Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36339
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
305
Ransomware-Bezug
6253
Kritisch

Zeige 1251 bis 1300 von 36339

  1. CVE-2026-67322 Hoch
    Score 45 CVSS 7.5 EPSS 0.27%

    GitPython Umgebungsvariablen-Exfiltration in Repo.clone_from()

  2. CVE-2026-18536 Hoch
    Score 45 CVSS 7.5 EPSS 0.15%

    Data::Entropy für Perl: Bezug von Entropiequellen über unverschlüsseltes HTTP

  3. CVE-2026-13157 Hoch
    Score 43 CVSS 7.2 EPSS 0.35%

    Demo Import WordPress-Plugin bis 1.1.3: Fehlende Dateityp-Validierung beim Import

  4. CVE-2026-13158 Hoch
    Score 43 CVSS 7.2 EPSS 0.35%

    Everest Toolkit WordPress-Plugin: Fehlende Dateityp-Prüfung beim Demo-Content-Import

  5. CVE-2026-13725 Hoch
    Score 43 CVSS 7.1 EPSS 0.16%

    Dynamic Pricing With Discount Rules for WooCommerce: Fehlende Nonce-Prüfung mit reflektierter Eingabe

  6. CVE-2026-15244 Hoch
    Score 43 CVSS 7.2 EPSS 0.70%

    HUSKY WordPress-Plugin: Directory Traversal in Datei-Include-Pfad

  7. CVE-2026-15052 Hoch
    Score 43 CVSS 7.2 EPSS 0.24%

    MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder (WordPress): Gespeichertes XSS über Formularfelder

  8. CVE-2026-67326 Hoch
    Score 42 CVSS 7 EPSS 0.19%

    GitPython config_writer() – Injection von Section-Headern in .git/config

  9. CVE-2026-17605 Mittel
    Score 40 CVSS 6.6 EPSS 0.71%

    GetPaid (WordPress): Local File Inclusion über getpaid_payment_form

  10. CVE-2026-14315 Mittel
    Score 39 CVSS 6.5 EPSS 0.16%

    Pixel Tag Manager for WooCommerce WordPress-Plugin vor 2.2.1: Fehlende Autorisierung bei AJAX-Aktion

  11. CVE-2026-14561 Mittel
    Score 39 CVSS 6.5 EPSS 0.16%

    Authora WordPress-Plugin: Offenlegung des Einmal-Login-Codes

  12. CVE-2026-13329 Mittel
    Score 39 CVSS 6.5 EPSS 0.17%

    Buckaroo Woocommerce Payments (WordPress) – fehlende Berechtigungsprüfung bei AJAX-Rückerstattung

  13. CVE-2026-16087 Mittel
    Score 39 CVSS 6.5 EPSS 0.27%

    Icegram Engage – Popups, Optins, CTAs & Lead Generation (WordPress): SQL-Injection über messages[][id]

  14. CVE-2026-17580 Mittel
    Score 39 CVSS 6.5 EPSS 0.31%

    Advanced Views – Display Custom Fields: Sensitive Information Exposure

  15. CVE-2026-6453 Mittel
    Score 39 CVSS 6.5 EPSS 0.28%

    CubeWP Framework (WordPress) – SQL-Injection über cubewp_remove_relation()

  16. CVE-2026-13362 Mittel
    Score 38 CVSS 6.4 EPSS 0.20%

    WordPress SendPulse Email Marketing Newsletter: Gespeichertes Cross-Site-Scripting

  17. CVE-2026-7623 Mittel
    Score 38 CVSS 6.4 EPSS 0.21%

    SureForms (WordPress) – Gespeichertes XSS über den Parameter headingWrapper

  18. CVE-2026-13458 Mittel
    Score 38 CVSS 6.4 EPSS 0.31%

    GenerateBlocks (WordPress): Gespeichertes XSS über dynamische Tag-Injection in HTML-Attributen

  19. CVE-2026-15644 Mittel
    Score 38 CVSS 6.4 EPSS 0.21%

    Powerkit: Stored XSS über 'style'-Shortcode-Attribut

  20. CVE-2026-15645 Mittel
    Score 38 CVSS 6.4 EPSS 0.21%

    Powerkit (WordPress) – Stored Cross-Site Scripting über Shortcode-Attribut nav

  21. CVE-2026-15649 Mittel
    Score 38 CVSS 6.4 EPSS 0.20%

    Powerkit (WordPress): Stored XSS über Shortcode-Attribute

  22. CVE-2026-15662 Mittel
    Score 38 CVSS 6.4 EPSS 0.24%

    Advanced Woo Labels – Product Labels & Badges for WooCommerce (WordPress): Gespeichertes XSS über bg_color

  23. CVE-2026-15950 Mittel
    Score 38 CVSS 6.4 EPSS 0.19%

    Cozy Blocks – Page Builder: Stored XSS über 'layoutCircle.alignment'-Block-Attribut

  24. CVE-2026-16090 Mittel
    Score 38 CVSS 6.4 EPSS 0.19%

    GamiPress (WordPress) – Stored Cross-Site Scripting über Shortcode-Attribut heading_size

