Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36339
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
305
Ransomware-Bezug
6253
Kritisch

Zeige 1301 bis 1350 von 36339

  1. CVE-2025-15669 Mittel
    Score 29 CVSS 4.8 EPSS 0.17%

    Bit Form WordPress-Plugin: Ungefilterte Formulareinstellung vor Version 3.1.4

  2. CVE-2026-15601 Mittel
    Score 29 CVSS 4.9 EPSS 0.77%

    Kirki (WordPress) – Path Traversal (Zip Slip) über extract_zip_file

  3. CVE-2026-15951 Mittel
    Score 29 CVSS 4.9 EPSS 0.27%

    Icegram Mailer (WordPress): SQL Injection über den Parameter fields

  4. CVE-2026-16614 Mittel
    Score 29 CVSS 4.9 EPSS 0.27%

    GSheetConnector – CF7 Google Sheets Connector (WordPress): SQL-Injection über den Parameter s

  5. CVE-2026-17555 Mittel
    Score 29 CVSS 4.9 EPSS 0.27%

    WPvivid Backup & Migration: SQL Injection über den Parameter export_data

  6. CVE-2025-14469 Mittel
    Score 26 CVSS 4.3 EPSS 0.13%

    Theme Editor WordPress-Plugin: CSRF durch fehlende Nonce-Prüfung

  7. CVE-2026-10782 Mittel
    Score 26 CVSS 4.3 EPSS 0.29%

    RealHomes Memberships (WordPress): Autorisierungsumgehung

  8. CVE-2026-13729 Mittel
    Score 26 CVSS 4.3 EPSS 0.10%

    Podlove Podcast Publisher (WordPress): Fehlende Nonce-Validierung

  9. CVE-2026-2916 Mittel
    Score 26 CVSS 4.3 EPSS 0.22%

    Jeg Kit for Elementor: Sensitive Information Exposure über enqueue_scripts()

  10. CVE-2026-14197 Niedrig
    Score 23 CVSS 3.8 EPSS 0.15%

    Fluent Support WordPress-Plugin vor 2.3.1: Fehlende Zugriffsprüfung bei Ticket-Zuweisung

  11. CVE-2026-11882 Niedrig
    Score 22 CVSS 3.7 EPSS 0.19%

    Builderall WordPress-Plugin: OAuth-State nicht an Nutzersitzung gebunden

  12. CVE-2026-10827 Niedrig
    Score 21 CVSS 3.5 EPSS 0.11%

    Spectra Legacy WordPress-Plugin vor 2.20.0: Fehlende Validierung von Block-Style-Attributen

  13. CVE-2026-14195 Niedrig
    Score 16 CVSS 2.7 EPSS 0.17%

    Brizy WordPress-Plugin: Fehlende Autorisierungsprüfung vor Version 2.8.18

  14. CVE-2026-14214 Niedrig
    Score 16 CVSS 2.7 EPSS 0.16%

    Booking for Appointments and Events Calendar: Ungeprüfter Feldzugriff beim Kundenimport

  15. CVE-2026-14823 Niedrig
    Score 13 CVSS 2.2 EPSS 0.15%

    Event Tickets and Registration WordPress-Plugin vor 5.29.0.1: Fehlende Autorisierung bei Seating-Aktionen

  16. CVE-2026-67305 Mittel
    Score 0 EPSS 0.49%

    FreeRDP Windows-Client – Heap-Buffer-Overflow im Clipboard-Kanal

  17. CVE-2026-67309 Mittel
    Score 0 EPSS 0.49%

    Traefik Path Traversal in der Kubernetes-Ingress-NGINX-Provider RewriteTarget-Middleware

  18. CVE-2026-55734 Mittel
    Score 0 EPSS 0.13%

    überauth guardian: Denial of Service durch BEAM-Atom-Table-Erschöpfung

  19. CVE-2026-18452 Kritisch
    Score 60 CVSS 10 EPSS 0.43%

    DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials Vulnerability

  20. CVE-2026-63223 Kritisch
    Score 59 CVSS 9.8 EPSS 0.49%

    CodeIgniter: Unsichere Validierung von Datei-Upload-Endungen (is_image/mime_in)

  21. CVE-2026-14483 Kritisch
    Score 59 CVSS 9.8 EPSS 0.61%

    Realtyna Organic IDX / WPL Real Estate (WordPress-Plugins): Arbitrary File Upload

  22. CVE-2026-14919 Kritisch
    Score 59 CVSS 9.8 EPSS 0.28%

    ShopMonitor.io WordPress-Plugin: Umgehbare Trusted-Source-Prüfung im E-Mail-Rerouting-Testmodus

  23. CVE-2026-17561 Kritisch
    Score 59 CVSS 9.8 EPSS 0.31%

    Code Injection durch unzureichende Codegenerierungs-Kontrolle

  24. CVE-2026-16504 Kritisch
    Score 59 CVSS 9.8 EPSS 0.13%

    VPS.org Zulip One-Click-Template: Hartkodierter Signing-Key und Standard-Datenbankpasswort

  25. CVE-2026-17566 Kritisch
    Score 59 CVSS 9.9 EPSS 0.43%

    pgAdmin 4: Kommandozeilen-Injection im Import/Export-Tool über psql

  26. CVE-2026-52855 Kritisch
    Score 59 CVSS 9.9

    CVE-2026-52855 – Schwachstelle in Pterodactyl Wings durch {{config.}}-Platzhalter in Egg-Konfigurationsvorlagen

