Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 201 bis 250 von 36300
- CVE-2026-61066 KritischScore 59 CVSS 9.9 EPSS 0.39%
Oracle Identity Manager: Schwachstelle in der Komponente OIM Legacy UI
- CVE-2026-61206 KritischScore 59 CVSS 9.9 EPSS 0.42%
Oracle Hyperion Calculation Manager – kritische Schwachstelle in der Komponente Security
- CVE-2026-61248 KritischScore 59 CVSS 9.9 EPSS 0.39%
Oracle Internet Directory – Schwachstelle im OID LDAP Server
- CVE-2026-61317 KritischScore 59 CVSS 9.9 EPSS 0.42%
Siebel CRM Cloud Applications – Schwachstelle im Siebel Cloud Manager
- CVE-2026-62452 KritischScore 59 CVSS 9.9 EPSS 0.36%
Oracle Siebel CRM: Schwachstelle im Siebel Cloud Manager (Siebel CRM Cloud Applications)
- CVE-2026-62512 KritischScore 59 CVSS 9.9 EPSS 0.45%
Oracle Siebel CRM Cloud Applications – kritische Schwachstelle in Siebel Cloud Manager
- CVE-2026-62588 KritischScore 59 CVSS 9.9 EPSS 0.39%
Oracle Siebel CRM Integration – Schwachstelle in der Komponente Open Integration
- CVE-2026-62608 KritischScore 59 CVSS 9.9 EPSS 0.45%
Oracle Reports Developer – Schwachstelle in Sicherheit und Authentifizierung
- CVE-2026-66627 KritischScore 59 CVSS 9.9 EPSS 0.45%
GP Premium: Arbitrary File Upload durch Contributor-Rolle (<= 2.5.5)
- CVE-2026-66780 KritischScore 59 CVSS 9.9 EPSS 0.24%
submariner-operator – übermässige Berechtigungen der submariner-k8s-broker-cluster Role
- CVE-2026-70920 KritischScore 59 CVSS 9.9 EPSS 0.42%
Oracle Hyperion Financial Management – Schwachstelle in der Komponente Security
- CVE-2026-71059 KritischScore 59 CVSS 9.9 EPSS 0.29%
Oracle BI Publisher – Schwachstelle in der Web-Service-API von Oracle Analytics
- CVE-2026-73930 KritischScore 59 CVSS 9.9 EPSS 0.38%
Oracle Helidon: Schwachstelle im Imperative Web Server (Oracle Fusion Middleware)
- CVE-2026-75843 KritischScore 59 CVSS 9.9
ArcadeDB – fehlende Principal-Bindung im gRPC Transaction Executor
- CVE-2026-75851 KritischScore 59 CVSS 9.9
ArcadeDB Server – fehlende Weitergabe des authentifizierten Principals an asynchrone Worker-Threads
- CVE-2026-75877 KritischScore 59 CVSS 9.9 EPSS 0.61%
TRENDnet TV-IP751WIC – Schwachstelle in mehreren System-Funktionen
- CVE-2026-64849 Kritisch Aktiv ausgenutztScore 100 CVSS 9.3 EPSS 16.41%
MLflow Server-Side Request Forgery Vulnerability
- CVE-2026-19977 KritischScore 60 CVSS 10 EPSS 0.71%
EFM ipTIME A3004T – Schwachstelle in der Session-Validierung (httpcon_check_session_url)
- CVE-2026-19982 HochScore 44 CVSS 7.4 EPSS 1.05%
GL.iNet BE9300/MT6000: Schwachstelle in Firewall-Management-RPC
- CVE-2026-19967 MittelScore 38 CVSS 6.3 EPSS 0.26%
Assimp: Schwachstelle in Assimp::Compression::decompressBlock
- CVE-2026-19970 MittelScore 38 CVSS 6.3 EPSS 0.34%
Open Asset Import Library (Assimp) – Schwachstelle in AddBonesToNodeGraph_3DGS_MDL7
- CVE-2026-19972 MittelScore 38 CVSS 6.3 EPSS 0.25%
itsourcecode Hospital Management System 1.0: SQL-Injection in /viewpatient.php
- CVE-2026-19973 MittelScore 38 CVSS 6.3 EPSS 0.20%
itsourcecode Hospital Management System – Schwachstelle in /viewpaymentreport.php
- CVE-2026-19964 MittelScore 33 CVSS 5.5 EPSS 0.22%
Jij-MCP-Server – Schwachstelle in PythonREPL.run (Argument code)
- CVE-2026-19966 MittelScore 32 CVSS 5.4 EPSS 0.24%
CodeCanyon TimeCamp Integration for CRM: Schwachstelle in /clients/save_contact
