Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 1051 bis 1100 von 36300

  1. CVE-2026-18645 Mittel
    Score 32 CVSS 5.4 EPSS 0.43%

    danpros HTMLy: Schwachstelle in add_content des Admin Content Endpoint

  2. CVE-2026-18646 Mittel
    Score 32 CVSS 5.3 EPSS 0.54%

    danpros HTMLy: Schwachstelle im Author Name Handler (/system/htmly.php)

  3. CVE-2026-49131 Mittel
    Score 32 CVSS 5.4 EPSS 0.17%

    OPNsense vor 26.1.9: Gespeichertes XSS bei Firewall-Regelverwaltung

  4. CVE-2026-49132 Mittel
    Score 32 CVSS 5.4 EPSS 0.11%

    OPNsense: Gespeicherte Cross-Site-Scripting-Lücke über Zertifikatsbeschreibung

  5. CVE-2026-52520 Mittel
    Score 32 CVSS 5.4 EPSS 0.20%

    Emlog CMS: Stored XSS im Artikel-Publishing-Modul (/admin/article.php)

  6. CVE-2025-15673 Mittel
    Score 29 CVSS 4.9 EPSS 0.34%

    Import and export users and customers WordPress-Plugin: Path Traversal beim CSV-Import (vor Version 2.4.3)

  7. CVE-2026-67617 Mittel
    Score 29 CVSS 4.8 EPSS 0.16%

    Microweber CMS: Gespeicherte Cross-Site-Scripting-Lücke im Content-Tagging-System

  8. CVE-2026-20471 Mittel
    Score 28 CVSS 4.6 EPSS 0.17%

    DA-Komponente: Out-of-Bounds-Schreibzugriff bei physischem Zugriff

  9. CVE-2026-18592 Mittel
    Score 28 CVSS 4.7 EPSS 0.20%

    osCommerce EmailController – Sicherheitslücke in der Email-Komponente

  10. CVE-2026-69093 Mittel
    Score 28 CVSS 4.6

    Admidio vor 5.0.11 – CSRF in den Category-Report-Einstellungen

  11. CVE-2026-18738 Mittel
    Score 28 CVSS 4.7 EPSS 0.38%

    Shlink 5.0.0 bis 5.1.5: CSV-Formel-Injection über exportierte Besuchsdaten

  12. CVE-2026-20472 Mittel
    Score 26 CVSS 4.4 EPSS 0.11%

    TFA: Out-of-Bounds Write durch fehlende Bounds-Prüfung ermöglicht lokalen Denial of Service

  13. CVE-2026-20484 Mittel
    Score 26 CVSS 4.4 EPSS 0.12%

    TFA: Informationsoffenlegung durch fehlende Berechtigungsprüfung

  14. CVE-2026-20488 Mittel
    Score 26 CVSS 4.4 EPSS 0.12%

    display: Informationsoffenlegung durch fehlende Bounds-Prüfung

  15. CVE-2026-20490 Mittel
    Score 26 CVSS 4.4 EPSS 0.10%

    ccci-Treiber: Out-of-Bounds-Lesezugriff durch fehlende Bounds-Prüfung

  16. CVE-2026-20493 Mittel
    Score 26 CVSS 4.4 EPSS 0.10%

    WiFi-Komponente: Out-of-Bounds-Write durch fehlende Bounds-Prüfung ermöglicht lokalen Denial-of-Service

  17. CVE-2026-20496 Mittel
    Score 26 CVSS 4.4 EPSS 0.11%

    Geniezone: Out-of-Bounds Read durch fehlende Bounds-Prüfung ermöglicht lokale Informationsoffenlegung

  18. CVE-2026-18585 Mittel
    Score 26 CVSS 4.3 EPSS 0.30%

    GL.iNet-Router (u. a. MT3000, MT6000, BE9300) – Schwachstelle in der Funktion nas-web.get_file

  19. CVE-2026-15260 Mittel
    Score 26 CVSS 4.3 EPSS 0.15%

    GEO my WP WordPress-Plugin: fehlende Besitzprüfung bei AJAX-Aktionen

  20. CVE-2026-16289 Mittel
    Score 26 CVSS 4.3 EPSS 0.16%

    ProfileGrid WordPress-Plugin: fehlende Berechtigungsprüfung bei Mitgliedschaftsanfragen (vor Version 6.0.0.0)

  21. CVE-2026-16564 Mittel
    Score 26 CVSS 4.3 EPSS 0.15%

    Dokan WooCommerce Multivendor Marketplace: fehlende Besitzprüfung bei Bestellstatus-Änderungen

  22. CVE-2026-16565 Mittel
    Score 26 CVSS 4.3 EPSS 0.15%

    Dokan WooCommerce Multivendor Plugin für WordPress: fehlende Eigentümerprüfung bei Produktattributen (vor Version 5.0.9)

  23. CVE-2026-69094 Mittel
    Score 26 CVSS 4.3

    Admidio: Insecure Direct Object Reference in mylist_function.php

  24. CVE-2026-18508 Mittel
    Score 26 CVSS 4.4 EPSS 0.14%

    GNU tar – Hardlink-Ziele bei --one-top-level nicht auf Zielverzeichnis beschränkt

