Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 1101 bis 1150 von 36300

  1. CVE-2026-8763 Mittel
    Score 0 EPSS 0.33%

    Bouncy Castle for Java: Umgehung der Name Constraints durch abschliessenden Punkt

  2. CVE-2026-58059 Mittel
    Score 0 EPSS 0.33%

    Bouncy Castle for Java: Quadratische Laufzeit bei der X.500-Distinguished-Name-Verarbeitung

  3. CVE-2026-58060 Mittel
    Score 0 EPSS 0.36%

    Bouncy Castle for Java: Unbegrenzte HSS Public-Key-Level-Anzahl ermöglicht Speicherüberlastung bei Verifikation

  4. CVE-2026-58061 Mittel
    Score 0 EPSS 0.21%

    Bouncy Castle for Java: CCM-Modi schreiben Klartext vor Tag-Prüfung in Callerpuffer

  5. CVE-2026-58062 Mittel
    Score 0 EPSS 0.20%

    Bouncy Castle for Java: Gestapelte OCSP-Response ohne Zertifikatsbindung akzeptiert

  6. CVE-2026-58063 Mittel
    Score 0 EPSS 0.33%

    Bouncy Castle for Java: Unbegrenzte KDF-Kosten beim Laden von BCFKS-Keystores

  7. CVE-2026-12802 Mittel
    Score 0 EPSS 0.17%

    Bouncy Castle for Java: CMS AuthEnvelopedData erzwingt Tag-Length bei Entschlüsselung nicht

  8. CVE-2026-12803 Mittel
    Score 0 EPSS 0.17%

    Bouncy Castle for Java: KCCMBlockCipher-MAC bindet Nonce nicht bei fehlendem AAD

  9. CVE-2026-12816 Mittel
    Score 0 EPSS 0.16%

    Bouncy Castle for Java – MAC-Fälschung im IESEngine-Streammodus durch längenabhängige KDF-Aufteilung

  10. CVE-2026-12817 Mittel
    Score 0 EPSS 0.16%

    Bouncy Castle for Java – OpenPGP-AEAD-Entschlüsselung prüft finalen Tag bei chunk-ausgerichteten Daten nicht

  11. CVE-2026-12852 Mittel
    Score 0 EPSS 0.28%

    Bouncy Castle for Java: MLS-Wire-Decoder alloziert Angreifer-kontrollierte Länge vor Bounds-Check

  12. CVE-2026-12860 Mittel
    Score 0 EPSS 0.18%

    Bouncy Castle for Java: RSA-PKCS#1-Signaturprüfung überspringt letzte zwei Hash-Bytes

  13. CVE-2026-13506 Mittel
    Score 0 EPSS 0.28%

    Bouncy Castle for Java – Lazy-ASN.1-Sequenzerzwingung setzt Nesting-Depth-Schutz zurück

  14. CVE-2026-13586 Mittel
    Score 0 EPSS 0.31%

    Bouncy Castle for Java – fehlende Begrenzung der KDF-Iterationszahl bei PKCS#12 ermöglicht Denial of Service

  15. CVE-2026-14682 Mittel
    Score 0 EPSS 0.28%

    Bouncy Castle for Java: Speicherausschöpfung durch unbegrenzte Vorab-Allokation bei definite-length Reads

  16. CVE-2026-15931 Mittel
    Score 0 EPSS 0.17%

    WordPress-Plugin Simple Membership vor 4.7.8: fehlende Bereinigung des Abonnenten-Namens

  17. CVE-2026-8793 Mittel
    Score 0 EPSS 0.68%

    PaperCut NG/MF – Fehlende Begrenzung von Anmeldeversuchen ermöglicht Brute-Force-Angriffe

  18. CVE-2026-8794 Mittel
    Score 0 EPSS 0.68%

    PaperCut NG/MF – Timing-Seitenkanal in der Authentifizierung (Benutzername-Enumeration)

  19. CVE-2026-69082 Mittel
    Score 0 EPSS 0.21%

    CTI-Transmute: Cross-Site-Request-Forgery bei Benutzerlöschung

  20. CVE-2026-18574 Mittel
    Score 0 EPSS 0.99%

    Check Point Security Management Server und MDS – Authentifizierungsumgehung

  21. CVE-2025-15627 Mittel
    Score 0 EPSS 0.35%

    TP-Link Omada: Hartcodierte kryptografische Schlüssel im Adoptionsprotokoll

  22. CVE-2025-9291 Mittel
    Score 0 EPSS 0.13%

    TP-Link Omada: Schwache Zertifikatsprüfung bei Cloud-Controller-Kommunikation

  23. CVE-2026-68945 Mittel
    Score 0 EPSS 0.19%

    Angular: Schwachstelle in HttpTransferCache vor Version 20.3.27/21.2.19/22.0.2

  24. CVE-2026-69149 Mittel
    Score 0 EPSS 0.34%

    Angular – Cross-Site-Scripting-Schwachstelle (XSS)

