Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 1001 bis 1050 von 36300

  1. CVE-2026-69089 Hoch
    Score 45 CVSS 7.5

    Grav CMS – Path Traversal in ImageMedium::watermark()

  2. CVE-2026-69091 Hoch
    Score 45 CVSS 7.5

    Admidio – Authentifizierungsumgehung im Forum-Modul

  3. CVE-2026-69095 Hoch
    Score 45 CVSS 7.5

    OpenWrt luci-app-bmx7: Path Traversal im CGI-Skript bmx7-info

  4. CVE-2026-18568 Hoch
    Score 45 CVSS 7.5 EPSS 0.19%

    XML::Sig für Perl: Signaturprüfung durch verify() umgehbar

  5. CVE-2026-68981 Hoch
    Score 45 CVSS 7.5 EPSS 0.32%

    Apache NiFi 1.5.0 bis 2.10.0: Grössenprüfung bei gzip-kodierten REST-API-Anfragen

  6. CVE-2026-4793 Hoch
    Score 44 CVSS 7.3 EPSS 0.15%

    Synology Assistant: Unsichere Standardberechtigungen vor Version 7.0.7-50095

  7. CVE-2026-0392 Hoch
    Score 44 CVSS 7.3 EPSS 0.06%

    eParakstītājs für Windows: Unauthentifizierter Auto-Update-Kanal

  8. CVE-2026-67598 Hoch
    Score 44 CVSS 7.4 EPSS 0.16%

    Emlog Pro bis 2.6.23: deaktivierte TLS-Zertifikatsprüfung

  9. CVE-2026-65875 Hoch
    Score 43 CVSS 7.1 EPSS 0.15%

    BaserCMS: CSV-Dateiinjection-Schwachstelle

  10. CVE-2026-67608 Hoch
    Score 43 CVSS 7.2

    Telenia TVox – OS-Command-Injection in action_audio.php

  11. CVE-2026-39931 Hoch
    Score 43 CVSS 7.2

    OpenEMR bis 8.2.0: Authentifizierte SQL-Injection im Backup-Konfigurationsimport

  12. CVE-2026-61523 Hoch
    Score 43 CVSS 7.2

    WebsiteBaker CMS (vor 2.13.10) – Code-Injection im Droplets-Editor

  13. CVE-2026-61524 Hoch
    Score 43 CVSS 7.2

    WebsiteBaker CMS: Unrestricted File Upload in der Modul-Installation (vor Version 2.13.10)

  14. CVE-2026-69246 Hoch
    Score 43 CVSS 7.2 EPSS 0.21%

    Guzzle (PHP HTTP-Client): Host-Header-Übergabe an cURL-Handler

  15. CVE-2026-69097 Hoch
    Score 42 CVSS 7 EPSS 0.19%

    GitPython: Konfigurations-Injection über nicht escapte Submodul-Namen

  16. CVE-2026-18718 Hoch
    Score 42 CVSS 7 EPSS 0.21%

    Ghidra – Codeausführung über Swift-Demangler-Analyzer

  17. CVE-2026-18654 Mittel
    Score 41 CVSS 6.8 EPSS 0.29%

    AWS CLI – Schlüsselaustausch ohne Authentifizierung in EMR-SSH-Hilfsbefehlen ermöglicht Man-in-the-Middle

  18. CVE-2026-40717 Mittel
    Score 40 CVSS 6.6 EPSS 0.11%

    Dell Monitor Driver – Improper Link Resolution Before File Access

  19. CVE-2026-20464 Mittel
    Score 39 CVSS 6.5 EPSS 0.35%

    HEVC-Decoder: Out-of-Bounds-Schreibzugriff durch Integer-Overflow

  20. CVE-2026-20482 Mittel
    Score 39 CVSS 6.5 EPSS 0.18%

    wlan STA FW: Denial of Service durch übermässiges Logging

  21. CVE-2026-15254 Mittel
    Score 39 CVSS 6.5 EPSS 0.20%

    WordPress-Plugin Simply Schedule Appointments vor 1.6.12.11: fehlende Berechtigungsprüfung bei Termin-Shortcode

  22. CVE-2026-16057 Mittel
    Score 39 CVSS 6.5 EPSS 0.23%

    Contest Gallery WordPress-Plugin: unzureichende Prüfung beim Löschen von Beiträgen

  23. CVE-2026-16563 Mittel
    Score 39 CVSS 6.5 EPSS 0.20%

    WordPress-Plugin Academy LMS vor 3.8.3: fehlende Zugriffsprüfung in REST-API

  24. CVE-2026-69092 Mittel
    Score 39 CVSS 6.5

    Admidio – Reflected XSS im SSO/SAML-Endpunkt

  25. CVE-2026-18655 Mittel
    Score 39 CVSS 6.5 EPSS 0.25%

    Amazon MQ MCP Server vor 2.0.24: unzureichende Endpunkt-Beschränkung bei RabbitMQ-Verbindungstools

  26. CVE-2026-69245 Mittel
    Score 39 CVSS 6.5 EPSS 0.14%

    Guzzle (PHP-HTTP-Client): Cookie-Domain-Prüfung in SetCookie::matchesDomain() unzureichend

