Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 1051 bis 1100 von 36300
- CVE-2026-18645 MittelScore 32 CVSS 5.4 EPSS 0.43%
danpros HTMLy: Schwachstelle in add_content des Admin Content Endpoint
- CVE-2026-18646 MittelScore 32 CVSS 5.3 EPSS 0.54%
danpros HTMLy: Schwachstelle im Author Name Handler (/system/htmly.php)
- CVE-2026-49131 MittelScore 32 CVSS 5.4 EPSS 0.17%
OPNsense vor 26.1.9: Gespeichertes XSS bei Firewall-Regelverwaltung
- CVE-2026-49132 MittelScore 32 CVSS 5.4 EPSS 0.11%
OPNsense: Gespeicherte Cross-Site-Scripting-Lücke über Zertifikatsbeschreibung
- CVE-2026-52520 MittelScore 32 CVSS 5.4 EPSS 0.20%
Emlog CMS: Stored XSS im Artikel-Publishing-Modul (/admin/article.php)
- CVE-2025-15673 MittelScore 29 CVSS 4.9 EPSS 0.34%
Import and export users and customers WordPress-Plugin: Path Traversal beim CSV-Import (vor Version 2.4.3)
- CVE-2026-67617 MittelScore 29 CVSS 4.8 EPSS 0.16%
Microweber CMS: Gespeicherte Cross-Site-Scripting-Lücke im Content-Tagging-System
- CVE-2026-20471 MittelScore 28 CVSS 4.6 EPSS 0.17%
DA-Komponente: Out-of-Bounds-Schreibzugriff bei physischem Zugriff
- CVE-2026-18592 MittelScore 28 CVSS 4.7 EPSS 0.20%
osCommerce EmailController – Sicherheitslücke in der Email-Komponente
- CVE-2026-69093 MittelScore 28 CVSS 4.6
Admidio vor 5.0.11 – CSRF in den Category-Report-Einstellungen
- CVE-2026-18738 MittelScore 28 CVSS 4.7 EPSS 0.38%
Shlink 5.0.0 bis 5.1.5: CSV-Formel-Injection über exportierte Besuchsdaten
- CVE-2026-20472 MittelScore 26 CVSS 4.4 EPSS 0.11%
TFA: Out-of-Bounds Write durch fehlende Bounds-Prüfung ermöglicht lokalen Denial of Service
- CVE-2026-20484 MittelScore 26 CVSS 4.4 EPSS 0.12%
TFA: Informationsoffenlegung durch fehlende Berechtigungsprüfung
- CVE-2026-20488 MittelScore 26 CVSS 4.4 EPSS 0.12%
display: Informationsoffenlegung durch fehlende Bounds-Prüfung
- CVE-2026-20490 MittelScore 26 CVSS 4.4 EPSS 0.10%
ccci-Treiber: Out-of-Bounds-Lesezugriff durch fehlende Bounds-Prüfung
- CVE-2026-20493 MittelScore 26 CVSS 4.4 EPSS 0.10%
WiFi-Komponente: Out-of-Bounds-Write durch fehlende Bounds-Prüfung ermöglicht lokalen Denial-of-Service
- CVE-2026-20496 MittelScore 26 CVSS 4.4 EPSS 0.11%
Geniezone: Out-of-Bounds Read durch fehlende Bounds-Prüfung ermöglicht lokale Informationsoffenlegung
- CVE-2026-18585 MittelScore 26 CVSS 4.3 EPSS 0.30%
GL.iNet-Router (u. a. MT3000, MT6000, BE9300) – Schwachstelle in der Funktion nas-web.get_file
- CVE-2026-15260 MittelScore 26 CVSS 4.3 EPSS 0.15%
GEO my WP WordPress-Plugin: fehlende Besitzprüfung bei AJAX-Aktionen
- CVE-2026-16289 MittelScore 26 CVSS 4.3 EPSS 0.16%
ProfileGrid WordPress-Plugin: fehlende Berechtigungsprüfung bei Mitgliedschaftsanfragen (vor Version 6.0.0.0)
- CVE-2026-16564 MittelScore 26 CVSS 4.3 EPSS 0.15%
Dokan WooCommerce Multivendor Marketplace: fehlende Besitzprüfung bei Bestellstatus-Änderungen
- CVE-2026-16565 MittelScore 26 CVSS 4.3 EPSS 0.15%
Dokan WooCommerce Multivendor Plugin für WordPress: fehlende Eigentümerprüfung bei Produktattributen (vor Version 5.0.9)
- CVE-2026-69094 MittelScore 26 CVSS 4.3
Admidio: Insecure Direct Object Reference in mylist_function.php
- CVE-2026-18508 MittelScore 26 CVSS 4.4 EPSS 0.14%
GNU tar – Hardlink-Ziele bei --one-top-level nicht auf Zielverzeichnis beschränkt
- CVE-2026-18477 MittelScore 26 CVSS 4.4 EPSS 0.10%
