Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 201 bis 250 von 36300

  1. CVE-2026-61066 Kritisch
    Score 59 CVSS 9.9 EPSS 0.39%

    Oracle Identity Manager: Schwachstelle in der Komponente OIM Legacy UI

  2. CVE-2026-61206 Kritisch
    Score 59 CVSS 9.9 EPSS 0.42%

    Oracle Hyperion Calculation Manager – kritische Schwachstelle in der Komponente Security

  3. CVE-2026-61248 Kritisch
    Score 59 CVSS 9.9 EPSS 0.39%

    Oracle Internet Directory – Schwachstelle im OID LDAP Server

  4. CVE-2026-61317 Kritisch
    Score 59 CVSS 9.9 EPSS 0.42%

    Siebel CRM Cloud Applications – Schwachstelle im Siebel Cloud Manager

  5. CVE-2026-62452 Kritisch
    Score 59 CVSS 9.9 EPSS 0.36%

    Oracle Siebel CRM: Schwachstelle im Siebel Cloud Manager (Siebel CRM Cloud Applications)

  6. CVE-2026-62512 Kritisch
    Score 59 CVSS 9.9 EPSS 0.45%

    Oracle Siebel CRM Cloud Applications – kritische Schwachstelle in Siebel Cloud Manager

  7. CVE-2026-62588 Kritisch
    Score 59 CVSS 9.9 EPSS 0.39%

    Oracle Siebel CRM Integration – Schwachstelle in der Komponente Open Integration

  8. CVE-2026-62608 Kritisch
    Score 59 CVSS 9.9 EPSS 0.45%

    Oracle Reports Developer – Schwachstelle in Sicherheit und Authentifizierung

  9. CVE-2026-66627 Kritisch
    Score 59 CVSS 9.9 EPSS 0.45%

    GP Premium: Arbitrary File Upload durch Contributor-Rolle (<= 2.5.5)

  10. CVE-2026-66780 Kritisch
    Score 59 CVSS 9.9 EPSS 0.24%

    submariner-operator – übermässige Berechtigungen der submariner-k8s-broker-cluster Role

  11. CVE-2026-70920 Kritisch
    Score 59 CVSS 9.9 EPSS 0.42%

    Oracle Hyperion Financial Management – Schwachstelle in der Komponente Security

  12. CVE-2026-71059 Kritisch
    Score 59 CVSS 9.9 EPSS 0.29%

    Oracle BI Publisher – Schwachstelle in der Web-Service-API von Oracle Analytics

  13. CVE-2026-73930 Kritisch
    Score 59 CVSS 9.9 EPSS 0.38%

    Oracle Helidon: Schwachstelle im Imperative Web Server (Oracle Fusion Middleware)

  14. CVE-2026-75843 Kritisch
    Score 59 CVSS 9.9

    ArcadeDB – fehlende Principal-Bindung im gRPC Transaction Executor

  15. CVE-2026-75851 Kritisch
    Score 59 CVSS 9.9

    ArcadeDB Server – fehlende Weitergabe des authentifizierten Principals an asynchrone Worker-Threads

  16. CVE-2026-75877 Kritisch
    Score 59 CVSS 9.9 EPSS 0.61%

    TRENDnet TV-IP751WIC – Schwachstelle in mehreren System-Funktionen

  17. CVE-2026-64849 Kritisch Aktiv ausgenutzt
    Score 100 CVSS 9.3 EPSS 16.41%

    MLflow Server-Side Request Forgery Vulnerability

  18. CVE-2026-19977 Kritisch
    Score 60 CVSS 10 EPSS 0.71%

    EFM ipTIME A3004T – Schwachstelle in der Session-Validierung (httpcon_check_session_url)

  19. CVE-2026-19982 Hoch
    Score 44 CVSS 7.4 EPSS 1.05%

    GL.iNet BE9300/MT6000: Schwachstelle in Firewall-Management-RPC

  20. CVE-2026-19967 Mittel
    Score 38 CVSS 6.3 EPSS 0.26%

    Assimp: Schwachstelle in Assimp::Compression::decompressBlock

  21. CVE-2026-19970 Mittel
    Score 38 CVSS 6.3 EPSS 0.34%

    Open Asset Import Library (Assimp) – Schwachstelle in AddBonesToNodeGraph_3DGS_MDL7

  22. CVE-2026-19972 Mittel
    Score 38 CVSS 6.3 EPSS 0.25%

    itsourcecode Hospital Management System 1.0: SQL-Injection in /viewpatient.php

  23. CVE-2026-19973 Mittel
    Score 38 CVSS 6.3 EPSS 0.20%

    itsourcecode Hospital Management System – Schwachstelle in /viewpaymentreport.php

  24. CVE-2026-19964 Mittel
    Score 33 CVSS 5.5 EPSS 0.22%

    Jij-MCP-Server – Schwachstelle in PythonREPL.run (Argument code)

  25. CVE-2026-19966 Mittel
    Score 32 CVSS 5.4 EPSS 0.24%

    CodeCanyon TimeCamp Integration for CRM: Schwachstelle in /clients/save_contact

  26. CVE-2026-19969 Mittel
    Score 32 CVSS 5.4 EPSS 0.29%

    Open Asset Import Library (Assimp) – Schwachstelle in GenerateOutputMeshes_3DGS_MDL7