  27. CVE-2026-18631 Mittel
    Score 38 CVSS 6.3 EPSS 0.38%

    jeequan jeepay bis 3.2.9: Schwachstelle in WebSecurityConfig

  28. CVE-2026-18632 Mittel
    Score 38 CVSS 6.3 EPSS 0.38%

    langgenius/dify – Jinja2-Template-Injection in jinja2_transformer.py

  29. CVE-2026-20470 Mittel
    Score 37 CVSS 6.2 EPSS 0.13%

    Telephony: Informationsoffenlegung durch fehlende Berechtigungsprüfung

  30. CVE-2026-13340 Mittel
    Score 37 CVSS 6.1 EPSS 0.18%

    SVG Support WordPress-Plugin: fehlende Bereinigung bei .svgz-Uploads

  31. CVE-2026-15383 Mittel
    Score 37 CVSS 6.1 EPSS 0.17%

    Blog Floating Button WordPress-Plugin: gespeicherte XSS über User-Agent-Header (bis Version 1.4.20)

  32. CVE-2026-38444 Mittel
    Score 37 CVSS 6.1

    osTicket v1.18.3: Stored XSS über den Anzeigenamen im E-Mail-From-Header

  33. CVE-2026-20467 Mittel
    Score 36 CVSS 6 EPSS 0.12%

    Apusys-Komponente: Rechteausweitung durch fehlende Bounds-Prüfung

  34. CVE-2026-20475 Mittel
    Score 36 CVSS 6 EPSS 0.12%

    Display-Komponente: Out-of-Bounds-Write durch fehlende Bounds-Prüfung ermöglicht lokale Rechteausweitung

  35. CVE-2026-20477 Mittel
    Score 36 CVSS 6 EPSS 0.12%

    Display-Komponente: Out-of-Bounds-Schreibzugriff durch fehlende Bounds-Prüfung

  36. CVE-2026-20481 Mittel
    Score 36 CVSS 6 EPSS 0.11%

    Geniezone: weitere Out-of-Bounds-Write-Schwachstelle durch fehlende Bounds-Prüfung

  37. CVE-2026-20485 Mittel
    Score 36 CVSS 6 EPSS 0.11%

    HFRP-Komponente: Out-of-Bounds-Write durch fehlende Bounds-Prüfung ermöglicht lokale Rechteausweitung

  38. CVE-2026-20497 Mittel
    Score 36 CVSS 6 EPSS 0.11%

    Geniezone: Out-of-Bounds-Write durch fehlende Bounds-Prüfung ermöglicht lokale Rechteausweitung

  39. CVE-2026-20498 Mittel
    Score 36 CVSS 6 EPSS 0.11%

    geniezone: Rechteausweitung durch fehlende Berechtigungsprüfung

  40. CVE-2026-68585 Mittel
    Score 35 CVSS 5.8 EPSS 0.19%

    SiYuan – Offenlegung von Metadaten über /api/block/getBlockInfo

  41. CVE-2026-20476 Mittel
    Score 33 CVSS 5.5 EPSS 0.11%

    ccci: Out-of-Bounds-Read durch fehlende Bounds-Prüfung

  42. CVE-2026-20491 Mittel
    Score 33 CVSS 5.5 EPSS 0.10%

    Med: Out-of-Bounds Write durch fehlerhafte Bounds-Prüfung ermöglicht lokalen Denial of Service

  43. CVE-2026-20494 Mittel
    Score 33 CVSS 5.5 EPSS 0.10%

    wifi: Out-of-Bounds-Read durch fehlende Bounds-Prüfung

  44. CVE-2026-6694 Mittel
    Score 33 CVSS 5.5 EPSS 0.15%

    GIMP: Schwachstelle im file-png-Plugin durch übergrossen tRNS-Chunk

  45. CVE-2026-6695 Mittel
    Score 33 CVSS 5.5 EPSS 0.15%

    GIMP – Heap-basierter Speicherfehler bei PAA-Bilddateien

  46. CVE-2026-18582 Mittel
    Score 32 CVSS 5.3 EPSS 0.50%

    mz-automation libiec61850: Schwachstelle in Reporting_RCBWriteAccessHandler

  47. CVE-2026-18583 Mittel
    Score 32 CVSS 5.3 EPSS 0.50%

    mz-automation libiec61850: Schwachstelle in checkDataSetAccess (mms_mapping.c)

  48. CVE-2026-18651 Mittel
    Score 32 CVSS 5.4 EPSS 0.17%

    389 Directory Server – Bind-Credentials vor Account-Lock-Prüfung bei SASL-PLAIN-Authentifizierung installiert

  49. CVE-2026-18604 Mittel
    Score 32 CVSS 5.3 EPSS 0.10%

    textPlus Text Message and Call App bis 8.3.5 (Android): Schwachstelle in DialerActivity

  50. CVE-2026-18644 Mittel
    Score 32 CVSS 5.4 EPSS 0.37%

    danpros HTMLy: Schwachstelle in der Delete-Username-Funktion (unlink)

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.