Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 51 bis 100 von 36300
- CVE-2026-77546 KritischScore 59 CVSS 9.9 EPSS 0.80%
Ubiquiti UniFi Access – Command Injection durch fehlerhafte Eingabevalidierung
- CVE-2026-77547 KritischScore 59 CVSS 9.9 EPSS 0.80%
Ubiquiti UniFi Access Command Injection Vulnerability
- CVE-2026-77548 KritischScore 59 CVSS 9.9 EPSS 0.80%
Ubiquiti UniFi Protect: Command Injection durch fehlerhafte Eingabevalidierung
- CVE-2026-77552 KritischScore 59 CVSS 9.8 EPSS 0.89%
Ubiquiti UniFi Enterprise Audio/Video Bridge Command Injection Vulnerability
- CVE-2026-77553 KritischScore 59 CVSS 9.9 EPSS 0.23%
Ubiquiti UniFi Access: Rechteausweitung durch unzureichende Zugriffskontrolle
- CVE-2026-77557 KritischScore 59 CVSS 9.8 EPSS 0.33%
Ubiquiti UniFi Protect AI Key: Rechteausweitung durch unzureichende Zugriffskontrolle
- CVE-2026-80203 KritischScore 59 CVSS 9.8 EPSS 0.39%
Grav-Plugin „grav-plugin-api“: Fehlende API-Key-Scope-Prüfung in mehreren Endpunkten
- CVE-2026-80235 KritischScore 59 CVSS 9.8 EPSS 0.68%
EFence (Thinking Software Technology): Unautorisierter Datei-Upload ermöglicht Webshell
- CVE-2026-80349 KritischScore 59 CVSS 9.8
TarsWeb – Umgehung der Vertrauensprüfung durch client-kontrollierten Proxy-Header
- CVE-2026-80428 KritischScore 59 CVSS 9.8 EPSS 0.52%
ILIAS: Unauthentifizierte Deserialisierung über Shibboleth-Backchannel
- CVE-2026-81032 KritischScore 59 CVSS 9.8
NebulaGraph: Unauthentifizierter Zugriff auf die Runtime-Konfiguration über HTTP
- CVE-2026-54523 KritischScore 58 CVSS 9.6
Kyverno: Generator-Library in NamespacedMutatingPolicy CEL-Compiler exponiert
- CVE-2026-77532 KritischScore 58 CVSS 9.6 EPSS 0.27%
Ubiquiti EdgeSwitch: Pufferüberlauf in der DHCPv6-Verarbeitung ermöglicht Remote Code Execution
- CVE-2026-77539 KritischScore 55 CVSS 9.1 EPSS 0.81%
Ubiquiti UniFi OS Server: Command Injection durch fehlerhafte Eingabevalidierung
- CVE-2026-77540 KritischScore 55 CVSS 9.1 EPSS 0.81%
Ubiquiti UniFi OS Server: Command Injection durch unzureichende Eingabevalidierung
- CVE-2026-77541 KritischScore 55 CVSS 9.1 EPSS 0.26%
Ubiquiti UniFi Network – Rechteausweitung durch fehlerhafte Zugriffskontrolle
- CVE-2026-77542 KritischScore 55 CVSS 9.1 EPSS 0.81%
UID Enterprise Agent Command Injection Vulnerability
- CVE-2026-60004 Kritisch Aktiv ausgenutztScore 100 CVSS 9.8 EPSS 82.40%
Gitea Code Injection Vulnerability
- CVE-2026-76193 KritischScore 60 CVSS 10 EPSS 0.62%
Adobe Campaign Classic (ACC) Server-Side Request Forgery
- CVE-2026-76195 KritischScore 60 CVSS 10 EPSS 1.47%
Adobe Campaign Classic – OS-Command-Injection-Schwachstelle
- CVE-2026-76197 KritischScore 60 CVSS 10 EPSS 1.47%
Adobe Campaign Classic – OS-Command-Injection
- CVE-2026-79911 KritischScore 60 CVSS 10 EPSS 0.64%
TOTOLINK N600R – Schwachstelle in der Funktion setSystemConfig (CGI Handler)
- CVE-2026-55546 KritischScore 59 CVSS 9.8
QWED-MCP Math-Engine Injection über verify_math_expression()
- CVE-2026-63586 KritischScore 59 CVSS 9.8 EPSS 0.52%
Web-Management-Oberfläche – Unsichere Verarbeitung des HTTP-Basic-Auth-Benutzernamens
- CVE-2026-65083 KritischScore 59 CVSS 9.9 EPSS 0.51%
