Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36339
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
305
Ransomware-Bezug
6253
Kritisch
Zeige 1251 bis 1300 von 36339
- CVE-2026-67322 HochScore 45 CVSS 7.5 EPSS 0.27%
GitPython Umgebungsvariablen-Exfiltration in Repo.clone_from()
- CVE-2026-18536 HochScore 45 CVSS 7.5 EPSS 0.15%
Data::Entropy für Perl: Bezug von Entropiequellen über unverschlüsseltes HTTP
- CVE-2026-13157 HochScore 43 CVSS 7.2 EPSS 0.35%
Demo Import WordPress-Plugin bis 1.1.3: Fehlende Dateityp-Validierung beim Import
- CVE-2026-13158 HochScore 43 CVSS 7.2 EPSS 0.35%
Everest Toolkit WordPress-Plugin: Fehlende Dateityp-Prüfung beim Demo-Content-Import
- CVE-2026-13725 HochScore 43 CVSS 7.1 EPSS 0.16%
Dynamic Pricing With Discount Rules for WooCommerce: Fehlende Nonce-Prüfung mit reflektierter Eingabe
- CVE-2026-15244 HochScore 43 CVSS 7.2 EPSS 0.70%
HUSKY WordPress-Plugin: Directory Traversal in Datei-Include-Pfad
- CVE-2026-15052 HochScore 43 CVSS 7.2 EPSS 0.24%
MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder (WordPress): Gespeichertes XSS über Formularfelder
- CVE-2026-67326 HochScore 42 CVSS 7 EPSS 0.19%
GitPython config_writer() – Injection von Section-Headern in .git/config
- CVE-2026-17605 MittelScore 40 CVSS 6.6 EPSS 0.71%
GetPaid (WordPress): Local File Inclusion über getpaid_payment_form
- CVE-2026-14315 MittelScore 39 CVSS 6.5 EPSS 0.16%
Pixel Tag Manager for WooCommerce WordPress-Plugin vor 2.2.1: Fehlende Autorisierung bei AJAX-Aktion
- CVE-2026-14561 MittelScore 39 CVSS 6.5 EPSS 0.16%
Authora WordPress-Plugin: Offenlegung des Einmal-Login-Codes
- CVE-2026-13329 MittelScore 39 CVSS 6.5 EPSS 0.17%
Buckaroo Woocommerce Payments (WordPress) – fehlende Berechtigungsprüfung bei AJAX-Rückerstattung
- CVE-2026-16087 MittelScore 39 CVSS 6.5 EPSS 0.27%
Icegram Engage – Popups, Optins, CTAs & Lead Generation (WordPress): SQL-Injection über messages[][id]
- CVE-2026-17580 MittelScore 39 CVSS 6.5 EPSS 0.31%
Advanced Views – Display Custom Fields: Sensitive Information Exposure
- CVE-2026-6453 MittelScore 39 CVSS 6.5 EPSS 0.28%
CubeWP Framework (WordPress) – SQL-Injection über cubewp_remove_relation()
- CVE-2026-13362 MittelScore 38 CVSS 6.4 EPSS 0.20%
WordPress SendPulse Email Marketing Newsletter: Gespeichertes Cross-Site-Scripting
- CVE-2026-7623 MittelScore 38 CVSS 6.4 EPSS 0.21%
SureForms (WordPress) – Gespeichertes XSS über den Parameter headingWrapper
- CVE-2026-13458 MittelScore 38 CVSS 6.4 EPSS 0.31%
GenerateBlocks (WordPress): Gespeichertes XSS über dynamische Tag-Injection in HTML-Attributen
- CVE-2026-15644 MittelScore 38 CVSS 6.4 EPSS 0.21%
Powerkit: Stored XSS über 'style'-Shortcode-Attribut
- CVE-2026-15645 MittelScore 38 CVSS 6.4 EPSS 0.21%
Powerkit (WordPress) – Stored Cross-Site Scripting über Shortcode-Attribut nav
- CVE-2026-15649 MittelScore 38 CVSS 6.4 EPSS 0.20%
Powerkit (WordPress): Stored XSS über Shortcode-Attribute
- CVE-2026-15662 MittelScore 38 CVSS 6.4 EPSS 0.24%
Advanced Woo Labels – Product Labels & Badges for WooCommerce (WordPress): Gespeichertes XSS über bg_color
- CVE-2026-15950 MittelScore 38 CVSS 6.4 EPSS 0.19%
Cozy Blocks – Page Builder: Stored XSS über 'layoutCircle.alignment'-Block-Attribut
- CVE-2026-16090 MittelScore 38 CVSS 6.4 EPSS 0.19%
GamiPress (WordPress) – Stored Cross-Site Scripting über Shortcode-Attribut heading_size
