Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 151 bis 200 von 36300
- CVE-2026-50112 HochScore 53 CVSS 8.8 EPSS 0.37%
SSRF über Metalink-Mirror-URL-Auflösung in der Secondary-Storage-VM
- CVE-2026-77234 HochScore 53 CVSS 8.8 EPSS 0.12%
FreeRTOS-Kernel – Eingabevalidierungsfehler ermöglicht Codeausführung im Kernel-Kontext
- CVE-2026-34741 HochScore 52 CVSS 8.6 EPSS 0.45%
Combodo iTop – Authentication Bypass ermöglicht Ausführung beliebiger PHP-Dateien
- CVE-2026-77755 HochScore 52 CVSS 8.7 EPSS 0.30%
MISP-STIX Denial of Service via sys.exit() in STIX Import
- CVE-2026-77811 HochScore 52 CVSS 8.7 EPSS 0.37%
OpenSearch Dashboards – Codeausführung über dashboards-observability-Plugin
- CVE-2026-63135 HochScore 49 CVSS 8.2 EPSS 0.25%
YOURLS – Unsichere Verarbeitung des HTTP-Referer-Headers
- CVE-2026-65801 KritischScore 60 CVSS 10 EPSS 0.52%
Microsoft Exchange Online – Server-Side Request Forgery (SSRF)
- CVE-2026-65816 KritischScore 60 CVSS 10 EPSS 0.53%
Azure Arc: Verwendung einer falsch aufgelösten Namensangabe ermöglicht Rechteausweitung
- CVE-2026-69555 KritischScore 60 CVSS 10 EPSS 0.45%
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-17141 KritischScore 59 CVSS 9.8 EPSS 0.56%
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
- CVE-2026-17145 KritischScore 59 CVSS 9.8 EPSS 0.51%
IBM AIX 7.2/7.3 und IBM PowerVM VIOS 4.1 – Remote Code Execution durch unzureichendes Privilege Management
- CVE-2026-17152 KritischScore 59 CVSS 9.8 EPSS 0.56%
IBM AIX / PowerVM VIOS: Pufferüberlauf ermöglicht Remote Code Execution
- CVE-2026-17157 KritischScore 59 CVSS 9.8 EPSS 0.56%
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
- CVE-2026-18265 KritischScore 59 CVSS 9.8 EPSS 0.69%
OSNEXUS QuantaStor – Missing Authentication Remote Code Execution Vulnerability
- CVE-2026-18835 KritischScore 59 CVSS 9.9 EPSS 0.56%
IBM AIX / PowerVM VIOS: OS-Command-Injection durch unzureichende Neutralisierung
- CVE-2026-55642 KritischScore 59 CVSS 9.8
dbx: Auth-Middleware in dbx-web vor Version 0.5.51 unzureichend abgesichert
- CVE-2026-63509 KritischScore 59 CVSS 9.9 EPSS 0.62%
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
- CVE-2026-66583 KritischScore 59 CVSS 9.8
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
- CVE-2026-66682 KritischScore 59 CVSS 9.8
Abandoned Cart Pro for WooCommerce <= 10.4.0 – Unauthenticated Privilege Escalation
- CVE-2026-66788 KritischScore 59 CVSS 9.9 EPSS 0.29%
Lighthouse – Resource Injection durch kompromittierten Spoke-Cluster
- CVE-2026-67567 KritischScore 59 CVSS 9.9 EPSS 0.43%
multicloud-operators-subscription: HelmRelease-CRs erlauben Umgehung von Sicherheitskontrollen
- CVE-2026-68782 KritischScore 59 CVSS 9.9 EPSS 0.54%
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69851 KritischScore 59 CVSS 9.9 EPSS 0.44%
Azure Active Directory – Server-Side Request Forgery (SSRF)
- CVE-2026-72843 KritischScore 59 CVSS 9.8 EPSS 0.57%
EverShop: Customer-Update-Route öffentlich zugänglich, Admin-Authentifizierung umgangen
- CVE-2026-73992 KritischScore 59 CVSS 9.9
Query Wrangler bis 1.5.57: Remote Code Execution für Subscriber
- CVE-2026-73993 KritischScore 59 CVSS 9.8
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
- CVE-2026-74014 KritischScore 59 CVSS 9.9
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
- CVE-2026-74018 KritischScore 59 CVSS 9.9
Warehouse Cargo <= 2.6.9 – Arbitrary File Upload
- CVE-2026-75860 KritischScore 59 CVSS 9.8 EPSS 0.34%
JSON Options WordPress-Plugin <= 0.0.4 – Fehlende Capability- und Nonce-Prüfung
- CVE-2026-77022 KritischScore 59 CVSS 9.9 EPSS 0.46%
Comfast CF-N1-S 2.6.0.1: Schwachstelle in Funktion sub_44B438 (mbox-config)
- CVE-2026-77148 KritischScore 59 CVSS 9.9 EPSS 0.47%
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel of the component Web Management.
