Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 901 bis 950 von 36300

  1. CVE-2026-58074 Mittel
    Score 0

    Caddy: Hochprivilegierter Nutzer kann beliebigen Code auf dem Server ausführen

  2. CVE-2026-64633 Mittel
    Score 0

    Remote Code Execution auf dem Agent-Host ohne Authentifizierung

  3. CVE-2026-66883 Mittel
    Score 0

    Erlang oidcc_plug: unsachgemässe Behandlung der Gross-/Kleinschreibung hebelt Session-Bindung im Authorize-Modul aus

  4. CVE-2026-66884 Mittel
    Score 0

    Erlang Ecosystem Foundation oidcc_plug: CSRF im Modul Oidcc.Plug.AuthorizationCallback

  5. CVE-2026-69250 Mittel
    Score 0

    Flowise: Unauthentifizierter OAuth2-Token-Refresh-Endpunkt

  6. CVE-2026-69251 Mittel
    Score 0

    Flowise: Record-Manager- und Agent-Memory-Nodes erlauben beliebige TypeORM-DataSource-Konfiguration

  7. CVE-2026-69252 Mittel
    Score 0

    Flowise: Route /api/v1/files nur durch Feature-Gate feat:files geschützt

  8. CVE-2026-69253 Mittel
    Score 0 EPSS 0.31%

    Flowise: Schwachstelle in den Custom-Tool-Komponenten AgentAsTool, ChatflowTool und ExecuteFlow (vor 3.1.3)

  9. CVE-2026-69254 Mittel
    Score 0

    Flowise: executeJavaScriptCode() übernimmt unsichere nodeVMOptions

  10. CVE-2026-69255 Mittel
    Score 0

    Flowise: CSVAgent extrahiert angreiferkontrollierte Daten

  11. CVE-2026-69256 Mittel
    Score 0 EPSS 0.39%

    Flowise: CSVAgent-Node ermöglicht Ausführung von Python-Code über pyodide

  12. CVE-2026-69257 Mittel
    Score 0

    Flowise: Fehlende Normalisierung von IPv4-mapped-IPv6-Adressen im HTTP-Security-Modul (vor 3.1.3)

  13. CVE-2026-69258 Mittel
    Score 0 EPSS 0.38%

    Flowise: Unauthentifizierter Endpunkt /api/v1/prediction akzeptiert overrideConfig

  14. CVE-2026-69259 Mittel
    Score 0

    Flowise: Schwachstelle im SQLite Record Manager Node

  15. CVE-2026-69262 Mittel
    Score 0 EPSS 0.25%

    Flowise: unzureichende Berechtigungsprüfung bei DELETE /api/v1/chatflows/:id

  16. CVE-2026-69263 Mittel
    Score 0

    Flowise: Unvollständige Absicherung gegen npx-Flags (Umgehung des Fixes für CVE-2025-8943, vor 3.1.3)

  17. CVE-2026-69264 Mittel
    Score 0

    Flowise: Code-Injection im CSVAgent über Pyodide-Template

  18. CVE-2026-70470 Mittel
    Score 0

    Flowise: unsichere Python-Codevalidierung in validatePythonCodeForDataFrame

  19. CVE-2026-70471 Mittel
    Score 0

    Flowise: $vars werden ohne Berechtigungsprüfung in die Code-Execution-Sandbox injiziert

  20. CVE-2026-70472 Mittel
    Score 0 EPSS 0.25%

    Flowise: Client-kontrollierter Credential-Parameter bei OpenAI-Assistants-Vector-Store-Endpunkten (vor 3.1.3)

  21. CVE-2026-70473 Mittel
    Score 0

    Flowise: Endpunkt /api/v1/upsert-history gibt serverweiten Verlauf preis

  22. CVE-2026-70474 Mittel
    Score 0 EPSS 0.29%

    Flowise: OAuth2-Credential-Endpunkte erlauben ID-basierten Zugriff ohne Eigentümerprüfung

  23. CVE-2026-70475 Mittel
    Score 0

    Flowise: Fehlende Zugriffsprüfung am Endpoint PUT /api/v1/executions/:id

  24. CVE-2026-70476 Mittel
    Score 0 EPSS 0.29%

    Flowise: Fehlende Zugriffskontrolle bei Organisation-Billing-Endpunkten (vor 3.1.3)

  25. CVE-2026-70477 Mittel
    Score 0 EPSS 0.44%

    Flowise: Prompt Injection über CSV-Agent-Node

  26. CVE-2026-70478 Mittel
    Score 0 EPSS 0.38%

    Flowise: OAuth2-Credential-Refresh-Endpunkt in WHITELIST_URLS umgeht Authentifizierung

