Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36339
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
305
Ransomware-Bezug
6253
Kritisch
Zeige 1301 bis 1350 von 36339
- CVE-2025-15669 MittelScore 29 CVSS 4.8 EPSS 0.17%
Bit Form WordPress-Plugin: Ungefilterte Formulareinstellung vor Version 3.1.4
- CVE-2026-15601 MittelScore 29 CVSS 4.9 EPSS 0.77%
Kirki (WordPress) – Path Traversal (Zip Slip) über extract_zip_file
- CVE-2026-15951 MittelScore 29 CVSS 4.9 EPSS 0.27%
Icegram Mailer (WordPress): SQL Injection über den Parameter fields
- CVE-2026-16614 MittelScore 29 CVSS 4.9 EPSS 0.27%
GSheetConnector – CF7 Google Sheets Connector (WordPress): SQL-Injection über den Parameter s
- CVE-2026-17555 MittelScore 29 CVSS 4.9 EPSS 0.27%
WPvivid Backup & Migration: SQL Injection über den Parameter export_data
- CVE-2025-14469 MittelScore 26 CVSS 4.3 EPSS 0.13%
Theme Editor WordPress-Plugin: CSRF durch fehlende Nonce-Prüfung
- CVE-2026-10782 MittelScore 26 CVSS 4.3 EPSS 0.29%
RealHomes Memberships (WordPress): Autorisierungsumgehung
- CVE-2026-13729 MittelScore 26 CVSS 4.3 EPSS 0.10%
Podlove Podcast Publisher (WordPress): Fehlende Nonce-Validierung
- CVE-2026-2916 MittelScore 26 CVSS 4.3 EPSS 0.22%
Jeg Kit for Elementor: Sensitive Information Exposure über enqueue_scripts()
- CVE-2026-14197 NiedrigScore 23 CVSS 3.8 EPSS 0.15%
Fluent Support WordPress-Plugin vor 2.3.1: Fehlende Zugriffsprüfung bei Ticket-Zuweisung
- CVE-2026-11882 NiedrigScore 22 CVSS 3.7 EPSS 0.19%
Builderall WordPress-Plugin: OAuth-State nicht an Nutzersitzung gebunden
- CVE-2026-10827 NiedrigScore 21 CVSS 3.5 EPSS 0.11%
Spectra Legacy WordPress-Plugin vor 2.20.0: Fehlende Validierung von Block-Style-Attributen
- CVE-2026-14195 NiedrigScore 16 CVSS 2.7 EPSS 0.17%
Brizy WordPress-Plugin: Fehlende Autorisierungsprüfung vor Version 2.8.18
- CVE-2026-14214 NiedrigScore 16 CVSS 2.7 EPSS 0.16%
Booking for Appointments and Events Calendar: Ungeprüfter Feldzugriff beim Kundenimport
- CVE-2026-14823 NiedrigScore 13 CVSS 2.2 EPSS 0.15%
Event Tickets and Registration WordPress-Plugin vor 5.29.0.1: Fehlende Autorisierung bei Seating-Aktionen
- CVE-2026-67305 MittelScore 0 EPSS 0.49%
FreeRDP Windows-Client – Heap-Buffer-Overflow im Clipboard-Kanal
- CVE-2026-67309 MittelScore 0 EPSS 0.49%
Traefik Path Traversal in der Kubernetes-Ingress-NGINX-Provider RewriteTarget-Middleware
- CVE-2026-55734 MittelScore 0 EPSS 0.13%
überauth guardian: Denial of Service durch BEAM-Atom-Table-Erschöpfung
- CVE-2026-18452 KritischScore 60 CVSS 10 EPSS 0.43%
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials Vulnerability
- CVE-2026-63223 KritischScore 59 CVSS 9.8 EPSS 0.49%
CodeIgniter: Unsichere Validierung von Datei-Upload-Endungen (is_image/mime_in)
- CVE-2026-14483 KritischScore 59 CVSS 9.8 EPSS 0.61%
Realtyna Organic IDX / WPL Real Estate (WordPress-Plugins): Arbitrary File Upload
- CVE-2026-14919 KritischScore 59 CVSS 9.8 EPSS 0.28%
ShopMonitor.io WordPress-Plugin: Umgehbare Trusted-Source-Prüfung im E-Mail-Rerouting-Testmodus
- CVE-2026-17561 KritischScore 59 CVSS 9.8 EPSS 0.31%
Code Injection durch unzureichende Codegenerierungs-Kontrolle
- CVE-2026-16504 KritischScore 59 CVSS 9.8 EPSS 0.13%
VPS.org Zulip One-Click-Template: Hartkodierter Signing-Key und Standard-Datenbankpasswort
- CVE-2026-17566 KritischScore 59 CVSS 9.9 EPSS 0.43%
pgAdmin 4: Kommandozeilen-Injection im Import/Export-Tool über psql
- CVE-2026-52855 KritischScore 59 CVSS 9.9