- CVE-2026-77647 KritischScore 59 CVSS 9.8 EPSS 0.81%
SPIP vor 4.4.20: Unauthenticated Remote Code Execution, seit August 2026 aktiv ausgenutzt
- CVE-2026-72529 Kritisch Aktiv ausgenutztScore 100 CVSS 9.8 EPSS 1.55%
TrueConf Server: Fehlende Authentifizierung für kritische Funktion (aktiv ausgenutzt)
- CVE-2026-72530 Kritisch Aktiv ausgenutztScore 100 CVSS 9 EPSS 1.83%
TrueConf Server Code Injection Vulnerability
- CVE-2026-76008 KritischScore 60 CVSS 10 EPSS 0.57%
Comfast CF-N1-S – Schwachstelle in der URI-Parameter-Verarbeitung
- CVE-2026-75976 KritischScore 59 CVSS 9.9 EPSS 0.63%
TRENDnet TEW-823DRU: Pufferüberlauf in wan.cgi (NVRAM)
- CVE-2026-76003 KritischScore 59 CVSS 9.9 EPSS 0.44%
UTT HiPER 1200GW – Pufferüberlauf in formGroupConfig
- CVE-2026-76004 KritischScore 59 CVSS 9.9 EPSS 0.44%
UTT HiPER 1250GW – Pufferüberlauf in aspApBasicConfigUrcp
- CVE-2026-61241 KritischScore 60 CVSS 10 EPSS 0.55%
Oracle Internet Directory (OID LDAP Server) – kritische Schwachstelle in Oracle Fusion Middleware
- CVE-2026-70880 KritischScore 60 CVSS 10 EPSS 0.36%
Oracle Hyperion Data Relationship Management: Schwachstelle in der Komponente Access and Security
- CVE-2026-70921 KritischScore 60 CVSS 10 EPSS 0.40%
Oracle Hyperion Financial Management – kritische Schwachstelle in der Komponente Security
- CVE-2026-73343 KritischScore 60 CVSS 10 EPSS 0.80%
WP Compress – Unauthenticated Remote Code Execution vor Version 7.20.01
- CVE-2026-75784 KritischScore 60 CVSS 10 EPSS 1.02%
TRENDnet TEW-WLC100 – Schwachstelle im HTTP Header Handler von nginx
- CVE-2026-75874 KritischScore 60 CVSS 10 EPSS 0.43%
Mozilla Firefox und Thunderbird: Sandbox-Escape in der Remote-Settings-Client-Komponente
- CVE-2026-60730 KritischScore 59 CVSS 9.9 EPSS 0.39%
Oracle WebCenter Portal – Schwachstelle in der Komponente Composer
- CVE-2026-60916 KritischScore 59 CVSS 9.9 EPSS 0.34%
Oracle WebCenter Enterprise Capture – Schwachstelle im Client Bundle
- CVE-2026-60990 KritischScore 59 CVSS 9.9 EPSS 0.38%
Oracle Identity Manager Connector: Schwachstelle in der Kernkomponente
- CVE-2026-60995 KritischScore 59 CVSS 9.9 EPSS 0.31%
Oracle Identity Manager Connector – kritische Schwachstelle in der Komponente Core
- CVE-2026-61003 KritischScore 59 CVSS 9.9 EPSS 0.52%
Oracle Managed File Transfer – Schwachstelle im MFT Runtime Server
- CVE-2026-61021 KritischScore 59 CVSS 9.9 EPSS 0.29%
Oracle WebCenter Sites – kritische Schwachstelle in Oracle Fusion Middleware
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.