- CVE-2026-19969 MittelScore 32 CVSS 5.4 EPSS 0.29%
Open Asset Import Library (Assimp) – Schwachstelle in GenerateOutputMeshes_3DGS_MDL7
- CVE-2026-19978 MittelScore 32 CVSS 5.3 EPSS 0.69%
android-mcp-server – Schwachstelle in child_process.exec (build/index.js)
- CVE-2026-19986 MittelScore 32 CVSS 5.4 EPSS 0.24%
Adblock for Youtube Extension (bis 7.2.1): Schwachstelle in updateDynamicRules
- CVE-2026-16098 KritischScore 59 CVSS 9.8 EPSS 0.64%
ProSolution WP Client Plugin für WordPress – Arbitrary File Upload
- CVE-2026-18432 KritischScore 59 CVSS 9.8 EPSS 0.45%
Frontend Admin by DynamiApps (WordPress) – Privilege Escalation
- CVE-2026-19924 KritischScore 59 CVSS 9.8 EPSS 0.90%
Tenda AC10 – Schwachstelle in R7WebsSecurityHandler (httpd)
- CVE-2024-13784 KritischScore 59 CVSS 9.8 EPSS 0.52%
ARForms-Plugin (Contact Form, Survey, Quiz & Popup Form Builder) für WordPress: PHP Object Injection
- CVE-2026-19959 KritischScore 59 CVSS 9.9 EPSS 0.47%
Edimax EW-7478APC – Stack-basierte Schwachstelle in formWanTcpipSetup (pppUserName)
- CVE-2026-19961 KritischScore 59 CVSS 9.9 EPSS 0.47%
Edimax EW-7478APC: Schwachstelle in formWlSiteSurvey (Argument selSSID)
- CVE-2026-73056 KritischScore 59 CVSS 9.8 EPSS 0.45%
SiYuan – Fehlende Begrenzung von Authentifizierungsversuchen in CheckAuth()
- CVE-2026-73061 KritischScore 59 CVSS 9.8 EPSS 0.30%
Scriban: Access-Modifier-Bypass in TypedObjectAccessor (vor 7.2.2)
- CVE-2026-18316 KritischScore 55 CVSS 9.1 EPSS 0.32%
Solace Extra (WordPress): Fehlende Rechteprüfung in import_zip()
- CVE-2026-74790 KritischScore 55 CVSS 9.1 EPSS 0.29%
Scriban – TypedObjectAccessor-Caching umgeht MemberFilter-Sichtbarkeitsprüfung
- CVE-2026-17087 HochScore 45 CVSS 7.5 EPSS 0.41%
WP Travel Engine (WordPress-Plugin) – Autorisierungsumgehung bis Version 6.8.4
- CVE-2026-73057 HochScore 45 CVSS 7.5 EPSS 0.28%
stoatchat: Denial of Service durch fehlende SVG-viewBox-Validierung im Proxy-Endpunkt
- CVE-2026-74787 HochScore 45 CVSS 7.5 EPSS 0.28%
Scriban – Unkontrollierte Rekursion in object.to_json
- CVE-2026-10734 HochScore 43 CVSS 7.2 EPSS 0.25%
Infility Global (WordPress): Stored XSS über /cf7_record Log-Endpoint
- CVE-2026-13424 HochScore 43 CVSS 7.2 EPSS 0.33%
Bookly (WordPress-Plugin) – Stored XSS über AJAX-Aktion bookly_speed_up_update_addons
- CVE-2026-17581 HochScore 43 CVSS 7.2 EPSS 0.73%
WCPOS – Point of Sale (POS) für WooCommerce: Code Injection über Thermal-Template-Engine
- CVE-2026-2497 HochScore 43 CVSS 7.2 EPSS 0.32%
Gallery by BestWebSoft – SQL-Injection über Parameter-Array-Schlüssel
- CVE-2026-10035 MittelScore 40 CVSS 6.6 EPSS 0.40%
Turnkey bbPress by WeaverTheme – PHP Object Injection durch unsichere Deserialisierung
- CVE-2026-15056 MittelScore 39 CVSS 6.5 EPSS 0.81%
StoreEngine (WordPress): Directory Traversal bis Version 2.1.1
- CVE-2026-17608 MittelScore 39 CVSS 6.5 EPSS 0.16%
WP Compress (WordPress-Plugin) – Cross-Site Request Forgery bis Version 7.10.09
- CVE-2026-9767 MittelScore 39 CVSS 6.5 EPSS 0.33%
School Management – Education & Learning ERP für WordPress: SQL Injection über Parameter order[0][dir]
- CVE-2026-15604 MittelScore 38 CVSS 6.4 EPSS 0.19%
Toocheke Companion für WordPress: Stored XSS über Post-Meta-Feld series_bg_color
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.