Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 1101 bis 1150 von 36300
- CVE-2026-8763 MittelScore 0 EPSS 0.33%
Bouncy Castle for Java: Umgehung der Name Constraints durch abschliessenden Punkt
- CVE-2026-58059 MittelScore 0 EPSS 0.33%
Bouncy Castle for Java: Quadratische Laufzeit bei der X.500-Distinguished-Name-Verarbeitung
- CVE-2026-58060 MittelScore 0 EPSS 0.36%
Bouncy Castle for Java: Unbegrenzte HSS Public-Key-Level-Anzahl ermöglicht Speicherüberlastung bei Verifikation
- CVE-2026-58061 MittelScore 0 EPSS 0.21%
Bouncy Castle for Java: CCM-Modi schreiben Klartext vor Tag-Prüfung in Callerpuffer
- CVE-2026-58062 MittelScore 0 EPSS 0.20%
Bouncy Castle for Java: Gestapelte OCSP-Response ohne Zertifikatsbindung akzeptiert
- CVE-2026-58063 MittelScore 0 EPSS 0.33%
Bouncy Castle for Java: Unbegrenzte KDF-Kosten beim Laden von BCFKS-Keystores
- CVE-2026-12802 MittelScore 0 EPSS 0.17%
Bouncy Castle for Java: CMS AuthEnvelopedData erzwingt Tag-Length bei Entschlüsselung nicht
- CVE-2026-12803 MittelScore 0 EPSS 0.17%
Bouncy Castle for Java: KCCMBlockCipher-MAC bindet Nonce nicht bei fehlendem AAD
- CVE-2026-12816 MittelScore 0 EPSS 0.16%
Bouncy Castle for Java – MAC-Fälschung im IESEngine-Streammodus durch längenabhängige KDF-Aufteilung
- CVE-2026-12817 MittelScore 0 EPSS 0.16%
Bouncy Castle for Java – OpenPGP-AEAD-Entschlüsselung prüft finalen Tag bei chunk-ausgerichteten Daten nicht
- CVE-2026-12852 MittelScore 0 EPSS 0.28%
Bouncy Castle for Java: MLS-Wire-Decoder alloziert Angreifer-kontrollierte Länge vor Bounds-Check
- CVE-2026-12860 MittelScore 0 EPSS 0.18%
Bouncy Castle for Java: RSA-PKCS#1-Signaturprüfung überspringt letzte zwei Hash-Bytes
- CVE-2026-13506 MittelScore 0 EPSS 0.28%
Bouncy Castle for Java – Lazy-ASN.1-Sequenzerzwingung setzt Nesting-Depth-Schutz zurück
- CVE-2026-13586 MittelScore 0 EPSS 0.31%
Bouncy Castle for Java – fehlende Begrenzung der KDF-Iterationszahl bei PKCS#12 ermöglicht Denial of Service
- CVE-2026-14682 MittelScore 0 EPSS 0.28%
Bouncy Castle for Java: Speicherausschöpfung durch unbegrenzte Vorab-Allokation bei definite-length Reads
- CVE-2026-15931 MittelScore 0 EPSS 0.17%
WordPress-Plugin Simple Membership vor 4.7.8: fehlende Bereinigung des Abonnenten-Namens
- CVE-2026-8793 MittelScore 0 EPSS 0.68%
PaperCut NG/MF – Fehlende Begrenzung von Anmeldeversuchen ermöglicht Brute-Force-Angriffe
- CVE-2026-8794 MittelScore 0 EPSS 0.68%
PaperCut NG/MF – Timing-Seitenkanal in der Authentifizierung (Benutzername-Enumeration)
- CVE-2026-69082 MittelScore 0 EPSS 0.21%
CTI-Transmute: Cross-Site-Request-Forgery bei Benutzerlöschung
- CVE-2026-18574 MittelScore 0 EPSS 0.99%
Check Point Security Management Server und MDS – Authentifizierungsumgehung
- CVE-2025-15627 MittelScore 0 EPSS 0.35%
TP-Link Omada: Hartcodierte kryptografische Schlüssel im Adoptionsprotokoll
- CVE-2025-9291 MittelScore 0 EPSS 0.13%
TP-Link Omada: Schwache Zertifikatsprüfung bei Cloud-Controller-Kommunikation
- CVE-2026-68945 MittelScore 0 EPSS 0.19%
Angular: Schwachstelle in HttpTransferCache vor Version 20.3.27/21.2.19/22.0.2
- CVE-2026-69149 MittelScore 0 EPSS 0.34%
Angular – Cross-Site-Scripting-Schwachstelle (XSS)
- CVE-2026-69151 MittelScore 0 EPSS 0.33%
