Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 1001 bis 1050 von 36300
- CVE-2026-69089 HochScore 45 CVSS 7.5
Grav CMS – Path Traversal in ImageMedium::watermark()
- CVE-2026-69091 HochScore 45 CVSS 7.5
Admidio – Authentifizierungsumgehung im Forum-Modul
- CVE-2026-69095 HochScore 45 CVSS 7.5
OpenWrt luci-app-bmx7: Path Traversal im CGI-Skript bmx7-info
- CVE-2026-18568 HochScore 45 CVSS 7.5 EPSS 0.19%
XML::Sig für Perl: Signaturprüfung durch verify() umgehbar
- CVE-2026-68981 HochScore 45 CVSS 7.5 EPSS 0.32%
Apache NiFi 1.5.0 bis 2.10.0: Grössenprüfung bei gzip-kodierten REST-API-Anfragen
- CVE-2026-4793 HochScore 44 CVSS 7.3 EPSS 0.15%
Synology Assistant: Unsichere Standardberechtigungen vor Version 7.0.7-50095
- CVE-2026-0392 HochScore 44 CVSS 7.3 EPSS 0.06%
eParakstītājs für Windows: Unauthentifizierter Auto-Update-Kanal
- CVE-2026-67598 HochScore 44 CVSS 7.4 EPSS 0.16%
Emlog Pro bis 2.6.23: deaktivierte TLS-Zertifikatsprüfung
- CVE-2026-65875 HochScore 43 CVSS 7.1 EPSS 0.15%
BaserCMS: CSV-Dateiinjection-Schwachstelle
- CVE-2026-67608 HochScore 43 CVSS 7.2
Telenia TVox – OS-Command-Injection in action_audio.php
- CVE-2026-39931 HochScore 43 CVSS 7.2
OpenEMR bis 8.2.0: Authentifizierte SQL-Injection im Backup-Konfigurationsimport
- CVE-2026-61523 HochScore 43 CVSS 7.2
WebsiteBaker CMS (vor 2.13.10) – Code-Injection im Droplets-Editor
- CVE-2026-61524 HochScore 43 CVSS 7.2
WebsiteBaker CMS: Unrestricted File Upload in der Modul-Installation (vor Version 2.13.10)
- CVE-2026-69246 HochScore 43 CVSS 7.2 EPSS 0.21%
Guzzle (PHP HTTP-Client): Host-Header-Übergabe an cURL-Handler
- CVE-2026-69097 HochScore 42 CVSS 7 EPSS 0.19%
GitPython: Konfigurations-Injection über nicht escapte Submodul-Namen
- CVE-2026-18718 HochScore 42 CVSS 7 EPSS 0.21%
Ghidra – Codeausführung über Swift-Demangler-Analyzer
- CVE-2026-18654 MittelScore 41 CVSS 6.8 EPSS 0.29%
AWS CLI – Schlüsselaustausch ohne Authentifizierung in EMR-SSH-Hilfsbefehlen ermöglicht Man-in-the-Middle
- CVE-2026-40717 MittelScore 40 CVSS 6.6 EPSS 0.11%
Dell Monitor Driver – Improper Link Resolution Before File Access
- CVE-2026-20464 MittelScore 39 CVSS 6.5 EPSS 0.35%
HEVC-Decoder: Out-of-Bounds-Schreibzugriff durch Integer-Overflow
- CVE-2026-20482 MittelScore 39 CVSS 6.5 EPSS 0.18%
wlan STA FW: Denial of Service durch übermässiges Logging
- CVE-2026-15254 MittelScore 39 CVSS 6.5 EPSS 0.20%
WordPress-Plugin Simply Schedule Appointments vor 1.6.12.11: fehlende Berechtigungsprüfung bei Termin-Shortcode
- CVE-2026-16057 MittelScore 39 CVSS 6.5 EPSS 0.23%
Contest Gallery WordPress-Plugin: unzureichende Prüfung beim Löschen von Beiträgen
- CVE-2026-16563 MittelScore 39 CVSS 6.5 EPSS 0.20%
WordPress-Plugin Academy LMS vor 3.8.3: fehlende Zugriffsprüfung in REST-API
- CVE-2026-69092 MittelScore 39 CVSS 6.5
Admidio – Reflected XSS im SSO/SAML-Endpunkt
- CVE-2026-18655 MittelScore 39 CVSS 6.5 EPSS 0.25%
Amazon MQ MCP Server vor 2.0.24: unzureichende Endpunkt-Beschränkung bei RabbitMQ-Verbindungstools
- CVE-2026-69245 MittelScore 39 CVSS 6.5 EPSS 0.14%
Guzzle (PHP-HTTP-Client): Cookie-Domain-Prüfung in SetCookie::matchesDomain() unzureichend
