Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 1151 bis 1200 von 36300
- CVE-2026-15236 HochScore 45 CVSS 7.5 EPSS 0.28%
Gallery for Google Photos: Offenlegung gespeicherter OAuth-Zugangsdaten
- CVE-2026-15241 HochScore 45 CVSS 7.5 EPSS 0.26%
AI ChatBot for WooCommerce: Fehlende Autorisierungsprüfung bei AJAX-Aktion
- CVE-2026-16261 HochScore 45 CVSS 7.5 EPSS 0.33%
WordPress login-social: Fehlende Validierung von Passwort-Reset-Anfragen
- CVE-2026-16285 HochScore 45 CVSS 7.5 EPSS 0.26%
Product Attachment for WooCommerce: Fehlende Autorisierungsprüfung beim Dateidownload
- CVE-2026-16540 HochScore 45 CVSS 7.5 EPSS 0.42%
Simply Schedule Appointments (WordPress): Fehlende Zugriffsbeschränkung bei Bulk-Terminabfrage
- CVE-2025-71400 HochScore 43 CVSS 7.1 EPSS 0.20%
better-auth Passkey: Insecure Direct Object Reference bei der Löschung
- CVE-2026-10848 HochScore 42 CVSS 7 EPSS 0.19%
OCPP-1.6-Client: Unsichere String-Kopie beim Parsen von WAMP-RPC-Frames
- CVE-2026-14817 MittelScore 41 CVSS 6.8 EPSS 0.28%
WordPress Element Pack Addons for Elementor: Unsanitisierte Datenattribute
- CVE-2026-16062 MittelScore 40 CVSS 6.6 EPSS 0.34%
WordPress Event Booking Manager for WooCommerce: Unsichere Deserialisierung
- CVE-2026-18571 MittelScore 40 CVSS 6.6 EPSS 0.24%
Keycloak: Rechteausweitung bei Benutzererstellung mit Fine-Grained Admin Permissions V2
- CVE-2026-13389 MittelScore 39 CVSS 6.5 EPSS 0.29%
WebToffee Cookie Consent: Fehlende Autorisierung bei REST-API-Routen
- CVE-2026-18572 MittelScore 39 CVSS 6.5 EPSS 0.20%
Keycloak: Schwachstelle bei zeitbasierten Autorisierungsrichtlinien
- CVE-2026-18573 MittelScore 39 CVSS 6.5 EPSS 0.25%
Keycloak: Schwachstelle in keycloak-services bei Client-Policy-Konfiguration
- CVE-2026-9335 MittelScore 39 CVSS 6.5 EPSS 0.65%
Keras: Offenlegung von HDF5-Dateiinhalten über ExternalLinks
- CVE-2026-68582 MittelScore 39 CVSS 6.5 EPSS 0.21%
Vikunja: Broken Object Level Authorization im Task-Collection-Endpunkt
- CVE-2026-12231 MittelScore 38 CVSS 6.4 EPSS 0.26%
Exclusive Addons for Elementor: Stored Cross-Site Scripting
- CVE-2026-14841 MittelScore 37 CVSS 6.1 EPSS 0.18%
King Addons for Elementor (WordPress): Fehlendes Escaping einer Grid-Einstellung in AJAX-Antwort
- CVE-2026-15248 MittelScore 33 CVSS 5.5 EPSS 0.28%
WordPress Meta Box: Fehlende Berechtigungsprüfung beim Löschen von Anhängen
- CVE-2026-14864 MittelScore 32 CVSS 5.4 EPSS 0.13%
JetEngine: Stored-XSS über Post-Meta-Wert in Shortcode
- CVE-2026-15385 MittelScore 32 CVSS 5.4 EPSS 0.13%
RT Mega Menu (WordPress): Fehlende Berechtigungsprüfung bei AJAX-Konfigurationsspeicherung
- CVE-2026-16063 MittelScore 32 CVSS 5.4 EPSS 0.13%
Event Booking Manager for WooCommerce (WordPress): Fehlendes Escaping bei Event-Timeline-Inhalten
- CVE-2026-16064 MittelScore 32 CVSS 5.4 EPSS 0.14%
Event Booking Manager for WooCommerce: Unzureichende Autorisierungsprüfung beim Quick-Edit
- CVE-2026-16292 MittelScore 32 CVSS 5.4 EPSS 0.09%
WordPress Frontend File Manager: Fehlende Nonce-Prüfung bei Datei-Metadaten
- CVE-2026-18570 MittelScore 32 CVSS 5.4 EPSS 0.15%
Keycloak: Schwachstelle im full-scope-disabled Client-Policy-Executor
- CVE-2026-68583 MittelScore 32 CVSS 5.4 EPSS 0.14%
OpenWrt luci-app-adblock-fast: Gespeichertes XSS im Blocklist-Namen