  27. CVE-2026-33591 Kritisch
    Score 60 CVSS 10

    SimpleHelp Wapt Server: Umgehung der Sicherheitsbeschränkung

  28. CVE-2026-69083 Kritisch
    Score 60 CVSS 10 EPSS 0.35%

    SiYuan – SQL-Injection im fullTextSearchAssetContent-Endpunkt

  29. CVE-2026-69084 Kritisch
    Score 60 CVSS 10 EPSS 1.10%

    SiYuan: SQL-Injection über den Endpunkt searchEmbedBlock

  30. CVE-2026-69085 Kritisch
    Score 60 CVSS 10 EPSS 0.25%

    SiYuan vor v3.7.3 – SQL-Injection im searchDocs-Endpunkt

  31. CVE-2026-48323 Kritisch
    Score 60 CVSS 10 EPSS 0.64%

    CVE-2026-48323 – Caddy (Light Code Labs)

  32. CVE-2026-48330 Kritisch
    Score 60 CVSS 10 EPSS 0.69%

    Caddy (Light Code Labs) – CVE-2026-48330

  33. CVE-2026-48331 Kritisch
    Score 60 CVSS 10 EPSS 0.48%

    Adobe Campaign Classic – Server-Side Request Forgery (SSRF) mit Privilege Escalation

  34. CVE-2026-12872 Kritisch
    Score 59 CVSS 9.8 EPSS 0.75%

    Webinfos WordPress-Plugin: Uneingeschränkter Datei-Upload ohne Authentifizierung (bis Version 1.2)

  35. CVE-2026-16060 Kritisch
    Score 59 CVSS 9.8 EPSS 0.46%

    Insert or Embed Articulate Content WordPress-Plugin: umgehbare Validierung hochgeladener Archive (bis Version 4.3000000027)

  36. CVE-2026-16250 Kritisch
    Score 59 CVSS 9.8 EPSS 0.51%

    Personal QR Message WordPress-Plugin: Unauthentifizierter Datei-Upload (bis Version 1.0)

  37. CVE-2026-16300 Kritisch
    Score 59 CVSS 9.8 EPSS 0.30%

    WordPress-Plugin ChamaWP vor 1.0.13: unzureichende Validierung bei Passwort-Zurücksetzung

  38. CVE-2026-18588 Kritisch
    Score 59 CVSS 9.8 EPSS 0.61%

    Wavlink WL-NU516U1: Stack-based Buffer Overflow in nas.cgi

  39. CVE-2026-18589 Kritisch
    Score 59 CVSS 9.8 EPSS 0.61%

    Wavlink WL-NU516U1: Stack-based Buffer Overflow in change_password (nas.cgi)

  40. CVE-2026-2346 Kritisch
    Score 59 CVSS 9.8 EPSS 0.29%

    Menulux Mobile App – Autorisierungsumgehung durch nutzergesteuerten Schlüssel

  41. CVE-2026-18108 Kritisch
    Score 59 CVSS 9.8 EPSS 0.22%

    Net::SAML2 (Perl) – Authentifizierungsumgehung durch fehlende Signaturprüfung

  42. CVE-2026-18601 Kritisch
    Score 59 CVSS 9.8 EPSS 2.38%

    GL.iNet GL-MT3000 – Schwachstelle in ovpn-client.check_config

  43. CVE-2026-64827 Kritisch
    Score 59 CVSS 9.8 EPSS 0.43%

    Telenia Software TVox – Authentifizierungsumgehung in set_env.php

  44. CVE-2026-18602 Kritisch
    Score 59 CVSS 9.8 EPSS 1.99%

    GL.iNet GL-MT3000 – Schwachstelle in ovpn-client.get_recommend_config

  45. CVE-2026-41452 Kritisch
    Score 59 CVSS 9.8

    Krayin CRM 2.2.4: Fehlende Authentifizierung in der Installer-Middleware ermöglicht Übernahme des Administrator-Kontos

  46. CVE-2026-18612 Kritisch
    Score 59 CVSS 9.8 EPSS 2.16%

    GL-iNet GL-MT3000 bis 4.4.5 – Schwachstelle in plugins.remove_package/plugins.install_package (plugins.so)

  47. CVE-2026-18613 Kritisch
    Score 59 CVSS 9.8 EPSS 0.55%

    GL-iNet GL-MT3000 – Schwachstelle in plugins.set_config

  48. CVE-2026-18614 Kritisch
    Score 59 CVSS 9.8 EPSS 2.01%

    GL-iNet GL-MT3000 – Schwachstelle in der Funktion s2s.enable_echo_server (bis 4.4.5)

  49. CVE-2026-18615 Kritisch
    Score 59 CVSS 9.8 EPSS 1.99%

    GL-iNet GL-MT3000: Schwachstelle in wg-server.generate_publickey (wg-server.so)

  50. CVE-2026-18616 Kritisch
    Score 59 CVSS 9.8 EPSS 1.99%

    GL-iNet GL-MT3000 bis 4.4.5 – Schwachstelle in server.set_peer (wg-server.so)

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.