NVIDIA OpenShell for Linux – Unzureichende Eingabevalidierung in der Sandbox-Provisioning-API
- CVE-2026-65093 KritischScore 59 CVSS 9.9 EPSS 0.49%
NVIDIA OpenShell for Linux – Sandbox Escape
- CVE-2026-78477 KritischScore 59 CVSS 9.8 EPSS 0.30%
WordPress-Theme „Jawn“ – Privilege Escalation (bis Version 1.4.2)
- CVE-2026-78568 KritischScore 59 CVSS 9.8 EPSS 0.30%
WordPress-Plugin „Total Donations“ – SQL-Injection (bis Version 2.0.5)
- CVE-2026-78570 KritischScore 59 CVSS 9.8 EPSS 0.40%
Total Donations Plugin für WordPress – Privilege Escalation
- CVE-2026-79657 KritischScore 59 CVSS 9.8 EPSS 1.17%
NLTK – Remote Code Execution über Pickle-Loader
- CVE-2026-79675 KritischScore 59 CVSS 9.8 EPSS 0.40%
NLTK – Injection von JVM-Optionen über die java()-Funktion
- CVE-2026-79787 KritischScore 59 CVSS 9.8
Alluxio S3 REST Proxy – Fehlende Prüfung der AWS-Signatur (SigV4) ermöglicht Identitätsspoofing
- CVE-2026-80104 KritischScore 59 CVSS 9.8 EPSS 0.71%
DB-GPT Path Traversal beim Skill-Upload
- CVE-2026-80138 KritischScore 59 CVSS 9.8 EPSS 0.80%
ClipBucket V5 – Command Injection über php_cli_filepath
- CVE-2026-78167 KritischScore 60 CVSS 10 EPSS 1.03%
EFM ipTIME T16000M – Schwachstelle in der Funktion httpcon_check_session_url
- CVE-2026-78168 KritischScore 59 CVSS 9.8 EPSS 0.93%
EFM ipTIME T24000M – Schwachstelle im Session Validation Handler
- CVE-2026-78169 KritischScore 59 CVSS 9.9 EPSS 0.44%
UTT HiPER 1250GW – Pufferüberlauf im HTTP Request Handler (strcpy)
- CVE-2026-78211 KritischScore 59 CVSS 9.8 EPSS 1.54%
4MOSAn GCB Doctor – OS Command Injection über ADOdb-Testseite
- CVE-2026-78207 KritischScore 56 CVSS 9.4 EPSS 0.44%
exceljs-hardened – Prototype Pollution im deepMerge-Helper
- CVE-2026-19200 HochScore 53 CVSS 8.9 EPSS 0.23%
Velociraptor verify() VQL-Funktion – fehlerhafte Nutzung des globalen Artifact-Repositorys
- CVE-2026-78213 HochScore 52 CVSS 8.7 EPSS 0.31%
Heptabase – Stored-Cross-Site-Scripting-Schwachstelle
- CVE-2026-78212 HochScore 45 CVSS 7.5 EPSS 0.50%
4MOSAn – Arbitrary File Read über Path Traversal
- CVE-2026-78154 HochScore 44 CVSS 7.3 EPSS 0.40%
the-momentum open-wearables bis 0.6.2 – Schwachstelle in redeem_invitation_code
- CVE-2026-78156 HochScore 44 CVSS 7.4 EPSS 0.33%
Open5GS 2.8.0 – Schwachstelle in der S6a-Authentication-Information-Komponente
- CVE-2026-78171 HochScore 44 CVSS 7.3 EPSS 0.33%
itsourcecode Sales and Inventory System – Schwachstelle in processlogin.php
- CVE-2026-78182 HochScore 44 CVSS 7.3 EPSS 0.31%
XBROTHER Dynamic Environment Monitoring System – Schwachstelle in PlanController.getImm
- CVE-2026-78197 HochScore 44 CVSS 7.3 EPSS 0.27%
SourceCodester Simple Online Food Ordering System 1.0 – Schwachstelle in ajax.php
- CVE-2026-78203 HochScore 43 CVSS 7.1 EPSS 0.27%
Ghostwriter – fehlende Prüfung der Template-Zugehörigkeit beim Report-Template-Swap
- CVE-2026-78158 MittelScore 38 CVSS 6.3 EPSS 0.21%
Open5GS 2.8.0 – Unsachgemässe Autorisierung im AMF UEContextReleaseRequest Path Handler
- CVE-2026-78160 MittelScore 38 CVSS 6.3 EPSS 0.29%
Dolibarr ERP – Schwachstelle im User Notes Handler (note.php)
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.