Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 951 bis 1000 von 36300

  1. CVE-2026-38447 Kritisch
    Score 59 CVSS 9.8

    osTicket 1.18.3: Vorhersagbare API-Schlüssel durch MD5-Hashing

  2. CVE-2026-69240 Kritisch
    Score 59 CVSS 9.8 EPSS 0.32%

    Sequelize (Node.js ORM): SQL-Injection bei Oracle-Dialekt durch fehlerhaftes String-Escaping

  3. CVE-2026-18684 Kritisch
    Score 59 CVSS 9.8 EPSS 2.03%

    GL.iNet GL-MT3000: Command Injection in remove_profile (modem.so)

  4. CVE-2026-48326 Kritisch
    Score 59 CVSS 9.9 EPSS 0.50%

    CVE-2026-48326 – SQL-Injection in Adobe Campaign Classic (ACC)

  5. CVE-2026-48333 Kritisch
    Score 59 CVSS 9.8 EPSS 0.48%

    Adobe Campaign Classic – Incorrect Authorization mit Privilege Escalation

  6. CVE-2026-68979 Kritisch
    Score 59 CVSS 9.8 EPSS 0.35%

    CVE-2026-68979 – Apache NiFi: fehlende Autorisierungsprüfung bei Parameter-Context-Updates

  7. CVE-2026-18667 Kritisch
    Score 58 CVSS 9.6 EPSS 0.39%

    CVE-2026-18667 – Tenable Sensor Proxy Remote Code Execution

  8. CVE-2026-48317 Kritisch
    Score 58 CVSS 9.6 EPSS 0.49%

    CVE-2026-48317 – Caddy (Light Code Labs)

  9. CVE-2026-15930 Kritisch
    Score 56 CVSS 9.4 EPSS 0.25%

    Simple Membership WordPress-Plugin: Fehlende Prüfung bei der Registrierung (vor Version 4.7.8)

  10. CVE-2026-12965 Kritisch
    Score 55 CVSS 9.1 EPSS 0.35%

    WordPress-Plugin Super Store Finder bis 7.8: SQL-Injection in AJAX-Aktion

  11. CVE-2026-14557 Kritisch
    Score 55 CVSS 9.1 EPSS 0.39%

    SoftMarket – Digital Marketplace WordPress-Plugin: fehlerhafte Token-Validierung bei E-Mail-Verifizierung (bis Version 1.0.0)

  12. CVE-2026-16532 Kritisch
    Score 55 CVSS 9.1 EPSS 0.26%

    Link Library WordPress-Plugin: SQL-Injection ohne Authentifizierung

  13. CVE-2026-16534 Kritisch
    Score 55 CVSS 9.1 EPSS 0.23%

    Import and export users and customers WordPress-Plugin: fehlende Rechteprüfung beim CSV-Import (vor Version 2.4.2)

  14. CVE-2026-18248 Kritisch
    Score 55 CVSS 9.1 EPSS 0.22%

    @fastify/aws-lambda: Autorisierungsrelevante Event-/Context-Dekorierung (Version 6.4.0)

  15. CVE-2026-39932 Kritisch
    Score 55 CVSS 9.1

    OpenEMR – Remote Code Execution über Dokumentenkategorie-Baum (Tree.class.php)

  16. CVE-2026-48031 Kritisch
    Score 55 CVSS 9.1

    go-base – Hartkodiertes JWT-Signing-Secret ermöglicht Authentifizierungsumgehung

  17. CVE-2026-9390 Kritisch
    Score 55 CVSS 9.1 EPSS 0.28%

    XML::Sig vor 0.71 (Perl): XPath-Injection beim ID-Lookup

  18. CVE-2026-9487 Kritisch
    Score 55 CVSS 9.1 EPSS 0.17%

    XML::Sig (Perl) vor 0.71 – Signature Wrapping durch doppelte ID

  19. CVE-2026-68980 Kritisch
    Score 55 CVSS 9.1 EPSS 0.26%

    Apache NiFi: Autorisierung beim Löschen von Assets in Parameter Contexts

  20. CVE-2026-18598 Hoch
    Score 53 CVSS 8.8 EPSS 1.65%

    GL.iNet GL-MT3000: Schwachstelle in logread.get_system_log (Logread Lua RPC)

  21. CVE-2026-69096 Hoch
    Score 53 CVSS 8.8 EPSS 1.67%

    OpenWrt luci-app-dockerman: OS-Command-Injection im ucode-RPC-Backend

  22. CVE-2026-18733 Hoch
    Score 53 CVSS 8.8 EPSS 0.32%

    Amazon Strands Agents Tools: Prompt-Injection im Shell-Tool ermöglicht Codeausführung

  23. CVE-2026-16572 Hoch
    Score 52 CVSS 8.6 EPSS 0.28%

    LogMyTrip WordPress-Plugin: SQL-Injection über Cookie-Wert (bis Version 1.9)

  24. CVE-2026-69079 Hoch
    Score 52 CVSS 8.7 EPSS 0.40%

    CTI-Transmute: Unkontrollierter Ressourcenverbrauch im /activity_timeline-Endpoint

  25. CVE-2026-20465 Hoch
    Score 49 CVSS 8.1 EPSS 0.20%

    WLAN-AP-Treiber: Out-of-Bounds Write ermöglicht Rechteausweitung über angrenzendes Netzwerk