Angular: Schwachstelle in der i18n-Pipeline des Compilers vor 20.3.27, 21.2.19 und 22.0.1
- CVE-2025-15628 MittelScore 0 EPSS 0.10%
TP-Link Omada: Gemeinsam genutzte eingebettete Zertifikate zwischen Controllern und Geräten
- CVE-2025-15629 MittelScore 0 EPSS 0.10%
Omada-Adoptionsprotokoll: Vorhersagbare Sitzungsschlüssel durch kryptografische Schwäche
- CVE-2025-15630 MittelScore 0 EPSS 0.19%
TP-Link Omada: Race Condition im cloudbasierten Geräte-Adoptionsprozess
- CVE-2026-46712 MittelScore 0 EPSS 0.21%
Misskey: Fehlende Berechtigungsprüfung ermöglicht Zugriff auf geschützte Inhalte
- CVE-2026-46713 MittelScore 0 EPSS 0.17%
Misskey 12.37.0 bis vor 2026.5.4: Schwachstelle bei JSON-LD-Signaturvalidierung
- CVE-2026-46714 MittelScore 0 EPSS 0.26%
Misskey: Web-Client kann durch präparierte Inhalte verlangsamt werden oder abstürzen
- CVE-2026-47746 MittelScore 0 EPSS 0.18%
Misskey: Timing-Angriffe bei JSON-LD-Signaturprüfung und Kompaktierung
- CVE-2026-48115 MittelScore 0 EPSS 0.25%
Misskey: Schwachstelle in der Server Announcements API
- CVE-2026-51190 MittelScore 0 EPSS 0.48%
Serverless-Devs @serverless-devs/s bis 3.1.11: Command Injection über „s init“
- CVE-2026-51775 MittelScore 0 EPSS 0.14%
Fastadmin: SQL-Injection in Backend.php ermöglicht Codeausführung
- CVE-2026-69243 MittelScore 0 EPSS 0.27%
aiohttp bis 3.14.1 – Request Smuggling über abgelehntes WebSocket-Upgrade
- CVE-2026-69244 MittelScore 0 EPSS 0.30%
AIOHTTP: Out-of-Bounds-Heap-Lesezugriff im C-Response-Parser
- CVE-2026-69247 MittelScore 0 EPSS 0.18%
Python cryptography-Paket: Problem in PKCS7-Entschlüsselungsfunktionen
- CVE-2026-69248 MittelScore 0 EPSS 0.18%
Python cryptography vor 49.0.0: Problem bei namensbeschränkten Zwischen-CAs
- CVE-2026-69249 MittelScore 0 EPSS 0.19%
python-cryptography: Fehlerhafte Auflösung ungültiger Zertifikatsketten mit Duplikaten
- CVE-2026-18577 Aktiv ausgenutztScore 100 EPSS 54.07%
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- CVE-2026-8457 KritischScore 59 CVSS 9.8 EPSS 0.40%
WooCommerce – Social Login (WordPress-Plugin): Authentication Bypass bis Version 2.8.7
- CVE-2026-16256 KritischScore 59 CVSS 9.8 EPSS 0.30%
POUCO Import Users: Fehlende Zugriffsprüfung bei AJAX-Aktionen zur Kontoerstellung
- CVE-2026-65321 KritischScore 59 CVSS 9.8 EPSS 0.44%
PyAthena: SQL-Injection in DefaultParameterFormatter.format()
- CVE-2026-68579 KritischScore 58 CVSS 9.6 EPSS 0.27%
FreeRDP – Heap-basierter Pufferüberlauf im Windows-Zwischenablage-Client (CliprdrStream_Read)
- CVE-2026-12586 HochScore 49 CVSS 8.1 EPSS 0.17%
Lenxel WP Theme: Fehlende Berechtigungsprüfung bei Passwort-Reset
- CVE-2026-13339 HochScore 45 CVSS 7.5 EPSS 0.64%
CubeWP Framework WordPress-Plugin: Directory Traversal via cubewp_get_svg_content
- CVE-2026-18352 HochScore 45 CVSS 7.5 EPSS 0.68%
User Access Manager (WordPress): Directory Traversal via uamgetfile-Parameter
- CVE-2026-15151 HochScore 45 CVSS 7.5 EPSS 0.23%
WordPress Five Star Restaurant Reservations: Fehlende Berechtigungsprüfung bei AJAX-Aktion
- CVE-2026-15206 HochScore 45 CVSS 7.5 EPSS 0.26%
SMS Alert (WordPress): Sitzungs-Flag nicht an verifizierte Telefonnummer gebunden
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.