Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 951 bis 1000 von 36300
- CVE-2026-38447 KritischScore 59 CVSS 9.8
osTicket 1.18.3: Vorhersagbare API-Schlüssel durch MD5-Hashing
- CVE-2026-69240 KritischScore 59 CVSS 9.8 EPSS 0.32%
Sequelize (Node.js ORM): SQL-Injection bei Oracle-Dialekt durch fehlerhaftes String-Escaping
- CVE-2026-18684 KritischScore 59 CVSS 9.8 EPSS 2.03%
GL.iNet GL-MT3000: Command Injection in remove_profile (modem.so)
- CVE-2026-48326 KritischScore 59 CVSS 9.9 EPSS 0.50%
CVE-2026-48326 – SQL-Injection in Adobe Campaign Classic (ACC)
- CVE-2026-48333 KritischScore 59 CVSS 9.8 EPSS 0.48%
Adobe Campaign Classic – Incorrect Authorization mit Privilege Escalation
- CVE-2026-68979 KritischScore 59 CVSS 9.8 EPSS 0.35%
CVE-2026-68979 – Apache NiFi: fehlende Autorisierungsprüfung bei Parameter-Context-Updates
- CVE-2026-18667 KritischScore 58 CVSS 9.6 EPSS 0.39%
CVE-2026-18667 – Tenable Sensor Proxy Remote Code Execution
- CVE-2026-48317 KritischScore 58 CVSS 9.6 EPSS 0.49%
CVE-2026-48317 – Caddy (Light Code Labs)
- CVE-2026-15930 KritischScore 56 CVSS 9.4 EPSS 0.25%
Simple Membership WordPress-Plugin: Fehlende Prüfung bei der Registrierung (vor Version 4.7.8)
- CVE-2026-12965 KritischScore 55 CVSS 9.1 EPSS 0.35%
WordPress-Plugin Super Store Finder bis 7.8: SQL-Injection in AJAX-Aktion
- CVE-2026-14557 KritischScore 55 CVSS 9.1 EPSS 0.39%
SoftMarket – Digital Marketplace WordPress-Plugin: fehlerhafte Token-Validierung bei E-Mail-Verifizierung (bis Version 1.0.0)
- CVE-2026-16532 KritischScore 55 CVSS 9.1 EPSS 0.26%
Link Library WordPress-Plugin: SQL-Injection ohne Authentifizierung
- CVE-2026-16534 KritischScore 55 CVSS 9.1 EPSS 0.23%
Import and export users and customers WordPress-Plugin: fehlende Rechteprüfung beim CSV-Import (vor Version 2.4.2)
- CVE-2026-18248 KritischScore 55 CVSS 9.1 EPSS 0.22%
@fastify/aws-lambda: Autorisierungsrelevante Event-/Context-Dekorierung (Version 6.4.0)
- CVE-2026-39932 KritischScore 55 CVSS 9.1
OpenEMR – Remote Code Execution über Dokumentenkategorie-Baum (Tree.class.php)
- CVE-2026-48031 KritischScore 55 CVSS 9.1
go-base – Hartkodiertes JWT-Signing-Secret ermöglicht Authentifizierungsumgehung
- CVE-2026-9390 KritischScore 55 CVSS 9.1 EPSS 0.28%
XML::Sig vor 0.71 (Perl): XPath-Injection beim ID-Lookup
- CVE-2026-9487 KritischScore 55 CVSS 9.1 EPSS 0.17%
XML::Sig (Perl) vor 0.71 – Signature Wrapping durch doppelte ID
- CVE-2026-68980 KritischScore 55 CVSS 9.1 EPSS 0.26%
Apache NiFi: Autorisierung beim Löschen von Assets in Parameter Contexts
- CVE-2026-18598 HochScore 53 CVSS 8.8 EPSS 1.65%
GL.iNet GL-MT3000: Schwachstelle in logread.get_system_log (Logread Lua RPC)
- CVE-2026-69096 HochScore 53 CVSS 8.8 EPSS 1.67%
OpenWrt luci-app-dockerman: OS-Command-Injection im ucode-RPC-Backend
- CVE-2026-18733 HochScore 53 CVSS 8.8 EPSS 0.32%
Amazon Strands Agents Tools: Prompt-Injection im Shell-Tool ermöglicht Codeausführung
- CVE-2026-16572 HochScore 52 CVSS 8.6 EPSS 0.28%
LogMyTrip WordPress-Plugin: SQL-Injection über Cookie-Wert (bis Version 1.9)
- CVE-2026-69079 HochScore 52 CVSS 8.7 EPSS 0.40%
CTI-Transmute: Unkontrollierter Ressourcenverbrauch im /activity_timeline-Endpoint
- CVE-2026-20465 HochScore 49 CVSS 8.1 EPSS 0.20%
WLAN-AP-Treiber: Out-of-Bounds Write ermöglicht Rechteausweitung über angrenzendes Netzwerk