- CVE-2026-18631 MittelScore 38 CVSS 6.3 EPSS 0.38%
jeequan jeepay bis 3.2.9: Schwachstelle in WebSecurityConfig
- CVE-2026-18632 MittelScore 38 CVSS 6.3 EPSS 0.38%
langgenius/dify – Jinja2-Template-Injection in jinja2_transformer.py
- CVE-2026-20470 MittelScore 37 CVSS 6.2 EPSS 0.13%
Telephony: Informationsoffenlegung durch fehlende Berechtigungsprüfung
- CVE-2026-13340 MittelScore 37 CVSS 6.1 EPSS 0.18%
SVG Support WordPress-Plugin: fehlende Bereinigung bei .svgz-Uploads
- CVE-2026-15383 MittelScore 37 CVSS 6.1 EPSS 0.17%
Blog Floating Button WordPress-Plugin: gespeicherte XSS über User-Agent-Header (bis Version 1.4.20)
- CVE-2026-38444 MittelScore 37 CVSS 6.1
osTicket v1.18.3: Stored XSS über den Anzeigenamen im E-Mail-From-Header
- CVE-2026-20467 MittelScore 36 CVSS 6 EPSS 0.12%
Apusys-Komponente: Rechteausweitung durch fehlende Bounds-Prüfung
- CVE-2026-20475 MittelScore 36 CVSS 6 EPSS 0.12%
Display-Komponente: Out-of-Bounds-Write durch fehlende Bounds-Prüfung ermöglicht lokale Rechteausweitung
- CVE-2026-20477 MittelScore 36 CVSS 6 EPSS 0.12%
Display-Komponente: Out-of-Bounds-Schreibzugriff durch fehlende Bounds-Prüfung
- CVE-2026-20481 MittelScore 36 CVSS 6 EPSS 0.11%
Geniezone: weitere Out-of-Bounds-Write-Schwachstelle durch fehlende Bounds-Prüfung
- CVE-2026-20485 MittelScore 36 CVSS 6 EPSS 0.11%
HFRP-Komponente: Out-of-Bounds-Write durch fehlende Bounds-Prüfung ermöglicht lokale Rechteausweitung
- CVE-2026-20497 MittelScore 36 CVSS 6 EPSS 0.11%
Geniezone: Out-of-Bounds-Write durch fehlende Bounds-Prüfung ermöglicht lokale Rechteausweitung
- CVE-2026-20498 MittelScore 36 CVSS 6 EPSS 0.11%
geniezone: Rechteausweitung durch fehlende Berechtigungsprüfung
- CVE-2026-68585 MittelScore 35 CVSS 5.8 EPSS 0.19%
SiYuan – Offenlegung von Metadaten über /api/block/getBlockInfo
- CVE-2026-20476 MittelScore 33 CVSS 5.5 EPSS 0.11%
ccci: Out-of-Bounds-Read durch fehlende Bounds-Prüfung
- CVE-2026-20491 MittelScore 33 CVSS 5.5 EPSS 0.10%
Med: Out-of-Bounds Write durch fehlerhafte Bounds-Prüfung ermöglicht lokalen Denial of Service
- CVE-2026-20494 MittelScore 33 CVSS 5.5 EPSS 0.10%
wifi: Out-of-Bounds-Read durch fehlende Bounds-Prüfung
- CVE-2026-6694 MittelScore 33 CVSS 5.5 EPSS 0.15%
GIMP: Schwachstelle im file-png-Plugin durch übergrossen tRNS-Chunk
- CVE-2026-6695 MittelScore 33 CVSS 5.5 EPSS 0.15%
GIMP – Heap-basierter Speicherfehler bei PAA-Bilddateien
- CVE-2026-18582 MittelScore 32 CVSS 5.3 EPSS 0.50%
mz-automation libiec61850: Schwachstelle in Reporting_RCBWriteAccessHandler
- CVE-2026-18583 MittelScore 32 CVSS 5.3 EPSS 0.50%
mz-automation libiec61850: Schwachstelle in checkDataSetAccess (mms_mapping.c)
- CVE-2026-18651 MittelScore 32 CVSS 5.4 EPSS 0.17%
389 Directory Server – Bind-Credentials vor Account-Lock-Prüfung bei SASL-PLAIN-Authentifizierung installiert
- CVE-2026-18604 MittelScore 32 CVSS 5.3 EPSS 0.10%
textPlus Text Message and Call App bis 8.3.5 (Android): Schwachstelle in DialerActivity
- CVE-2026-18644 MittelScore 32 CVSS 5.4 EPSS 0.37%
danpros HTMLy: Schwachstelle in der Delete-Username-Funktion (unlink)
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.