  26. CVE-2025-15672 Hoch
    Score 49 CVSS 8.1 EPSS 0.47%

    ChamaWP WordPress-Plugin: PHP Object Injection durch unsichere Deserialisierung

  27. CVE-2026-16539 Hoch
    Score 49 CVSS 8.1 EPSS 0.21%

    sm page duplicator WordPress-Plugin: SQL-Injection beim Duplizieren von Seiten (bis Version 1.0.0)

  28. CVE-2026-18092 Hoch
    Score 49 CVSS 8.1 EPSS 0.20%

    Net::SAML2 (Perl) – SAML-Authentifizierungsumgehung durch XML Signature Wrapping

  29. CVE-2026-69088 Hoch
    Score 49 CVSS 8.1

    Grav CMS – unsichere Validierung von Blueprint Dynamic-Field-Aufrufen

  30. CVE-2026-67610 Hoch
    Score 49 CVSS 8.1

    OpenEMR bis 8.2.0: unsachgemässe Authentifizierung am OAuth2-Dynamic-Client-Registration-Endpunkt

  31. CVE-2026-18599 Hoch
    Score 48 CVSS 8 EPSS 1.40%

    GL.iNet GL-MT3000: Schwachstelle in logread.set_config (Logread Lua RPC Plugin)

  32. CVE-2026-20495 Hoch
    Score 47 CVSS 7.8 EPSS 0.11%

    Bluetooth-Treiber: Rechteumgehung durch fehlende Berechtigungsprüfung

  33. CVE-2026-18642 Hoch
    Score 47 CVSS 7.8 EPSS 0.13%

    eta-otp-lock – Deserialisierung nicht vertrauenswürdiger Daten (Object Injection)

  34. CVE-2026-59912 Hoch
    Score 47 CVSS 7.8 EPSS 0.10%

    Dell Display and Peripheral Manager (DDPM Mac) vor 2.3.0.1005 – Improper Access Control

  35. CVE-2026-59913 Hoch
    Score 47 CVSS 7.8 EPSS 0.11%

    Dell Display and Peripheral Manager (DDPM Mac) – Missing Authentication for Critical Function

  36. CVE-2026-41447 Hoch
    Score 47 CVSS 7.8 EPSS 0.11%

    FirmaCheck for Windows vor 1.3.16: DLL-Hijacking über openssl.cnf

  37. CVE-2026-20483 Hoch
    Score 46 CVSS 7.7 EPSS 0.13%

    Telephony-Komponente: Rechteausweitung durch fehlende Berechtigungsprüfung

  38. CVE-2026-69086 Hoch
    Score 46 CVSS 7.7 EPSS 0.35%

    SiYuan vor v3.7.3 – Path Traversal in attribute-view-Lese-Endpunkten

  39. CVE-2026-3245 Hoch
    Score 45 CVSS 7.5 EPSS 0.24%

    PRISMAproduction: Deserialisierung ermöglicht Codeausführung (bis Version 6.5)

  40. CVE-2026-20479 Hoch
    Score 45 CVSS 7.5 EPSS 0.50%

    Modem: Out-of-Bounds Read durch fehlende Bounds-Prüfung ermöglicht Denial of Service über Rogue Base Station

  41. CVE-2026-18587 Hoch
    Score 45 CVSS 7.5 EPSS 1.26%

    Wavlink WL-NU516U1: Schwachstelle im Passwort-Parameter der Komponente Config Import

  42. CVE-2026-21548 Hoch
    Score 45 CVSS 7.5 EPSS 0.40%

    SimpleHelp – Unsachgemässe Eingabevalidierung im NR-Modem-Modul ermöglicht Denial of Service

  43. CVE-2026-21549 Hoch
    Score 45 CVSS 7.5 EPSS 0.40%

    SimpleHelp – Unsachgemässe Eingabevalidierung im Modem-Modul (Denial of Service)

  44. CVE-2026-21550 Hoch
    Score 45 CVSS 7.5 EPSS 0.40%

    Unzureichende Eingabevalidierung im Modem-Subsystem – Remote Denial of Service

  45. CVE-2026-21551 Hoch
    Score 45 CVSS 7.5 EPSS 0.40%

    SimpleHelp Modem-Komponente – Denial of Service durch fehlerhafte Eingabevalidierung

  46. CVE-2026-21552 Hoch
    Score 45 CVSS 7.5 EPSS 0.40%

    SimpleHelp – Unsachgemässe Eingabevalidierung im Modem-Modul ermöglicht Denial of Service

  47. CVE-2026-21553 Hoch
    Score 45 CVSS 7.5 EPSS 0.40%

    SimpleHelp – Unsachgemässe Eingabevalidierung im Modem-Modul (Denial of Service)

  48. CVE-2026-21554 Hoch
    Score 45 CVSS 7.5 EPSS 0.40%

    Unzureichende Eingabevalidierung im Modem-Subsystem – Remote Denial of Service

  49. CVE-2026-21555 Hoch
    Score 45 CVSS 7.5 EPSS 0.40%

    SimpleHelp Modem-Komponente – Denial of Service durch fehlerhafte Eingabevalidierung

  50. CVE-2026-18089 Hoch
    Score 45 CVSS 7.5 EPSS 0.18%

    Net::SAML2 vor 0.86 – SAML-Authentifizierungsumgehung

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.