- CVE-2025-15672 HochScore 49 CVSS 8.1 EPSS 0.47%
ChamaWP WordPress-Plugin: PHP Object Injection durch unsichere Deserialisierung
- CVE-2026-16539 HochScore 49 CVSS 8.1 EPSS 0.21%
sm page duplicator WordPress-Plugin: SQL-Injection beim Duplizieren von Seiten (bis Version 1.0.0)
- CVE-2026-18092 HochScore 49 CVSS 8.1 EPSS 0.20%
Net::SAML2 (Perl) – SAML-Authentifizierungsumgehung durch XML Signature Wrapping
- CVE-2026-69088 HochScore 49 CVSS 8.1
Grav CMS – unsichere Validierung von Blueprint Dynamic-Field-Aufrufen
- CVE-2026-67610 HochScore 49 CVSS 8.1
OpenEMR bis 8.2.0: unsachgemässe Authentifizierung am OAuth2-Dynamic-Client-Registration-Endpunkt
- CVE-2026-18599 HochScore 48 CVSS 8 EPSS 1.40%
GL.iNet GL-MT3000: Schwachstelle in logread.set_config (Logread Lua RPC Plugin)
- CVE-2026-20495 HochScore 47 CVSS 7.8 EPSS 0.11%
Bluetooth-Treiber: Rechteumgehung durch fehlende Berechtigungsprüfung
- CVE-2026-18642 HochScore 47 CVSS 7.8 EPSS 0.13%
eta-otp-lock – Deserialisierung nicht vertrauenswürdiger Daten (Object Injection)
- CVE-2026-59912 HochScore 47 CVSS 7.8 EPSS 0.10%
Dell Display and Peripheral Manager (DDPM Mac) vor 2.3.0.1005 – Improper Access Control
- CVE-2026-59913 HochScore 47 CVSS 7.8 EPSS 0.11%
Dell Display and Peripheral Manager (DDPM Mac) – Missing Authentication for Critical Function
- CVE-2026-41447 HochScore 47 CVSS 7.8 EPSS 0.11%
FirmaCheck for Windows vor 1.3.16: DLL-Hijacking über openssl.cnf
- CVE-2026-20483 HochScore 46 CVSS 7.7 EPSS 0.13%
Telephony-Komponente: Rechteausweitung durch fehlende Berechtigungsprüfung
- CVE-2026-69086 HochScore 46 CVSS 7.7 EPSS 0.35%
SiYuan vor v3.7.3 – Path Traversal in attribute-view-Lese-Endpunkten
- CVE-2026-3245 HochScore 45 CVSS 7.5 EPSS 0.24%
PRISMAproduction: Deserialisierung ermöglicht Codeausführung (bis Version 6.5)
- CVE-2026-20479 HochScore 45 CVSS 7.5 EPSS 0.50%
Modem: Out-of-Bounds Read durch fehlende Bounds-Prüfung ermöglicht Denial of Service über Rogue Base Station
- CVE-2026-18587 HochScore 45 CVSS 7.5 EPSS 1.26%
Wavlink WL-NU516U1: Schwachstelle im Passwort-Parameter der Komponente Config Import
- CVE-2026-21548 HochScore 45 CVSS 7.5 EPSS 0.40%
SimpleHelp – Unsachgemässe Eingabevalidierung im NR-Modem-Modul ermöglicht Denial of Service
- CVE-2026-21549 HochScore 45 CVSS 7.5 EPSS 0.40%
SimpleHelp – Unsachgemässe Eingabevalidierung im Modem-Modul (Denial of Service)
- CVE-2026-21550 HochScore 45 CVSS 7.5 EPSS 0.40%
Unzureichende Eingabevalidierung im Modem-Subsystem – Remote Denial of Service
- CVE-2026-21551 HochScore 45 CVSS 7.5 EPSS 0.40%
SimpleHelp Modem-Komponente – Denial of Service durch fehlerhafte Eingabevalidierung
- CVE-2026-21552 HochScore 45 CVSS 7.5 EPSS 0.40%
SimpleHelp – Unsachgemässe Eingabevalidierung im Modem-Modul ermöglicht Denial of Service
- CVE-2026-21553 HochScore 45 CVSS 7.5 EPSS 0.40%
SimpleHelp – Unsachgemässe Eingabevalidierung im Modem-Modul (Denial of Service)
- CVE-2026-21554 HochScore 45 CVSS 7.5 EPSS 0.40%
Unzureichende Eingabevalidierung im Modem-Subsystem – Remote Denial of Service
- CVE-2026-21555 HochScore 45 CVSS 7.5 EPSS 0.40%
SimpleHelp Modem-Komponente – Denial of Service durch fehlerhafte Eingabevalidierung
- CVE-2026-18089 HochScore 45 CVSS 7.5 EPSS 0.18%
Net::SAML2 vor 0.86 – SAML-Authentifizierungsumgehung
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.