GNU tar – TOCTOU-Schwachstelle im inkrementellen Dumpdir-Rename
- CVE-2026-67616 MittelScore 26 CVSS 4.3 EPSS 0.25%
Camaleon CMS: Fehlende Autorisierungsprüfung am Drafts-Endpunkt
- CVE-2026-16297 MittelScore 25 CVSS 4.1 EPSS 0.22%
Clearfy Cache WordPress-Plugin: PHP Object Injection beim Import von Einstellungen (vor Version 2.4.3)
- CVE-2026-18581 NiedrigScore 20 CVSS 3.3 EPSS 0.11%
llama.cpp: Schwachstelle im Jinja-Minja-Template-Parser (common/jinja/parser.cpp)
- CVE-2026-18682 NiedrigScore 19 CVSS 3.1 EPSS 0.25%
OpenAkita bis 1.27.12: Schwachstelle in der File Upload API
- CVE-2026-15231 NiedrigScore 16 CVSS 2.7 EPSS 0.22%
Tag, Category, and Taxonomy Manager WordPress-Plugin: Fehlende Zugriffsprüfung (vor Version 3.51.0)
- CVE-2026-16274 NiedrigScore 16 CVSS 2.7 EPSS 0.18%
WordPress-Plugin Classified Listing vor 5.4.4: fehlende Berechtigungsprüfung in AJAX-Aktion
- CVE-2026-16276 NiedrigScore 16 CVSS 2.7 EPSS 0.18%
Classified Listing WordPress-Plugin: fehlende Berechtigungsprüfung bei Umsatzdaten
- CVE-2026-18591 NiedrigScore 13 CVSS 2.1 EPSS 0.08%
Meesho Online Shopping App: Schwachstelle in Komponente com.meesho.supply
- CVE-2026-12185 MittelScore 0 EPSS 0.28%
Bouncy Castle for Java: BKS/UBER-Keystore alloziert vor Integritätsprüfung anhand nicht vertrauenswürdiger Längen
- CVE-2026-15055 MittelScore 0 EPSS 0.28%
Bouncy Castle for Java: PKCS#8/PBES2-Entschlüsselung akzeptiert unbegrenzte KDF-Kosten
- CVE-2026-59638 MittelScore 0 EPSS 0.29%
Bouncy Castle for Java: JSSE-Hostname-Verifier aktiviert CN-Fallback standardmässig
- CVE-2026-59639 MittelScore 0 EPSS 0.18%
Bouncy Castle for Java: CMS verifySignatures liefert true bei SignedData ohne Unterzeichner
- CVE-2026-59640 MittelScore 0 EPSS 0.28%
Bouncy Castle for Java: OpenPGP-CFB-Quick-Check-Oracle bei symmetrischen Schlüsseln
- CVE-2026-59641 MittelScore 0 EPSS 0.18%
Bouncy Castle for Java: S/MIME-Validator vertraut vom Signierer angegebener signingTime
- CVE-2026-59642 MittelScore 0 EPSS 0.17%
Bouncy Castle for Java: CMS-AuthenticatedData-Inhalt bei vorhandenen authAttrs nicht an MAC gebunden
- CVE-2026-59643 MittelScore 0 EPSS 0.17%
Bouncy Castle for Java: OpenPGP ignoriert Fehler bei Inline-Signaturprüfung stillschweigend
- CVE-2026-59644 MittelScore 0 EPSS 0.26%
Bouncy Castle for Java: MLS-Hash-Ratchet akzeptiert beliebigen Generation-Counter
- CVE-2026-59645 MittelScore 0 EPSS 0.28%
Bouncy Castle for Java: Unbegrenzte Rekursion im OER-Parser
- CVE-2026-59646 MittelScore 0 EPSS 0.31%
Bouncy Castle for Java: Ungeprüfte 24-Bit-Länge im DTLS-Handshake-Reassembler
- CVE-2026-59647 MittelScore 0 EPSS 0.28%
Bouncy Castle for Java: CRMF/CMP Passwort-MAC ohne Begrenzung der Iterationszahl
- CVE-2026-59648 MittelScore 0 EPSS 0.28%
Bouncy Castle for Java: OpenPGP Argon2 S2K nutzt angreiferkontrollierte Speicher-/Pass-Parameter
- CVE-2026-59649 MittelScore 0 EPSS 0.26%
Bouncy Castle for Java: Unbegrenzte OpenPGP-User-Attribute-Subpacket-Laenge
- CVE-2026-59650 MittelScore 0 EPSS 0.26%
Bouncy Castle for Java: Unvalidierter Peer-Wert bei MTI/A0-DH-Schlüsselaustausch
- CVE-2026-59651 MittelScore 0 EPSS 0.17%
Bouncy Castle for Java: BKS-Keystore akzeptiert schwache Legacy-Integritätsprüfung
- CVE-2026-59652 MittelScore 0 EPSS 0.34%
Bouncy Castle for Java: LDAP-Filter-Injection in LDAPStoreHelper (jdk1.4)
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.