Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 101 bis 150 von 36300
- CVE-2026-78166 MittelScore 38 CVSS 6.3 EPSS 0.30%
kafka-ui – Schwachstelle in executeSmartFilterTest
- CVE-2026-78185 MittelScore 38 CVSS 6.3 EPSS 0.25%
itsourcecode Sales and Inventory System 1.0 – Schwachstelle in cust_edit.php
- CVE-2026-19852 MittelScore 37 CVSS 6.1 EPSS 0.23%
NewSiteServer (NSS) – Arbitrary File Upload
- CVE-2026-19853 MittelScore 32 CVSS 5.3 EPSS 0.34%
NewSiteServer (NSS) – Missing Authentication
- CVE-2026-78148 MittelScore 32 CVSS 5.3 EPSS 0.54%
llama.cpp (ggml-org) – Schwachstelle im ggml-RPC-Server (rpc_server::graph_compute)
- CVE-2026-78196 MittelScore 26 CVSS 4.4 EPSS 0.14%
achorein expo-share-intent – Schwachstelle in der Android File Copy Routine
- CVE-2026-5388 KritischScore 59 CVSS 9.8 EPSS 0.34%
justhtml – mehrere Sicherheitsprobleme in URL-Sanitisierung und Markdown-Passthrough
- CVE-2026-7808 KritischScore 59 CVSS 9.8 EPSS 0.35%
justhtml vor 1.16.0 – Mehrere HTML-Sanitisierungs-Bypässe (Cross-Site-Scripting)
- CVE-2026-78155 KritischScore 59 CVSS 9.9 EPSS 0.27%
StackGres Operator – Rechteausweitung für datenbankbesitzende Mandanten
- CVE-2026-8445 KritischScore 59 CVSS 9.8 EPSS 0.38%
justhtml – unzureichende HTML-Maskierung bei Markdown-Konvertierung
- CVE-2026-10053 HochScore 51 CVSS 8.5 EPSS 0.72%
GitLab CE/EE – behobene Schwachstelle in mehreren Versionszweigen
- CVE-2026-4671 HochScore 45 CVSS 7.5 EPSS 0.37%
justhtml – Denial-of-Service in der CSS-Selektor-Verarbeitung und Linkifizierung
- CVE-2026-78143 HochScore 44 CVSS 7.3 EPSS 0.26%
Barangay Resident Profiling Management System – Schwachstelle in residents.php
- CVE-2026-78147 HochScore 44 CVSS 7.3 EPSS 0.43%
llama.cpp ggml-RPC Server – Schwachstelle in deserialize_tensor
- CVE-2026-77115 HochScore 43 CVSS 7.1 EPSS 0.15%
Brave Popup Builder bis 0.8.5 – Reflected Cross-Site-Scripting über UTM-Parameter
- CVE-2026-78112 MittelScore 38 CVSS 6.3 EPSS 0.25%
itsourcecode Hospital Management System – Schwachstelle in viewservicetype.php
- CVE-2026-78142 MittelScore 38 CVSS 6.3 EPSS 0.22%
Barangay Resident Profiling Management System – Schwachstelle in archived_records.php
- CVE-2026-78144 MittelScore 38 CVSS 6.3 EPSS 0.29%
code-projects Barangay Resident Profiling Management System 1.0 – Schwachstelle in boarders.php
- CVE-2026-77088 MittelScore 37 CVSS 6.1 EPSS 0.19%
justhtml 0.9.0 bis 1.21.0 – Cross-Site-Scripting in to_markdown()
- CVE-2026-78115 MittelScore 32 CVSS 5.4 EPSS 0.30%
SourceCodester Class and Exam Timetabling System – Schwachstelle in edit_user_account.php
- CVE-2026-78140 MittelScore 28 CVSS 4.7 EPSS 0.24%
Dromara UJCMS – Schwachstelle in WebFileTemplateController.update
- CVE-2026-19883 HochScore 53 CVSS 8.8 EPSS 0.37%
WordPress-Plugin WPeMatico RSS Feed Fetcher – Fehlende Capability-Prüfung ermöglicht Rechteausweitung
- CVE-2026-61539 KritischScore 60 CVSS 10 EPSS 0.66%
Xinference Code Injection via eval() on Llama3 Tool-Call Output
- CVE-2026-69502 KritischScore 60 CVSS 10 EPSS 0.58%
Azure SQL Database – SSRF-Schwachstelle mit Rechteausweitung
