Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 151 bis 200 von 36300

  1. CVE-2026-50112 Hoch
    Score 53 CVSS 8.8 EPSS 0.37%

    SSRF über Metalink-Mirror-URL-Auflösung in der Secondary-Storage-VM

  2. CVE-2026-77234 Hoch
    Score 53 CVSS 8.8 EPSS 0.12%

    FreeRTOS-Kernel – Eingabevalidierungsfehler ermöglicht Codeausführung im Kernel-Kontext

  3. CVE-2026-34741 Hoch
    Score 52 CVSS 8.6 EPSS 0.45%

    Combodo iTop – Authentication Bypass ermöglicht Ausführung beliebiger PHP-Dateien

  4. CVE-2026-77755 Hoch
    Score 52 CVSS 8.7 EPSS 0.30%

    MISP-STIX Denial of Service via sys.exit() in STIX Import

  5. CVE-2026-77811 Hoch
    Score 52 CVSS 8.7 EPSS 0.37%

    OpenSearch Dashboards – Codeausführung über dashboards-observability-Plugin

  6. CVE-2026-63135 Hoch
    Score 49 CVSS 8.2 EPSS 0.25%

    YOURLS – Unsichere Verarbeitung des HTTP-Referer-Headers

  7. CVE-2026-65801 Kritisch
    Score 60 CVSS 10 EPSS 0.52%

    Microsoft Exchange Online – Server-Side Request Forgery (SSRF)

  8. CVE-2026-65816 Kritisch
    Score 60 CVSS 10 EPSS 0.53%

    Azure Arc: Verwendung einer falsch aufgelösten Namensangabe ermöglicht Rechteausweitung

  9. CVE-2026-69555 Kritisch
    Score 60 CVSS 10 EPSS 0.45%

    Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  10. CVE-2026-17141 Kritisch
    Score 59 CVSS 9.8 EPSS 0.56%

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

  11. CVE-2026-17145 Kritisch
    Score 59 CVSS 9.8 EPSS 0.51%

    IBM AIX 7.2/7.3 und IBM PowerVM VIOS 4.1 – Remote Code Execution durch unzureichendes Privilege Management

  12. CVE-2026-17152 Kritisch
    Score 59 CVSS 9.8 EPSS 0.56%

    IBM AIX / PowerVM VIOS: Pufferüberlauf ermöglicht Remote Code Execution

  13. CVE-2026-17157 Kritisch
    Score 59 CVSS 9.8 EPSS 0.56%

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

  14. CVE-2026-18265 Kritisch
    Score 59 CVSS 9.8 EPSS 0.69%

    OSNEXUS QuantaStor – Missing Authentication Remote Code Execution Vulnerability

  15. CVE-2026-18835 Kritisch
    Score 59 CVSS 9.9 EPSS 0.56%

    IBM AIX / PowerVM VIOS: OS-Command-Injection durch unzureichende Neutralisierung

  16. CVE-2026-55642 Kritisch
    Score 59 CVSS 9.8

    dbx: Auth-Middleware in dbx-web vor Version 0.5.51 unzureichend abgesichert

  17. CVE-2026-63509 Kritisch
    Score 59 CVSS 9.9 EPSS 0.62%

    Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

  18. CVE-2026-66583 Kritisch
    Score 59 CVSS 9.8

    Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.

  19. CVE-2026-66682 Kritisch
    Score 59 CVSS 9.8

    Abandoned Cart Pro for WooCommerce <= 10.4.0 – Unauthenticated Privilege Escalation

  20. CVE-2026-66788 Kritisch
    Score 59 CVSS 9.9 EPSS 0.29%

    Lighthouse – Resource Injection durch kompromittierten Spoke-Cluster

  21. CVE-2026-67567 Kritisch
    Score 59 CVSS 9.9 EPSS 0.43%

    multicloud-operators-subscription: HelmRelease-CRs erlauben Umgehung von Sicherheitskontrollen

  22. CVE-2026-68782 Kritisch
    Score 59 CVSS 9.9 EPSS 0.54%

    Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

  23. CVE-2026-69851 Kritisch
    Score 59 CVSS 9.9 EPSS 0.44%

    Azure Active Directory – Server-Side Request Forgery (SSRF)

  24. CVE-2026-72843 Kritisch
    Score 59 CVSS 9.8 EPSS 0.57%

    EverShop: Customer-Update-Route öffentlich zugänglich, Admin-Authentifizierung umgangen

  25. CVE-2026-73992 Kritisch
    Score 59 CVSS 9.9

    Query Wrangler bis 1.5.57: Remote Code Execution für Subscriber

  26. CVE-2026-73993 Kritisch
    Score 59 CVSS 9.8

    Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

  27. CVE-2026-74014 Kritisch
    Score 59 CVSS 9.9

    Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.

