise: Fehlende Zugriffsprüfung am Endpoint PUT /api/v1/executions/:id
- CVE-2026-70476 MittelScore 0 EPSS 0.29%
Flowise: Fehlende Zugriffskontrolle bei Organisation-Billing-Endpunkten (vor 3.1.3)
- CVE-2026-70477 MittelScore 0 EPSS 0.44%
Flowise: Prompt Injection über CSV-Agent-Node
- CVE-2026-70478 MittelScore 0 EPSS 0.38%
Flowise: OAuth2-Credential-Refresh-Endpunkt in WHITELIST_URLS umgeht Authentifizierung
- CVE-2026-33591 KritischScore 60 CVSS 10
SimpleHelp Wapt Server: Umgehung der Sicherheitsbeschränkung
- CVE-2026-69083 KritischScore 60 CVSS 10 EPSS 0.35%
SiYuan – SQL-Injection im fullTextSearchAssetContent-Endpunkt
- CVE-2026-69084 KritischScore 60 CVSS 10 EPSS 1.10%
SiYuan: SQL-Injection über den Endpunkt searchEmbedBlock
- CVE-2026-69085 KritischScore 60 CVSS 10 EPSS 0.25%
SiYuan vor v3.7.3 – SQL-Injection im searchDocs-Endpunkt
- CVE-2026-48323 KritischScore 60 CVSS 10 EPSS 0.64%
CVE-2026-48323 – Caddy (Light Code Labs)
- CVE-2026-48330 KritischScore 60 CVSS 10 EPSS 0.69%
Caddy (Light Code Labs) – CVE-2026-48330
- CVE-2026-48331 KritischScore 60 CVSS 10 EPSS 0.48%
Adobe Campaign Classic – Server-Side Request Forgery (SSRF) mit Privilege Escalation
- CVE-2026-12872 KritischScore 59 CVSS 9.8 EPSS 0.75%
Webinfos WordPress-Plugin: Uneingeschränkter Datei-Upload ohne Authentifizierung (bis Version 1.2)
- CVE-2026-16060 KritischScore 59 CVSS 9.8 EPSS 0.46%
Insert or Embed Articulate Content WordPress-Plugin: umgehbare Validierung hochgeladener Archive (bis Version 4.3000000027)
- CVE-2026-16250 KritischScore 59 CVSS 9.8 EPSS 0.51%
Personal QR Message WordPress-Plugin: Unauthentifizierter Datei-Upload (bis Version 1.0)
- CVE-2026-16300 KritischScore 59 CVSS 9.8 EPSS 0.30%
WordPress-Plugin ChamaWP vor 1.0.13: unzureichende Validierung bei Passwort-Zurücksetzung
- CVE-2026-18588 KritischScore 59 CVSS 9.8 EPSS 0.61%
Wavlink WL-NU516U1: Stack-based Buffer Overflow in nas.cgi
- CVE-2026-18589 KritischScore 59 CVSS 9.8 EPSS 0.61%
Wavlink WL-NU516U1: Stack-based Buffer Overflow in change_password (nas.cgi)
- CVE-2026-2346 KritischScore 59 CVSS 9.8 EPSS 0.29%
Menulux Mobile App – Autorisierungsumgehung durch nutzergesteuerten Schlüssel
- CVE-2026-18108 KritischScore 59 CVSS 9.8 EPSS 0.22%
Net::SAML2 (Perl) – Authentifizierungsumgehung durch fehlende Signaturprüfung
- CVE-2026-18601 KritischScore 59 CVSS 9.8 EPSS 2.38%
GL.iNet GL-MT3000 – Schwachstelle in ovpn-client.check_config
- CVE-2026-64827 KritischScore 59 CVSS 9.8 EPSS 0.43%
Telenia Software TVox – Authentifizierungsumgehung in set_env.php
- CVE-2026-18602 KritischScore 59 CVSS 9.8 EPSS 1.99%
GL.iNet GL-MT3000 – Schwachstelle in ovpn-client.get_recommend_config
- CVE-2026-41452 KritischScore 59 CVSS 9.8
Krayin CRM 2.2.4: Fehlende Authentifizierung in der Installer-Middleware ermöglicht Übernahme des Administrator-Kontos
- CVE-2026-18612 KritischScore 59 CVSS 9.8 EPSS 2.16%
GL-iNet GL-MT3000 bis 4.4.5 – Schwachstelle in plugins.remove_package/plugins.install_package (plugins.so)
- CVE-2026-18613 KritischScore 59 CVSS 9.8 EPSS 0.55%
GL-iNet GL-MT3000 – Schwachstelle in plugins.set_config
- CVE-2026-18614 KritischScore 59 CVSS 9.8 EPSS 2.01%
GL-iNet GL-MT3000 – Schwachstelle in der Funktion s2s.enable_echo_server (bis 4.4.5)
- CVE-2026-18615 KritischScore 59 CVSS 9.8 EPSS 1.99%
GL-iNet GL-MT3000: Schwachstelle in wg-server.generate_publickey (wg-server.so)
- CVE-2026-18616 KritischScore 59 CVSS 9.8 EPSS 1.99%
GL-iNet GL-MT3000 bis 4.4.5 – Schwachstelle in server.set_peer (wg-server.so)
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.