Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36339
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
305
Ransomware-Bezug
6253
Kritisch
Zeige 1351 bis 1400 von 36339
- CVE-2026-12695 HochScore 49 CVSS 8.1 EPSS 0.29%
miniOrange 2FA für WordPress: Fehlerhafte OTP-Validierung vor Version 6.2.6
- CVE-2026-15258 HochScore 49 CVSS 8.1 EPSS 0.21%
Product Feed Manager für WooCommerce: SQL-Injection vor Version 7.6.1
- CVE-2026-56670 HochScore 49 CVSS 8.2 EPSS 0.22%
ComfyUI: SVG-Dateien im /view-Endpoint werden inline ausgeliefert (vor 0.28.0)
- CVE-2026-18141 HochScore 49 CVSS 8.2 EPSS 0.25%
Ansible Automation Platform: mTLS-Authentifizierungsumgehung im aap-gateway (EDA)
- CVE-2026-53501 HochScore 49 CVSS 8.2
Thumbor: HMAC-Signaturprüfung durch Python .replace() umgehbar
- CVE-2026-53510 HochScore 49 CVSS 8.1
Savon Ruby SOAP Client: Code-Ausführung über all_operations bei manipulierten WSDL-Operationsnamen
- CVE-2026-17583 HochScore 49 CVSS 8.2
Thermo Fisher: Forensische .fsa/.hid-Dateien von DNA-Identifikationsgeräten ohne Manipulationsschutz
- CVE-2026-34641 HochScore 47 CVSS 7.8 EPSS 0.14%
Premiere Pro: Out-of-Bounds-Write-Schwachstelle ermöglicht Codeausführung
- CVE-2026-43829 HochScore 45 CVSS 7.5 EPSS 0.24%
Stack-basierter Pufferüberlauf in der Passwort-Funktionalität
- CVE-2026-43831 HochScore 45 CVSS 7.5 EPSS 0.24%
Caddy: Stack-Based Buffer Overflow in der Log-Message-Funktionalität
- CVE-2026-43832 HochScore 45 CVSS 7.5 EPSS 0.24%
Caddy: Stapelbasierter Bufferoverflow beim Cookie-Parsing
- CVE-2026-63222 HochScore 45 CVSS 7.5 EPSS 0.45%
CodeIgniter UploadedFile::move() verwendet ungefilterten Dateinamen
- CVE-2026-12720 HochScore 45 CVSS 7.5 EPSS 0.38%
Kirki WordPress Plugin PHP Object Injection via Unrestricted Deserialization
- CVE-2026-14319 HochScore 45 CVSS 7.5 EPSS 0.32%
GiveWP für WordPress: Unzureichender Zugriffsschutz auf REST-API vor Version 4.16.3
- CVE-2026-14333 HochScore 45 CVSS 7.5 EPSS 0.30%
Demi (WordPress-Plugin): Ungeschützte Backup-Archive öffentlich zugänglich
- CVE-2026-14830 HochScore 45 CVSS 7.5 EPSS 0.21%
FlxWoo WordPress-Plugin: Fehlende Zahlungsverifikation ermöglicht Markierung unbezahlter Bestellungen als bezahlt (vor 3.1.1)
- CVE-2026-14930 HochScore 45 CVSS 7.5 EPSS 0.24%
JS Help Desk für WordPress: Datei-Upload ohne Authentifizierung vor Version 3.1.4
- CVE-2026-15048 HochScore 45 CVSS 7.5 EPSS 0.26%
Geeky Bot WordPress Plugin Missing Authorization Check on AJAX Action
- CVE-2026-65309 HochScore 45 CVSS 7.5 EPSS 0.15%
CVE-2026-65309 – Sicherheitslücke in Omnissa Workspace ONE Horizon
- CVE-2026-65310 HochScore 45 CVSS 7.5 EPSS 0.32%
ANDRITZ HIPASE-250: Fehlende Authentifizierung und permissives CORS am Daten-/Konfigurationsendpunkt
- CVE-2026-11770 HochScore 45 CVSS 7.5 EPSS 0.69%
389 Directory Server – LDAP-Filter-Injection in Replikationsstatusprüfung
- CVE-2026-18358 HochScore 45 CVSS 7.5 EPSS 0.43%
gnome-remote-desktop: Umgehung der Verbindungsprüfung im RDP-Systemdienst
- CVE-2026-53503 HochScore 45 CVSS 7.5
Thumbor: Ungeprüfter Columns-Parameter im convolution-Filter
- CVE-2026-53599 HochScore 45 CVSS 7.5
REDAXO: Umgehung der Dateiendungsprüfung in rex_mediapool::isAllowedExtension (5.18.2–5.21.1)
- CVE-2026-18481 HochScore 44 CVSS 7.3 EPSS 0.28%
AWS Ops Wheel: Gespeichertes XSS in der Participant-URL-Verarbeitung vor PR #168
- CVE-2026-18394 HochScore 44 CVSS 7.4 EPSS 0.29%