  27. CVE-2026-67822 Kritisch
    Score 59 CVSS 9.8

    Tenda W6-S: Stack-basierter Pufferüberlauf im wifiSSIDset-Endpunkt

  28. CVE-2025-69946 Kritisch
    Score 59 CVSS 9.8 EPSS 0.16%

    SourceCodester Modern Loan Management System: SQL-Injection in ajaxData.php

  29. CVE-2025-69948 Kritisch
    Score 59 CVSS 9.8 EPSS 0.16%

    SourceCodester Modern Loan Management System: SQL-Injection in delete_group.php

  30. CVE-2026-51785 Kritisch
    Score 59 CVSS 9.8 EPSS 0.36%

    Hiawatha (Hugo Leisink) v12.1 und früher: Remotecodeausführung über präparierte Anfrage

  31. CVE-2026-68770 Kritisch
    Score 59 CVSS 9.8 EPSS 0.52%

    sentence-transformers: Codeausführung durch Umgehung der Sicherheitskontrolle in import_module_class

  32. CVE-2026-68771 Kritisch
    Score 59 CVSS 9.8 EPSS 0.62%

    ComfyUI: Unsichere Deserialisierung im LoadTrainingDataset-Node ermöglicht Remotecodeausführung

  33. CVE-2026-52134 Kritisch
    Score 59 CVSS 9.8 EPSS 0.26%

    libiec61850 – Authentifizierungsumgehung über GOOSE-Frame in parseGoosePayload()

  34. CVE-2026-38708 Kritisch
    Score 59 CVSS 9.8 EPSS 1.21%

    TR/WR-Router-Serie: Command-Injection-Schwachstelle in mehreren Firmware-Versionen

  35. CVE-2026-38711 Kritisch
    Score 59 CVSS 9.8 EPSS 1.21%

    Command-Injection-Schwachstelle in mehreren Router-Firmware-Versionen (TR/WR-Serie)

  36. CVE-2026-38713 Kritisch
    Score 59 CVSS 9.8 EPSS 1.21%

    TR1200/TR3000/WR-Serie: Command-Injection-Schwachstelle in mehreren Router-Firmwareversionen

  37. CVE-2026-17349 Kritisch
    Score 58 CVSS 9.6 EPSS 0.30%

    pgAdmin 4 Workspaces: Klonen fremder Server-Konfigurationen über adhoc_connect_server

  38. CVE-2026-54725 Kritisch
    Score 58 CVSS 9.6

    vault-secrets-webhook: Schwachstelle in parseVaultConfig() vor Version 1.23.1

  39. CVE-2026-63221 Kritisch
    Score 56 CVSS 9.4 EPSS 0.38%

    CodeIgniter Query Builder deleteBatch() – SQL-Injection durch fehlendes Escaping gebundener Werte

  40. CVE-2025-67649 Kritisch
    Score 56 CVSS 9.3 EPSS 0.27%

    SQL-Injection in PHP Jabbers Car Rental Script

  41. CVE-2026-16503 Kritisch
    Score 55 CVSS 9.1 EPSS 0.14%

    VPS.org Supabase-Template: PostgreSQL mit Standardpasswort auf allen Netzwerkschnittstellen erreichbar

  42. CVE-2026-17351 Kritisch
    Score 54 CVSS 9 EPSS 0.45%

    pgAdmin 4 AI Assistant: Unzureichende Prüfung der SQL-Anweisung im execute_sql_query-Tool (Nachtrag zu CVE-2026-12045)

  43. CVE-2026-13609 Hoch
    Score 53 CVSS 8.8 EPSS 0.24%

    Frontend Admin by DynamiApps WordPress Plugin HTML Entity Decoding Restores Neutralized Tags

  44. CVE-2026-16236 Hoch
    Score 53 CVSS 8.8 EPSS 0.63%

    Realtyna Organic IDX Plugin für WordPress: Arbitrary File Upload bis Version 5.3.0

  45. CVE-2026-50986 Hoch
    Score 53 CVSS 8.8 EPSS 0.14%

    PrestaShop: CSRF im Zahlungsvalidierungs-Controller des Moduls totadministrativemandate

  46. CVE-2026-12721 Hoch
    Score 52 CVSS 8.6 EPSS 0.26%

    Kirki WordPress-Plugin: SQL-Injection durch unzureichende Eingabevalidierung (vor 6.0.13)

  47. CVE-2025-67650 Hoch
    Score 52 CVSS 8.6 EPSS 0.28%

    PHP Jabbers Skripte: Authentifizierte SQL-Injection

  48. CVE-2026-46593 Hoch
    Score 52 CVSS 8.6 EPSS 0.30%

    PHP Jabbers Poll Script: SQL-Injection über pjAdminPolls.controller.php

  49. CVE-2026-10079 Hoch
    Score 51 CVSS 8.5 EPSS 0.17%

    Red Hat Advanced Cluster Security – Identitätswechsel über Deployment-Metadaten

  50. CVE-2026-12251 Hoch
    Score 49 CVSS 8.1 EPSS 0.23%

    Ultimate Member WordPress Plugin Fails to Filter Administrator Capabilities from Registration Roles

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.