- CVE-2026-16091 MittelScore 38 CVSS 6.4 EPSS 0.20%
GamiPress (WordPress): Stored XSS über den Shortcode gamipress_rank
- CVE-2026-16684 MittelScore 38 CVSS 6.4 EPSS 0.19%
Easy Property Listings (WordPress): Gespeichertes XSS über das Kontaktfeld facebook
- CVE-2026-16685 MittelScore 38 CVSS 6.4 EPSS 0.24%
Download Manager: Stored XSS über 'icon'-Shortcode-Attribut
- CVE-2026-18062 MittelScore 38 CVSS 6.4 EPSS 0.21%
Kadence Blocks (WordPress) – Stored Cross-Site Scripting über Identity Block
- CVE-2026-18435 MittelScore 38 CVSS 6.4 EPSS 0.19%
Kadence Blocks (WordPress): Stored XSS über das Attribut toggleIcon
- CVE-2026-67307 MittelScore 38 CVSS 6.3 EPSS 0.17%
Wazuh Inventory-Sync FlatBuffer-Validierungsfehler
- CVE-2026-17571 MittelScore 37 CVSS 6.1 EPSS 0.21%
Fluent Forms (WordPress) – Reflected Cross-Site Scripting über Parameter param
- CVE-2026-18344 MittelScore 37 CVSS 6.1 EPSS 0.22%
WP Responsive Thumbnail Slider: Reflected XSS über den Parameter id
- CVE-2026-12966 MittelScore 32 CVSS 5.3 EPSS 0.22%
Direct Payments for WooCommerce WordPress-Plugin: Fehlende Eigentümerprüfung vor Version 2.5.3
- CVE-2026-13604 MittelScore 32 CVSS 5.3 EPSS 0.17%
Pixelavo WordPress-Plugin vor 1.5.4: Unauthentifizierte AJAX-Aktion mit öffentlich sichtbarem Nonce
- CVE-2026-14822 MittelScore 32 CVSS 5.3 EPSS 0.18%
Event Tickets and Registration WordPress-Plugin: Fehlende Autorisierungsprüfung vor Version 5.29.0.1
- CVE-2026-14840 MittelScore 32 CVSS 5.3 EPSS 0.22%
YOP Poll WordPress-Plugin: IP-Validierung über manipulierbare Forwarding-Header vor Version 7.0.6
- CVE-2026-15234 MittelScore 32 CVSS 5.4 EPSS 0.13%
Codeless Page Builder WordPress-Plugin bis 1.1.4: Fehlende Validierung von Shortcode-Attributen
- CVE-2026-15932 MittelScore 32 CVSS 5.3 EPSS 0.48%
Support Genix WordPress-Plugin vor 1.4.48: Directory Traversal im Anhang-Download
- CVE-2025-14073 MittelScore 32 CVSS 5.3 EPSS 0.23%
WooCommerce PayPal Payments (WordPress) – Offenlegung sensibler Daten durch IDOR
- CVE-2026-11995 MittelScore 32 CVSS 5.3 EPSS 0.32%
Gutena Forms (WordPress): Umgehung der Autorisierung
- CVE-2026-12696 MittelScore 32 CVSS 5.4 EPSS 0.13%
wpForo Forum: Unzureichende Eingabe-Bereinigung im Profilfeld
- CVE-2026-14292 MittelScore 32 CVSS 5.4 EPSS 0.15%
Download Manager (WordPress): Gespeichertes XSS über den Paket-Titel
- CVE-2026-15018 MittelScore 32 CVSS 5.3 EPSS 0.27%
Database Collation Fix (WordPress): Zeitbasierte SQL-Injection über force-collation-algorithm
- CVE-2026-15262 MittelScore 32 CVSS 5.4 EPSS 0.13%
Admin Columns for ACF Fields (WordPress): Fehlende Eskapierung von ACF-Werten
- CVE-2026-18059 MittelScore 32 CVSS 5.3 EPSS 0.33%
PixelYourSite: Sensitive Information Exposure über getWooPurchaseEventParams
- CVE-2026-10773 MittelScore 32 CVSS 5.4 EPSS 0.18%
Zephyr DHCPv4-Client – fehlerhafte Bounds-Prüfung in net_dhcpv4_msg_type_name()
- CVE-2026-67310 MittelScore 32 CVSS 5.4 EPSS 0.18%
OpenRemote Insecure Direct Object Reference im AlarmResourceImpl-Endpunkt setAssetLinks
- CVE-2026-67335 MittelScore 32 CVSS 5.3 EPSS 0.17%
better-auth OAuth-State-Parameter-Validierungslücke
- CVE-2026-67339 MittelScore 32 CVSS 5.3 EPSS 0.23%
Guzzle – Offenlegung von Proxy-Authorization-Headern in cURL-Handlern
- CVE-2026-15403 MittelScore 29 CVSS 4.9 EPSS 0.27%
Pinpoint Booking System – Version 2 <= 2.9.9.6.9 – Blind SQL-Injection
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.