Strands Agents Tools: Fehlerhafte Autorisierung im http_request-Tool ermöglicht Preisgabe konfigurierter Credentials
- CVE-2026-13392 HochScore 43 CVSS 7.2 EPSS 0.36%
ElementsKit Elementor Addons für WordPress: Schwachstelle in Custom-Widget-Verarbeitung vor Version 3.10.01
- CVE-2026-16843 HochScore 43 CVSS 7.2 EPSS 0.46%
Hikvision Wireless Access Points: authentifizierte Command Execution
- CVE-2026-18214 MittelScore 41 CVSS 6.8 EPSS 0.20%
Keycloak: Schwachstelle im Token-Exchange-Feature bei Google-Workspace-Anmeldung
- CVE-2026-18215 MittelScore 41 CVSS 6.8 EPSS 0.19%
Keycloak: Organisationsbeschränkung bei Microsoft-Login umgehbar
- CVE-2025-67651 MittelScore 41 CVSS 6.9 EPSS 0.17%
Cross-Site-Request-Forgery in mehreren PHP-Jabbers-Skripten
- CVE-2026-55497 MittelScore 39 CVSS 6.5 EPSS 0.53%
Cloudreve: Fehlende Pixel-Grössenbegrenzung in Thumbnail-/Avatar-Decodern
- CVE-2026-14554 MittelScore 39 CVSS 6.5 EPSS 0.22%
Check & Log Email für WordPress: SQL-Injection durch Administratoren (vor 2.0.15)
- CVE-2026-14834 MittelScore 39 CVSS 6.5 EPSS 0.16%
Mailgun for WordPress: Fehlende Berechtigungsprüfung bei AJAX-Aktion
- CVE-2026-14928 MittelScore 39 CVSS 6.5 EPSS 0.22%
JS Help Desk WordPress Plugin Missing Authorization and Ownership Checks
- CVE-2026-14931 MittelScore 39 CVSS 6.5 EPSS 0.22%
JS Help Desk (WordPress-Plugin): Fehlende Berechtigungsprüfung ermöglicht Rechteausweitung
- CVE-2026-15209 MittelScore 39 CVSS 6.5 EPSS 0.20%
JS Help Desk für WordPress: Fehlende Besitzprüfung ermöglicht Zugriff auf fremde Tickets (vor 3.1.5)
- CVE-2026-18203 MittelScore 39 CVSS 6.5 EPSS 0.20%
Keycloak: Fehlerhafte Rechteausweitung bei Gruppenrichtlinien-Vererbung
- CVE-2026-18208 MittelScore 39 CVSS 6.5 EPSS 0.22%
Keycloak: Schwachstelle im OIDC-Token-Introspection-Endpunkt (keycloak-services)
- CVE-2026-17348 MittelScore 39 CVSS 6.5 EPSS 0.25%
pgAdmin 4: Fehlende Authentifizierungsprüfung durch unvollständigen before_request-Hook
- CVE-2026-14845 MittelScore 37 CVSS 6.1 EPSS 0.16%
NewStatPress WordPress-Plugin: Gespeichertes XSS über unauthentifizierte Besucheranfragen (vor 1.4.5)
- CVE-2026-14921 MittelScore 37 CVSS 6.1 EPSS 0.15%
Ultimate Addons for WPBakery Page Builder: Schwachstelle in Link-Rendering-Funktion vor Version 3.21.5
- CVE-2026-10686 MittelScore 35 CVSS 5.8 EPSS 0.25%
Zephyr RTOS: IPv6-Forwarding dekrementiert Hop Limit nicht
- CVE-2026-67607 MittelScore 35 CVSS 5.9 EPSS 0.28%
LightFTP 2.3.1: Race Condition beim FTP-Verbindungsaufbau führt zu Server-Absturz
- CVE-2026-43833 MittelScore 32 CVSS 5.3 EPSS 0.20%
Caddy – Stack-based Buffer Overflow in der Upload-Funktion
- CVE-2026-12697 MittelScore 32 CVSS 5.4 EPSS 0.17%
wpForo Forum (WordPress-Plugin): Fehlende Eigentümerprüfung beim Löschen von KI-Chat-Nachrichten
- CVE-2026-8155 MittelScore 32 CVSS 5.4 EPSS 0.14%
BuddyPress WordPress Plugin Missing Authorization on Private Messaging Endpoints
- CVE-2026-65311 MittelScore 32 CVSS 5.3 EPSS 0.27%
ANDRITZ HIPASE-250: Unauthentifizierter Zugriff auf Logging-Konfiguration
- CVE-2026-18436 MittelScore 32 CVSS 5.3 EPSS 0.23%
CVE-2026-18436 – Unautorisierter Zugriff im WordPress-Plugin MailPress über REST-Endpunkt zur Kampagnen-Revision-Wiederherstellung
- CVE-2026-18437 MittelScore 32 CVSS 5.3 EPSS 0.30%
MailerPress: Fehlende Berechtigungsprüfung am Contact-Endpunkt
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.