- CVE-2025-15675 MittelScore 29 CVSS 4.8 EPSS 0.17%
WordPress Charitable: Fehlende Bereinigung eines Kampagnenbild-Textfelds
- CVE-2026-16273 MittelScore 28 CVSS 4.6 EPSS 0.13%
Narrative Publisher (WordPress): Ungesicherter Schreibzugriff auf REST-Metafeld
- CVE-2026-11872 MittelScore 26 CVSS 4.3 EPSS 0.18%
Clever Mega Menu for Visual Composer (WordPress): Fehlende Nonce-/Berechtigungsprüfung bei Menü-Metadaten
- CVE-2026-14938 MittelScore 26 CVSS 4.3 EPSS 0.16%
FluentBoards: Fehlende Berechtigungsprüfung beim Board-Import
- CVE-2026-16042 MittelScore 26 CVSS 4.3 EPSS 0.19%
LWS Optimize: Fehlende Berechtigungsprüfung beim Leeren des Caches
- CVE-2026-16291 MittelScore 26 CVSS 4.3 EPSS 0.15%
ProfileGrid: Fehlende Berechtigungsprüfung beim Löschen von Benachrichtigungen
- CVE-2026-15939 NiedrigScore 16 CVSS 2.7 EPSS 0.18%
Simple Restrict: Fehlende Berechtigungsprüfung der REST API
- CVE-2026-10774 NiedrigScore 14 CVSS 2.4 EPSS 0.15%
Zephyr Bluetooth Mesh: PSA-Crypto-Key-Leck beim Subnet-Key-Teardown
- CVE-2026-18556 Hoch Aktiv ausgenutztScore 100 CVSS 7.4 EPSS 40.16%
N-able N-central – Authentication Bypass über einen alternativen Pfad
- CVE-2026-67308 KritischScore 60 CVSS 10 EPSS 0.45%
Wazuh GitHub Actions Workflow Shell-Injection
- CVE-2026-15964 KritischScore 59 CVSS 9.8 EPSS 0.49%
Single Sign On For TNG (WordPress): Authentifizierungsumgehung via Passwort-Reset
- CVE-2026-67289 KritischScore 59 CVSS 9.8 EPSS 0.38%
FreeRDP – fehlende Validierung von CRLF-Zeichen im RDP-Redirection-Feld TargetNetAddress
- CVE-2026-67324 KritischScore 59 CVSS 9.8 EPSS 0.38%
GitPython Unsafe-Option-Gate-Umgehung durch zusammengesetzte Kurzoptionen
- CVE-2026-67330 KritischScore 59 CVSS 9.9 EPSS 0.35%
@better-auth/scim Autorisierungsumgehung bei SCIM-Token-Ausstellung
- CVE-2026-67340 KritischScore 59 CVSS 9.8 EPSS 0.61%
ArcadeDB Trigger-Skript Java.lang Sandbox-Umgehung
- CVE-2026-67342 KritischScore 59 CVSS 9.8 EPSS 0.32%
ArcadeDB – Autorisierungsumgehung in HTTP-Handlern für Grafana-Endpunkte
- CVE-2026-66402 KritischScore 59 CVSS 9.8 EPSS 0.29%
FreeRDP: Mehrere Schwachstellen bei der TLS-Zertifikatsvalidierung
- CVE-2026-67341 KritischScore 59 CVSS 9.8 EPSS 0.32%
ArcadeDB – fehlende Autorisierungsprüfung bei SQL DEFINE FUNCTION (JavaScript)
- CVE-2026-3141 KritischScore 55 CVSS 9.1 EPSS 0.47%
FormGent (WordPress-Plugin) – Unautorisierte Löschung beliebiger Dateien via REST-API
- CVE-2026-13596 KritischScore 55 CVSS 9.1 EPSS 0.26%
Participants Database WordPress-Plugin: SQL-Injection vor Version 2.7.8.4
- CVE-2026-15414 HochScore 53 CVSS 8.8 EPSS 0.34%
Subscriptions for WooCommerce <= 2.0.0 – Privilegien-Eskalation
- CVE-2026-15988 HochScore 53 CVSS 8.8 EPSS 0.22%
AI Engine WordPress-Plugin: Cross-Site-Request-Forgery bis Version 3.6.5
- CVE-2026-14596 HochScore 53 CVSS 8.8 EPSS 0.22%
DynamicKit for Elementor: Fehlende Host-Validierung im Passwort-Reset-Link
- CVE-2026-16635 HochScore 53 CVSS 8.8 EPSS 0.31%
Pronamic Pay (WordPress): Privilege Escalation über maybe_update_user_role()
- CVE-2026-67325 HochScore 53 CVSS 8.8 EPSS 1.48%
GitPython unvollständige Command-Injection-Sperrliste bei Long-Option-Abkürzungen
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.