  27. CVE-2026-19978 Mittel
    Score 32 CVSS 5.3 EPSS 0.69%

    android-mcp-server – Schwachstelle in child_process.exec (build/index.js)

  28. CVE-2026-19986 Mittel
    Score 32 CVSS 5.4 EPSS 0.24%

    Adblock for Youtube Extension (bis 7.2.1): Schwachstelle in updateDynamicRules

  29. CVE-2026-16098 Kritisch
    Score 59 CVSS 9.8 EPSS 0.64%

    ProSolution WP Client Plugin für WordPress – Arbitrary File Upload

  30. CVE-2026-18432 Kritisch
    Score 59 CVSS 9.8 EPSS 0.45%

    Frontend Admin by DynamiApps (WordPress) – Privilege Escalation

  31. CVE-2026-19924 Kritisch
    Score 59 CVSS 9.8 EPSS 0.90%

    Tenda AC10 – Schwachstelle in R7WebsSecurityHandler (httpd)

  32. CVE-2024-13784 Kritisch
    Score 59 CVSS 9.8 EPSS 0.52%

    ARForms-Plugin (Contact Form, Survey, Quiz & Popup Form Builder) für WordPress: PHP Object Injection

  33. CVE-2026-19959 Kritisch
    Score 59 CVSS 9.9 EPSS 0.47%

    Edimax EW-7478APC – Stack-basierte Schwachstelle in formWanTcpipSetup (pppUserName)

  34. CVE-2026-19961 Kritisch
    Score 59 CVSS 9.9 EPSS 0.47%

    Edimax EW-7478APC: Schwachstelle in formWlSiteSurvey (Argument selSSID)

  35. CVE-2026-73056 Kritisch
    Score 59 CVSS 9.8 EPSS 0.45%

    SiYuan – Fehlende Begrenzung von Authentifizierungsversuchen in CheckAuth()

  36. CVE-2026-73061 Kritisch
    Score 59 CVSS 9.8 EPSS 0.30%

    Scriban: Access-Modifier-Bypass in TypedObjectAccessor (vor 7.2.2)

  37. CVE-2026-18316 Kritisch
    Score 55 CVSS 9.1 EPSS 0.32%

    Solace Extra (WordPress): Fehlende Rechteprüfung in import_zip()

  38. CVE-2026-74790 Kritisch
    Score 55 CVSS 9.1 EPSS 0.29%

    Scriban – TypedObjectAccessor-Caching umgeht MemberFilter-Sichtbarkeitsprüfung

  39. CVE-2026-17087 Hoch
    Score 45 CVSS 7.5 EPSS 0.41%

    WP Travel Engine (WordPress-Plugin) – Autorisierungsumgehung bis Version 6.8.4

  40. CVE-2026-73057 Hoch
    Score 45 CVSS 7.5 EPSS 0.28%

    stoatchat: Denial of Service durch fehlende SVG-viewBox-Validierung im Proxy-Endpunkt

  41. CVE-2026-74787 Hoch
    Score 45 CVSS 7.5 EPSS 0.28%

    Scriban – Unkontrollierte Rekursion in object.to_json

  42. CVE-2026-10734 Hoch
    Score 43 CVSS 7.2 EPSS 0.25%

    Infility Global (WordPress): Stored XSS über /cf7_record Log-Endpoint

  43. CVE-2026-13424 Hoch
    Score 43 CVSS 7.2 EPSS 0.33%

    Bookly (WordPress-Plugin) – Stored XSS über AJAX-Aktion bookly_speed_up_update_addons

  44. CVE-2026-17581 Hoch
    Score 43 CVSS 7.2 EPSS 0.73%

    WCPOS – Point of Sale (POS) für WooCommerce: Code Injection über Thermal-Template-Engine

  45. CVE-2026-2497 Hoch
    Score 43 CVSS 7.2 EPSS 0.32%

    Gallery by BestWebSoft – SQL-Injection über Parameter-Array-Schlüssel

  46. CVE-2026-10035 Mittel
    Score 40 CVSS 6.6 EPSS 0.40%

    Turnkey bbPress by WeaverTheme – PHP Object Injection durch unsichere Deserialisierung

  47. CVE-2026-15056 Mittel
    Score 39 CVSS 6.5 EPSS 0.81%

    StoreEngine (WordPress): Directory Traversal bis Version 2.1.1

  48. CVE-2026-17608 Mittel
    Score 39 CVSS 6.5 EPSS 0.16%

    WP Compress (WordPress-Plugin) – Cross-Site Request Forgery bis Version 7.10.09

  49. CVE-2026-9767 Mittel
    Score 39 CVSS 6.5 EPSS 0.33%

    School Management – Education & Learning ERP für WordPress: SQL Injection über Parameter order[0][dir]

  50. CVE-2026-15604 Mittel
    Score 38 CVSS 6.4 EPSS 0.19%

    Toocheke Companion für WordPress: Stored XSS über Post-Meta-Feld series_bg_color

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.