Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 101 bis 150 von 36300

  1. CVE-2026-78166 Mittel
    Score 38 CVSS 6.3 EPSS 0.30%

    kafka-ui – Schwachstelle in executeSmartFilterTest

  2. CVE-2026-78185 Mittel
    Score 38 CVSS 6.3 EPSS 0.25%

    itsourcecode Sales and Inventory System 1.0 – Schwachstelle in cust_edit.php

  3. CVE-2026-19852 Mittel
    Score 37 CVSS 6.1 EPSS 0.23%

    NewSiteServer (NSS) – Arbitrary File Upload

  4. CVE-2026-19853 Mittel
    Score 32 CVSS 5.3 EPSS 0.34%

    NewSiteServer (NSS) – Missing Authentication

  5. CVE-2026-78148 Mittel
    Score 32 CVSS 5.3 EPSS 0.54%

    llama.cpp (ggml-org) – Schwachstelle im ggml-RPC-Server (rpc_server::graph_compute)

  6. CVE-2026-78196 Mittel
    Score 26 CVSS 4.4 EPSS 0.14%

    achorein expo-share-intent – Schwachstelle in der Android File Copy Routine

  7. CVE-2026-5388 Kritisch
    Score 59 CVSS 9.8 EPSS 0.34%

    justhtml – mehrere Sicherheitsprobleme in URL-Sanitisierung und Markdown-Passthrough

  8. CVE-2026-7808 Kritisch
    Score 59 CVSS 9.8 EPSS 0.35%

    justhtml vor 1.16.0 – Mehrere HTML-Sanitisierungs-Bypässe (Cross-Site-Scripting)

  9. CVE-2026-78155 Kritisch
    Score 59 CVSS 9.9 EPSS 0.27%

    StackGres Operator – Rechteausweitung für datenbankbesitzende Mandanten

  10. CVE-2026-8445 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    justhtml – unzureichende HTML-Maskierung bei Markdown-Konvertierung

  11. CVE-2026-10053 Hoch
    Score 51 CVSS 8.5 EPSS 0.72%

    GitLab CE/EE – behobene Schwachstelle in mehreren Versionszweigen

  12. CVE-2026-4671 Hoch
    Score 45 CVSS 7.5 EPSS 0.37%

    justhtml – Denial-of-Service in der CSS-Selektor-Verarbeitung und Linkifizierung

  13. CVE-2026-78143 Hoch
    Score 44 CVSS 7.3 EPSS 0.26%

    Barangay Resident Profiling Management System – Schwachstelle in residents.php

  14. CVE-2026-78147 Hoch
    Score 44 CVSS 7.3 EPSS 0.43%

    llama.cpp ggml-RPC Server – Schwachstelle in deserialize_tensor

  15. CVE-2026-77115 Hoch
    Score 43 CVSS 7.1 EPSS 0.15%

    Brave Popup Builder bis 0.8.5 – Reflected Cross-Site-Scripting über UTM-Parameter

  16. CVE-2026-78112 Mittel
    Score 38 CVSS 6.3 EPSS 0.25%

    itsourcecode Hospital Management System – Schwachstelle in viewservicetype.php

  17. CVE-2026-78142 Mittel
    Score 38 CVSS 6.3 EPSS 0.22%

    Barangay Resident Profiling Management System – Schwachstelle in archived_records.php

  18. CVE-2026-78144 Mittel
    Score 38 CVSS 6.3 EPSS 0.29%

    code-projects Barangay Resident Profiling Management System 1.0 – Schwachstelle in boarders.php

  19. CVE-2026-77088 Mittel
    Score 37 CVSS 6.1 EPSS 0.19%

    justhtml 0.9.0 bis 1.21.0 – Cross-Site-Scripting in to_markdown()

  20. CVE-2026-78115 Mittel
    Score 32 CVSS 5.4 EPSS 0.30%

    SourceCodester Class and Exam Timetabling System – Schwachstelle in edit_user_account.php

  21. CVE-2026-78140 Mittel
    Score 28 CVSS 4.7 EPSS 0.24%

    Dromara UJCMS – Schwachstelle in WebFileTemplateController.update

  22. CVE-2026-19883 Hoch
    Score 53 CVSS 8.8 EPSS 0.37%

    WordPress-Plugin WPeMatico RSS Feed Fetcher – Fehlende Capability-Prüfung ermöglicht Rechteausweitung