- CVE-2026-69836 KritischScore 60 CVSS 10
Microsoft Entra ID – Unauthentifizierte Deserialisierungs-RCE
- CVE-2026-77649 KritischScore 59 CVSS 9.8 EPSS 0.43%
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control
- CVE-2026-77651 KritischScore 59 CVSS 9.8 EPSS 0.43%
arrayref crate 0.3.10 (Rust) – Schadcode-Ausführung durch Rogue Dependency
- CVE-2026-48749 KritischScore 59 CVSS 9.9
Incus – Arbiträrer Dateizugriff auf dem Host über präpariertes Image
- CVE-2026-48750 KritischScore 59 CVSS 9.9 EPSS 0.78%
Incus Exec Endpoint Output Exposure via record-output Parameter
- CVE-2026-48751 KritischScore 59 CVSS 9.9
Incus – Snapshot-Restriction-Bypass ermöglicht Codeausführung
- CVE-2026-48753 KritischScore 59 CVSS 9.9
Incus – Path Traversal im S3-Upload-Endpunkt (vor 7.1.0)
- CVE-2026-48755 KritischScore 59 CVSS 9.9
Incus – Argument-Injection über Backup-Kompressionsalgorithmus
- CVE-2026-62283 KritischScore 59 CVSS 9.9
Nezha Monitoring Stream Identifier Vulnerability
- CVE-2026-62867 KritischScore 59 CVSS 9.9
Incus – Argument-Injection über block.create_options in Storage-Volume-Konfiguration
- CVE-2026-62940 KritischScore 59 CVSS 9.9
Incus – Ungeprüfte sicherheitskritische Konfigurationsüberschreibungen bei Cluster-Migration (vor 7.3.0)
- CVE-2026-62941 KritischScore 59 CVSS 9.9
Incus – Restriktionsprüfung bei Instanz-Kopie zwischen Projekten umgehbar
- CVE-2026-63125 KritischScore 59 CVSS 9.9
Incus Privilege Escalation for Project-Confined Users
- CVE-2026-63343 KritischScore 59 CVSS 9.9
Incus – Symlink-Schwachstelle in metadata.yaml erlaubt Zugriff auf Host-Pfade
- CVE-2026-76904 KritischScore 59 CVSS 9.8 EPSS 1.79%
GeoTools SQL Injection Vulnerability
- CVE-2026-77264 KritischScore 59 CVSS 9.8 EPSS 0.57%
WordPress-Plugin für WooCommerce-Benachrichtigungen und OTP – Authentifizierungsumgehung
- CVE-2026-77683 KritischScore 59 CVSS 9.9 EPSS 1.51%
Comfast CF-N1-S 2.6.0.1 – Schwachstelle in ntp_timezone-Funktion (mbox-config)
- CVE-2026-77806 KritischScore 59 CVSS 9.8
SPIP – Unauthentifizierte Remote Code Execution über X-Spip-Filtre-Header (vor 4.4.21)
- CVE-2026-77810 KritischScore 59 CVSS 9.9 EPSS 0.35%
AWS Neptune-Connector – Rechteausweitung über Athena Federated Query
- CVE-2026-77087 KritischScore 58 CVSS 9.6
Paperclip – Command Execution über Host-Header/DNS-Rebinding im local_trusted-Modus
- CVE-2026-77812 KritischScore 56 CVSS 9.4 EPSS 0.06%
DJI-Drohnen – Unverschlüsselte DUML-Kommunikation über Bluetooth Low Energy
- CVE-2026-49849 KritischScore 55 CVSS 9.1 EPSS 0.70%
xShop – Unrestricted File Upload ermöglicht Ausführung von PHP-Dateien
- CVE-2026-62316 KritischScore 55 CVSS 9.1 EPSS 0.32%
Microsoft UFO MCP HTTP Server Binding Exposure
- CVE-2026-77086 KritischScore 55 CVSS 9.1 EPSS 0.65%
SiYuan Path Traversal via Bazaar Install/Uninstall Endpoints
- CVE-2026-77776 KritischScore 55 CVSS 9.1
Headroom LLM-Proxy – Manipulierbarer x-headroom-user-id-Header
- CVE-2026-62674 KritischScore 54 CVSS 9 EPSS 0.34%
Omnigent – Unzureichende Berechtigungsprüfung im Endpunkt PUT /sessions/{session_id}/agent (vor 0.3.0)
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.