  28. CVE-2026-74018 Kritisch
    Score 59 CVSS 9.9

    Warehouse Cargo <= 2.6.9 – Arbitrary File Upload

  29. CVE-2026-75860 Kritisch
    Score 59 CVSS 9.8 EPSS 0.34%

    JSON Options WordPress-Plugin <= 0.0.4 – Fehlende Capability- und Nonce-Prüfung

  30. CVE-2026-77022 Kritisch
    Score 59 CVSS 9.9 EPSS 0.46%

    Comfast CF-N1-S 2.6.0.1: Schwachstelle in Funktion sub_44B438 (mbox-config)

  31. CVE-2026-77148 Kritisch
    Score 59 CVSS 9.9 EPSS 0.47%

    A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management.

  32. CVE-2026-77647 Kritisch
    Score 59 CVSS 9.8 EPSS 0.81%

    SPIP vor 4.4.20: Unauthenticated Remote Code Execution, seit August 2026 aktiv ausgenutzt

  33. CVE-2026-72529 Kritisch Aktiv ausgenutzt
    Score 100 CVSS 9.8 EPSS 1.55%

    TrueConf Server: Fehlende Authentifizierung für kritische Funktion (aktiv ausgenutzt)

  34. CVE-2026-72530 Kritisch Aktiv ausgenutzt
    Score 100 CVSS 9 EPSS 1.83%

    TrueConf Server Code Injection Vulnerability

  35. CVE-2026-76008 Kritisch
    Score 60 CVSS 10 EPSS 0.57%

    Comfast CF-N1-S – Schwachstelle in der URI-Parameter-Verarbeitung

  36. CVE-2026-75976 Kritisch
    Score 59 CVSS 9.9 EPSS 0.63%

    TRENDnet TEW-823DRU: Pufferüberlauf in wan.cgi (NVRAM)

  37. CVE-2026-76003 Kritisch
    Score 59 CVSS 9.9 EPSS 0.44%

    UTT HiPER 1200GW – Pufferüberlauf in formGroupConfig

  38. CVE-2026-76004 Kritisch
    Score 59 CVSS 9.9 EPSS 0.44%

    UTT HiPER 1250GW – Pufferüberlauf in aspApBasicConfigUrcp

  39. CVE-2026-61241 Kritisch
    Score 60 CVSS 10 EPSS 0.55%

    Oracle Internet Directory (OID LDAP Server) – kritische Schwachstelle in Oracle Fusion Middleware

  40. CVE-2026-70880 Kritisch
    Score 60 CVSS 10 EPSS 0.36%

    Oracle Hyperion Data Relationship Management: Schwachstelle in der Komponente Access and Security

  41. CVE-2026-70921 Kritisch
    Score 60 CVSS 10 EPSS 0.40%

    Oracle Hyperion Financial Management – kritische Schwachstelle in der Komponente Security

  42. CVE-2026-73343 Kritisch
    Score 60 CVSS 10 EPSS 0.80%

    WP Compress – Unauthenticated Remote Code Execution vor Version 7.20.01

  43. CVE-2026-75784 Kritisch
    Score 60 CVSS 10 EPSS 1.02%

    TRENDnet TEW-WLC100 – Schwachstelle im HTTP Header Handler von nginx

  44. CVE-2026-75874 Kritisch
    Score 60 CVSS 10 EPSS 0.43%

    Mozilla Firefox und Thunderbird: Sandbox-Escape in der Remote-Settings-Client-Komponente

  45. CVE-2026-60730 Kritisch
    Score 59 CVSS 9.9 EPSS 0.39%

    Oracle WebCenter Portal – Schwachstelle in der Komponente Composer

  46. CVE-2026-60916 Kritisch
    Score 59 CVSS 9.9 EPSS 0.34%

    Oracle WebCenter Enterprise Capture – Schwachstelle im Client Bundle

  47. CVE-2026-60990 Kritisch
    Score 59 CVSS 9.9 EPSS 0.38%

    Oracle Identity Manager Connector: Schwachstelle in der Kernkomponente

  48. CVE-2026-60995 Kritisch
    Score 59 CVSS 9.9 EPSS 0.31%

    Oracle Identity Manager Connector – kritische Schwachstelle in der Komponente Core

  49. CVE-2026-61003 Kritisch
    Score 59 CVSS 9.9 EPSS 0.52%

    Oracle Managed File Transfer – Schwachstelle im MFT Runtime Server

  50. CVE-2026-61021 Kritisch
    Score 59 CVSS 9.9 EPSS 0.29%

    Oracle WebCenter Sites – kritische Schwachstelle in Oracle Fusion Middleware

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.