  25. CVE-2026-18477 Mittel
    Score 26 CVSS 4.4 EPSS 0.10%

    GNU tar – TOCTOU-Schwachstelle im inkrementellen Dumpdir-Rename

  26. CVE-2026-67616 Mittel
    Score 26 CVSS 4.3 EPSS 0.25%

    Camaleon CMS: Fehlende Autorisierungsprüfung am Drafts-Endpunkt

  27. CVE-2026-16297 Mittel
    Score 25 CVSS 4.1 EPSS 0.22%

    Clearfy Cache WordPress-Plugin: PHP Object Injection beim Import von Einstellungen (vor Version 2.4.3)

  28. CVE-2026-18581 Niedrig
    Score 20 CVSS 3.3 EPSS 0.11%

    llama.cpp: Schwachstelle im Jinja-Minja-Template-Parser (common/jinja/parser.cpp)

  29. CVE-2026-18682 Niedrig
    Score 19 CVSS 3.1 EPSS 0.25%

    OpenAkita bis 1.27.12: Schwachstelle in der File Upload API

  30. CVE-2026-15231 Niedrig
    Score 16 CVSS 2.7 EPSS 0.22%

    Tag, Category, and Taxonomy Manager WordPress-Plugin: Fehlende Zugriffsprüfung (vor Version 3.51.0)

  31. CVE-2026-16274 Niedrig
    Score 16 CVSS 2.7 EPSS 0.18%

    WordPress-Plugin Classified Listing vor 5.4.4: fehlende Berechtigungsprüfung in AJAX-Aktion

  32. CVE-2026-16276 Niedrig
    Score 16 CVSS 2.7 EPSS 0.18%

    Classified Listing WordPress-Plugin: fehlende Berechtigungsprüfung bei Umsatzdaten

  33. CVE-2026-18591 Niedrig
    Score 13 CVSS 2.1 EPSS 0.08%

    Meesho Online Shopping App: Schwachstelle in Komponente com.meesho.supply

  34. CVE-2026-12185 Mittel
    Score 0 EPSS 0.28%

    Bouncy Castle for Java: BKS/UBER-Keystore alloziert vor Integritätsprüfung anhand nicht vertrauenswürdiger Längen

  35. CVE-2026-15055 Mittel
    Score 0 EPSS 0.28%

    Bouncy Castle for Java: PKCS#8/PBES2-Entschlüsselung akzeptiert unbegrenzte KDF-Kosten

  36. CVE-2026-59638 Mittel
    Score 0 EPSS 0.29%

    Bouncy Castle for Java: JSSE-Hostname-Verifier aktiviert CN-Fallback standardmässig

  37. CVE-2026-59639 Mittel
    Score 0 EPSS 0.18%

    Bouncy Castle for Java: CMS verifySignatures liefert true bei SignedData ohne Unterzeichner

  38. CVE-2026-59640 Mittel
    Score 0 EPSS 0.28%

    Bouncy Castle for Java: OpenPGP-CFB-Quick-Check-Oracle bei symmetrischen Schlüsseln

  39. CVE-2026-59641 Mittel
    Score 0 EPSS 0.18%

    Bouncy Castle for Java: S/MIME-Validator vertraut vom Signierer angegebener signingTime

  40. CVE-2026-59642 Mittel
    Score 0 EPSS 0.17%

    Bouncy Castle for Java: CMS-AuthenticatedData-Inhalt bei vorhandenen authAttrs nicht an MAC gebunden

  41. CVE-2026-59643 Mittel
    Score 0 EPSS 0.17%

    Bouncy Castle for Java: OpenPGP ignoriert Fehler bei Inline-Signaturprüfung stillschweigend

  42. CVE-2026-59644 Mittel
    Score 0 EPSS 0.26%

    Bouncy Castle for Java: MLS-Hash-Ratchet akzeptiert beliebigen Generation-Counter

  43. CVE-2026-59645 Mittel
    Score 0 EPSS 0.28%

    Bouncy Castle for Java: Unbegrenzte Rekursion im OER-Parser

  44. CVE-2026-59646 Mittel
    Score 0 EPSS 0.31%

    Bouncy Castle for Java: Ungeprüfte 24-Bit-Länge im DTLS-Handshake-Reassembler

  45. CVE-2026-59647 Mittel
    Score 0 EPSS 0.28%

    Bouncy Castle for Java: CRMF/CMP Passwort-MAC ohne Begrenzung der Iterationszahl

  46. CVE-2026-59648 Mittel
    Score 0 EPSS 0.28%

    Bouncy Castle for Java: OpenPGP Argon2 S2K nutzt angreiferkontrollierte Speicher-/Pass-Parameter

  47. CVE-2026-59649 Mittel
    Score 0 EPSS 0.26%

    Bouncy Castle for Java: Unbegrenzte OpenPGP-User-Attribute-Subpacket-Laenge

  48. CVE-2026-59650 Mittel
    Score 0 EPSS 0.26%

    Bouncy Castle for Java: Unvalidierter Peer-Wert bei MTI/A0-DH-Schlüsselaustausch

  49. CVE-2026-59651 Mittel
    Score 0 EPSS 0.17%

    Bouncy Castle for Java: BKS-Keystore akzeptiert schwache Legacy-Integritätsprüfung

  50. CVE-2026-59652 Mittel
    Score 0 EPSS 0.34%

    Bouncy Castle for Java: LDAP-Filter-Injection in LDAPStoreHelper (jdk1.4)

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.