CVE-2026-52855 – Schwachstelle in Pterodactyl Wings durch {{config.}}-Platzhalter in Egg-Konfigurationsvorlagen
- CVE-2026-67822 KritischScore 59 CVSS 9.8
Tenda W6-S: Stack-basierter Pufferüberlauf im wifiSSIDset-Endpunkt
- CVE-2025-69946 KritischScore 59 CVSS 9.8 EPSS 0.16%
SourceCodester Modern Loan Management System: SQL-Injection in ajaxData.php
- CVE-2025-69948 KritischScore 59 CVSS 9.8 EPSS 0.16%
SourceCodester Modern Loan Management System: SQL-Injection in delete_group.php
- CVE-2026-51785 KritischScore 59 CVSS 9.8 EPSS 0.36%
Hiawatha (Hugo Leisink) v12.1 und früher: Remotecodeausführung über präparierte Anfrage
- CVE-2026-68770 KritischScore 59 CVSS 9.8 EPSS 0.52%
sentence-transformers: Codeausführung durch Umgehung der Sicherheitskontrolle in import_module_class
- CVE-2026-68771 KritischScore 59 CVSS 9.8 EPSS 0.62%
ComfyUI: Unsichere Deserialisierung im LoadTrainingDataset-Node ermöglicht Remotecodeausführung
- CVE-2026-52134 KritischScore 59 CVSS 9.8 EPSS 0.26%
libiec61850 – Authentifizierungsumgehung über GOOSE-Frame in parseGoosePayload()
- CVE-2026-38708 KritischScore 59 CVSS 9.8 EPSS 1.21%
TR/WR-Router-Serie: Command-Injection-Schwachstelle in mehreren Firmware-Versionen
- CVE-2026-38711 KritischScore 59 CVSS 9.8 EPSS 1.21%
Command-Injection-Schwachstelle in mehreren Router-Firmware-Versionen (TR/WR-Serie)
- CVE-2026-38713 KritischScore 59 CVSS 9.8 EPSS 1.21%
TR1200/TR3000/WR-Serie: Command-Injection-Schwachstelle in mehreren Router-Firmwareversionen
- CVE-2026-17349 KritischScore 58 CVSS 9.6 EPSS 0.30%
pgAdmin 4 Workspaces: Klonen fremder Server-Konfigurationen über adhoc_connect_server
- CVE-2026-54725 KritischScore 58 CVSS 9.6
vault-secrets-webhook: Schwachstelle in parseVaultConfig() vor Version 1.23.1
- CVE-2026-63221 KritischScore 56 CVSS 9.4 EPSS 0.38%
CodeIgniter Query Builder deleteBatch() – SQL-Injection durch fehlendes Escaping gebundener Werte
- CVE-2025-67649 KritischScore 56 CVSS 9.3 EPSS 0.27%
SQL-Injection in PHP Jabbers Car Rental Script
- CVE-2026-16503 KritischScore 55 CVSS 9.1 EPSS 0.14%
VPS.org Supabase-Template: PostgreSQL mit Standardpasswort auf allen Netzwerkschnittstellen erreichbar
- CVE-2026-17351 KritischScore 54 CVSS 9 EPSS 0.45%
pgAdmin 4 AI Assistant: Unzureichende Prüfung der SQL-Anweisung im execute_sql_query-Tool (Nachtrag zu CVE-2026-12045)
- CVE-2026-13609 HochScore 53 CVSS 8.8 EPSS 0.24%
Frontend Admin by DynamiApps WordPress Plugin HTML Entity Decoding Restores Neutralized Tags
- CVE-2026-16236 HochScore 53 CVSS 8.8 EPSS 0.63%
Realtyna Organic IDX Plugin für WordPress: Arbitrary File Upload bis Version 5.3.0
- CVE-2026-50986 HochScore 53 CVSS 8.8 EPSS 0.14%
PrestaShop: CSRF im Zahlungsvalidierungs-Controller des Moduls totadministrativemandate
- CVE-2026-12721 HochScore 52 CVSS 8.6 EPSS 0.26%
Kirki WordPress-Plugin: SQL-Injection durch unzureichende Eingabevalidierung (vor 6.0.13)
- CVE-2025-67650 HochScore 52 CVSS 8.6 EPSS 0.28%
PHP Jabbers Skripte: Authentifizierte SQL-Injection
- CVE-2026-46593 HochScore 52 CVSS 8.6 EPSS 0.30%
PHP Jabbers Poll Script: SQL-Injection über pjAdminPolls.controller.php
- CVE-2026-10079 HochScore 51 CVSS 8.5 EPSS 0.17%
Red Hat Advanced Cluster Security – Identitätswechsel über Deployment-Metadaten
- CVE-2026-12251 HochScore 49 CVSS 8.1 EPSS 0.23%
Ultimate Member WordPress Plugin Fails to Filter Administrator Capabilities from Registration Roles
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.