  25. CVE-2026-69151 Mittel
    Score 0 EPSS 0.33%

    Angular: Schwachstelle in der i18n-Pipeline des Compilers vor 20.3.27, 21.2.19 und 22.0.1

  26. CVE-2025-15628 Mittel
    Score 0 EPSS 0.10%

    TP-Link Omada: Gemeinsam genutzte eingebettete Zertifikate zwischen Controllern und Geräten

  27. CVE-2025-15629 Mittel
    Score 0 EPSS 0.10%

    Omada-Adoptionsprotokoll: Vorhersagbare Sitzungsschlüssel durch kryptografische Schwäche

  28. CVE-2025-15630 Mittel
    Score 0 EPSS 0.19%

    TP-Link Omada: Race Condition im cloudbasierten Geräte-Adoptionsprozess

  29. CVE-2026-46712 Mittel
    Score 0 EPSS 0.21%

    Misskey: Fehlende Berechtigungsprüfung ermöglicht Zugriff auf geschützte Inhalte

  30. CVE-2026-46713 Mittel
    Score 0 EPSS 0.17%

    Misskey 12.37.0 bis vor 2026.5.4: Schwachstelle bei JSON-LD-Signaturvalidierung

  31. CVE-2026-46714 Mittel
    Score 0 EPSS 0.26%

    Misskey: Web-Client kann durch präparierte Inhalte verlangsamt werden oder abstürzen

  32. CVE-2026-47746 Mittel
    Score 0 EPSS 0.18%

    Misskey: Timing-Angriffe bei JSON-LD-Signaturprüfung und Kompaktierung

  33. CVE-2026-48115 Mittel
    Score 0 EPSS 0.25%

    Misskey: Schwachstelle in der Server Announcements API

  34. CVE-2026-51190 Mittel
    Score 0 EPSS 0.48%

    Serverless-Devs @serverless-devs/s bis 3.1.11: Command Injection über „s init“

  35. CVE-2026-51775 Mittel
    Score 0 EPSS 0.14%

    Fastadmin: SQL-Injection in Backend.php ermöglicht Codeausführung

  36. CVE-2026-69243 Mittel
    Score 0 EPSS 0.27%

    aiohttp bis 3.14.1 – Request Smuggling über abgelehntes WebSocket-Upgrade

  37. CVE-2026-69244 Mittel
    Score 0 EPSS 0.30%

    AIOHTTP: Out-of-Bounds-Heap-Lesezugriff im C-Response-Parser

  38. CVE-2026-69247 Mittel
    Score 0 EPSS 0.18%

    Python cryptography-Paket: Problem in PKCS7-Entschlüsselungsfunktionen

  39. CVE-2026-69248 Mittel
    Score 0 EPSS 0.18%

    Python cryptography vor 49.0.0: Problem bei namensbeschränkten Zwischen-CAs

  40. CVE-2026-69249 Mittel
    Score 0 EPSS 0.19%

    python-cryptography: Fehlerhafte Auflösung ungültiger Zertifikatsketten mit Duplikaten

  41. CVE-2026-18577 Aktiv ausgenutzt
    Score 100 EPSS 54.07%

    N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

  42. CVE-2026-8457 Kritisch
    Score 59 CVSS 9.8 EPSS 0.40%

    WooCommerce – Social Login (WordPress-Plugin): Authentication Bypass bis Version 2.8.7

  43. CVE-2026-16256 Kritisch
    Score 59 CVSS 9.8 EPSS 0.30%

    POUCO Import Users: Fehlende Zugriffsprüfung bei AJAX-Aktionen zur Kontoerstellung

  44. CVE-2026-65321 Kritisch
    Score 59 CVSS 9.8 EPSS 0.44%

    PyAthena: SQL-Injection in DefaultParameterFormatter.format()

  45. CVE-2026-68579 Kritisch
    Score 58 CVSS 9.6 EPSS 0.27%

    FreeRDP – Heap-basierter Pufferüberlauf im Windows-Zwischenablage-Client (CliprdrStream_Read)

  46. CVE-2026-12586 Hoch
    Score 49 CVSS 8.1 EPSS 0.17%

    Lenxel WP Theme: Fehlende Berechtigungsprüfung bei Passwort-Reset

  47. CVE-2026-13339 Hoch
    Score 45 CVSS 7.5 EPSS 0.64%

    CubeWP Framework WordPress-Plugin: Directory Traversal via cubewp_get_svg_content

  48. CVE-2026-18352 Hoch
    Score 45 CVSS 7.5 EPSS 0.68%

    User Access Manager (WordPress): Directory Traversal via uamgetfile-Parameter

  49. CVE-2026-15151 Hoch
    Score 45 CVSS 7.5 EPSS 0.23%

    WordPress Five Star Restaurant Reservations: Fehlende Berechtigungsprüfung bei AJAX-Aktion

  50. CVE-2026-15206 Hoch
    Score 45 CVSS 7.5 EPSS 0.26%

    SMS Alert (WordPress): Sitzungs-Flag nicht an verifizierte Telefonnummer gebunden

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.