  23. CVE-2026-61539 Kritisch
    Score 60 CVSS 10 EPSS 0.66%

    Xinference Code Injection via eval() on Llama3 Tool-Call Output

  24. CVE-2026-69502 Kritisch
    Score 60 CVSS 10 EPSS 0.58%

    Azure SQL Database – SSRF-Schwachstelle mit Rechteausweitung

  25. CVE-2026-69836 Kritisch
    Score 60 CVSS 10

    Microsoft Entra ID – Unauthentifizierte Deserialisierungs-RCE

  26. CVE-2026-77649 Kritisch
    Score 59 CVSS 9.8 EPSS 0.43%

    The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control

  27. CVE-2026-77651 Kritisch
    Score 59 CVSS 9.8 EPSS 0.43%

    arrayref crate 0.3.10 (Rust) – Schadcode-Ausführung durch Rogue Dependency

  28. CVE-2026-48749 Kritisch
    Score 59 CVSS 9.9

    Incus – Arbiträrer Dateizugriff auf dem Host über präpariertes Image

  29. CVE-2026-48750 Kritisch
    Score 59 CVSS 9.9 EPSS 0.78%

    Incus Exec Endpoint Output Exposure via record-output Parameter

  30. CVE-2026-48751 Kritisch
    Score 59 CVSS 9.9

    Incus – Snapshot-Restriction-Bypass ermöglicht Codeausführung

  31. CVE-2026-48753 Kritisch
    Score 59 CVSS 9.9

    Incus – Path Traversal im S3-Upload-Endpunkt (vor 7.1.0)

  32. CVE-2026-48755 Kritisch
    Score 59 CVSS 9.9

    Incus – Argument-Injection über Backup-Kompressionsalgorithmus

  33. CVE-2026-62283 Kritisch
    Score 59 CVSS 9.9

    Nezha Monitoring Stream Identifier Vulnerability

  34. CVE-2026-62867 Kritisch
    Score 59 CVSS 9.9

    Incus – Argument-Injection über block.create_options in Storage-Volume-Konfiguration

  35. CVE-2026-62940 Kritisch
    Score 59 CVSS 9.9

    Incus – Ungeprüfte sicherheitskritische Konfigurationsüberschreibungen bei Cluster-Migration (vor 7.3.0)

  36. CVE-2026-62941 Kritisch
    Score 59 CVSS 9.9

    Incus – Restriktionsprüfung bei Instanz-Kopie zwischen Projekten umgehbar

  37. CVE-2026-63125 Kritisch
    Score 59 CVSS 9.9

    Incus Privilege Escalation for Project-Confined Users

  38. CVE-2026-63343 Kritisch
    Score 59 CVSS 9.9

    Incus – Symlink-Schwachstelle in metadata.yaml erlaubt Zugriff auf Host-Pfade

  39. CVE-2026-76904 Kritisch
    Score 59 CVSS 9.8 EPSS 1.79%

    GeoTools SQL Injection Vulnerability

  40. CVE-2026-77264 Kritisch
    Score 59 CVSS 9.8 EPSS 0.57%

    WordPress-Plugin für WooCommerce-Benachrichtigungen und OTP – Authentifizierungsumgehung

  41. CVE-2026-77683 Kritisch
    Score 59 CVSS 9.9 EPSS 1.51%

    Comfast CF-N1-S 2.6.0.1 – Schwachstelle in ntp_timezone-Funktion (mbox-config)

  42. CVE-2026-77806 Kritisch
    Score 59 CVSS 9.8

    SPIP – Unauthentifizierte Remote Code Execution über X-Spip-Filtre-Header (vor 4.4.21)

  43. CVE-2026-77810 Kritisch
    Score 59 CVSS 9.9 EPSS 0.35%

    AWS Neptune-Connector – Rechteausweitung über Athena Federated Query

  44. CVE-2026-77087 Kritisch
    Score 58 CVSS 9.6

    Paperclip – Command Execution über Host-Header/DNS-Rebinding im local_trusted-Modus

  45. CVE-2026-77812 Kritisch
    Score 56 CVSS 9.4 EPSS 0.06%

    DJI-Drohnen – Unverschlüsselte DUML-Kommunikation über Bluetooth Low Energy

  46. CVE-2026-49849 Kritisch
    Score 55 CVSS 9.1 EPSS 0.70%

    xShop – Unrestricted File Upload ermöglicht Ausführung von PHP-Dateien

  47. CVE-2026-62316 Kritisch
    Score 55 CVSS 9.1 EPSS 0.32%

    Microsoft UFO MCP HTTP Server Binding Exposure

  48. CVE-2026-77086 Kritisch
    Score 55 CVSS 9.1 EPSS 0.65%

    SiYuan Path Traversal via Bazaar Install/Uninstall Endpoints

  49. CVE-2026-77776 Kritisch
    Score 55 CVSS 9.1

    Headroom LLM-Proxy – Manipulierbarer x-headroom-user-id-Header

  50. CVE-2026-62674 Kritisch
    Score 54 CVSS 9 EPSS 0.34%

    Omnigent – Unzureichende Berechtigungsprüfung im Endpunkt PUT /sessions/{session_id}/agent (vor 0.3.0)

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.