  25. CVE-2026-16091 Mittel
    Score 38 CVSS 6.4 EPSS 0.20%

    GamiPress (WordPress): Stored XSS über den Shortcode gamipress_rank

  26. CVE-2026-16684 Mittel
    Score 38 CVSS 6.4 EPSS 0.19%

    Easy Property Listings (WordPress): Gespeichertes XSS über das Kontaktfeld facebook

  27. CVE-2026-16685 Mittel
    Score 38 CVSS 6.4 EPSS 0.24%

    Download Manager: Stored XSS über 'icon'-Shortcode-Attribut

  28. CVE-2026-18062 Mittel
    Score 38 CVSS 6.4 EPSS 0.21%

    Kadence Blocks (WordPress) – Stored Cross-Site Scripting über Identity Block

  29. CVE-2026-18435 Mittel
    Score 38 CVSS 6.4 EPSS 0.19%

    Kadence Blocks (WordPress): Stored XSS über das Attribut toggleIcon

  30. CVE-2026-67307 Mittel
    Score 38 CVSS 6.3 EPSS 0.17%

    Wazuh Inventory-Sync FlatBuffer-Validierungsfehler

  31. CVE-2026-17571 Mittel
    Score 37 CVSS 6.1 EPSS 0.21%

    Fluent Forms (WordPress) – Reflected Cross-Site Scripting über Parameter param

  32. CVE-2026-18344 Mittel
    Score 37 CVSS 6.1 EPSS 0.22%

    WP Responsive Thumbnail Slider: Reflected XSS über den Parameter id

  33. CVE-2026-12966 Mittel
    Score 32 CVSS 5.3 EPSS 0.22%

    Direct Payments for WooCommerce WordPress-Plugin: Fehlende Eigentümerprüfung vor Version 2.5.3

  34. CVE-2026-13604 Mittel
    Score 32 CVSS 5.3 EPSS 0.17%

    Pixelavo WordPress-Plugin vor 1.5.4: Unauthentifizierte AJAX-Aktion mit öffentlich sichtbarem Nonce

  35. CVE-2026-14822 Mittel
    Score 32 CVSS 5.3 EPSS 0.18%

    Event Tickets and Registration WordPress-Plugin: Fehlende Autorisierungsprüfung vor Version 5.29.0.1

  36. CVE-2026-14840 Mittel
    Score 32 CVSS 5.3 EPSS 0.22%

    YOP Poll WordPress-Plugin: IP-Validierung über manipulierbare Forwarding-Header vor Version 7.0.6

  37. CVE-2026-15234 Mittel
    Score 32 CVSS 5.4 EPSS 0.13%

    Codeless Page Builder WordPress-Plugin bis 1.1.4: Fehlende Validierung von Shortcode-Attributen

  38. CVE-2026-15932 Mittel
    Score 32 CVSS 5.3 EPSS 0.48%

    Support Genix WordPress-Plugin vor 1.4.48: Directory Traversal im Anhang-Download

  39. CVE-2025-14073 Mittel
    Score 32 CVSS 5.3 EPSS 0.23%

    WooCommerce PayPal Payments (WordPress) – Offenlegung sensibler Daten durch IDOR

  40. CVE-2026-11995 Mittel
    Score 32 CVSS 5.3 EPSS 0.32%

    Gutena Forms (WordPress): Umgehung der Autorisierung

  41. CVE-2026-12696 Mittel
    Score 32 CVSS 5.4 EPSS 0.13%

    wpForo Forum: Unzureichende Eingabe-Bereinigung im Profilfeld

  42. CVE-2026-14292 Mittel
    Score 32 CVSS 5.4 EPSS 0.15%

    Download Manager (WordPress): Gespeichertes XSS über den Paket-Titel

  43. CVE-2026-15018 Mittel
    Score 32 CVSS 5.3 EPSS 0.27%

    Database Collation Fix (WordPress): Zeitbasierte SQL-Injection über force-collation-algorithm

  44. CVE-2026-15262 Mittel
    Score 32 CVSS 5.4 EPSS 0.13%

    Admin Columns for ACF Fields (WordPress): Fehlende Eskapierung von ACF-Werten

  45. CVE-2026-18059 Mittel
    Score 32 CVSS 5.3 EPSS 0.33%

    PixelYourSite: Sensitive Information Exposure über getWooPurchaseEventParams

  46. CVE-2026-10773 Mittel
    Score 32 CVSS 5.4 EPSS 0.18%

    Zephyr DHCPv4-Client – fehlerhafte Bounds-Prüfung in net_dhcpv4_msg_type_name()

  47. CVE-2026-67310 Mittel
    Score 32 CVSS 5.4 EPSS 0.18%

    OpenRemote Insecure Direct Object Reference im AlarmResourceImpl-Endpunkt setAssetLinks

  48. CVE-2026-67335 Mittel
    Score 32 CVSS 5.3 EPSS 0.17%

    better-auth OAuth-State-Parameter-Validierungslücke

  49. CVE-2026-67339 Mittel
    Score 32 CVSS 5.3 EPSS 0.23%

    Guzzle – Offenlegung von Proxy-Authorization-Headern in cURL-Handlern

  50. CVE-2026-15403 Mittel
    Score 29 CVSS 4.9 EPSS 0.27%

    Pinpoint Booking System – Version 2 <= 2.9.9.6.9 – Blind SQL-Injection

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.