Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 251 bis 300 von 36300
- CVE-2026-15790 MittelScore 38 CVSS 6.4 EPSS 0.20%
Youtube Showcase – Stored XSS über Shortcode 'emd_mb_meta'
- CVE-2026-16758 MittelScore 38 CVSS 6.4 EPSS 0.19%
Snippet Shortcodes (WordPress): Stored XSS über Shortcode-Attribute
- CVE-2026-16775 MittelScore 38 CVSS 6.4 EPSS 0.19%
Smash Balloon Social Post Feed (WordPress-Plugin) – Stored XSS über Shortcode-Attribut „id“
- CVE-2026-18402 MittelScore 38 CVSS 6.4 EPSS 0.19%
SureDash für WordPress: Stored XSS über Shortcode-Attribut draweropenverposition
- CVE-2026-19934 MittelScore 38 CVSS 6.3 EPSS 0.20%
itsourcecode Hospital Management System 1.0: SQL Injection über Parameter delid in /vieworder.php
- CVE-2026-19956 MittelScore 38 CVSS 6.3 EPSS 0.21%
gomarble-ai facebook-ads-mcp-server – Schwachstelle in fetch_pagination_url
- CVE-2026-19957 MittelScore 38 CVSS 6.3 EPSS 0.27%
graphlit-mcp-server 1.0.1: Schwachstelle in fetch-Funktion (ssrf-test Endpoint)
- CVE-2026-19958 MittelScore 38 CVSS 6.3 EPSS 0.23%
pptr-mcp – Schwachstelle in executeCode (vm-executor.ts, Execute Tool)
- CVE-2026-2357 MittelScore 38 CVSS 6.4 EPSS 0.19%
Bold Page Builder – Stored XSS über Shortcode 'bt_bb_shortcode'
- CVE-2026-12998 MittelScore 32 CVSS 5.3 EPSS 0.30%
Forminator Forms (WordPress): Insecure Direct Object Reference bis 1.55.0.2
- CVE-2026-74764 KritischScore 60 CVSS 10 EPSS 0.40%
Pandora – Path Traversal bei TAR-Archivextraktion
- CVE-2026-16142 KritischScore 59 CVSS 9.8 EPSS 0.38%
TrueBooker (WordPress) – Account Takeover durch unauthentifizierten AJAX-Handler
- CVE-2026-19598 KritischScore 59 CVSS 9.8 EPSS 0.43%
WordPress Pods Plugin – Privilege Escalation via Authorization Bypass
- CVE-2026-73046 KritischScore 59 CVSS 9.8 EPSS 0.43%
SiYuan – Unzureichende Begrenzung von Authentifizierungsversuchen in CheckAuth()
- CVE-2026-8452 Kritisch Aktiv ausgenutztScore 100 CVSS 9.8 EPSS 1.61%
Citrix NetScaler ADC/Gateway: Speicherüberlauf ermöglicht Denial of Service
- CVE-2026-73570 Hoch Aktiv ausgenutztScore 100 CVSS 8.9 EPSS 20.53%
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- CVE-2026-15413 KritischScore 60 CVSS 10 EPSS 0.29%
Link Factory WordPress-Plugin – Backdoor mit REST-API
- CVE-2026-27544 KritischScore 60 CVSS 10 EPSS 0.59%
QA Analytics ≤ 5.2.0.0 – Unauthenticated Remote Code Execution (RCE)
- CVE-2026-59500 KritischScore 60 CVSS 10 EPSS 0.30%
Unzureichende Authentifizierung (CWE-287)
- CVE-2026-61962 KritischScore 60 CVSS 10 EPSS 0.48%
WP BASE Booking (<= 6.3.0) – Unauthenticated Arbitrary Code Execution
- CVE-2026-72851 KritischScore 60 CVSS 10 EPSS 0.29%
Budibase – Unauthenticated SQL Injection in Webhook-Automationen
- CVE-2026-72842 KritischScore 59 CVSS 9.9 EPSS 0.42%
OpenWrt luci-app-lxc: ACL-Inkonsistenz erlaubt Zugriff auf Container-Verwaltung
- CVE-2026-73656 KritischScore 59 CVSS 9.9 EPSS 0.34%
Trigger.dev – Schwachstelle im Endpoint /api/v1/deployments/:deploymentId/background-workers
- CVE-2026-66384 Mittel Aktiv ausgenutztScore 100 CVSS 5.3 EPSS 0.54%
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- CVE-2026-20349 Hoch Aktiv ausgenutztScore 100 CVSS 8.6 EPSS 2.21%
Cisco Secure Firewall ASA und FTD – Heap Inspection Vulnerability
- CVE-2026-68820 Hoch Aktiv ausgenutztScore 100 CVSS 7 EPSS 6.18%
Microsoft Windows Ancillary Function Driver für WinSock – Use-after-Free
- CVE-2026-17106 MittelScore 0 EPSS 0.33%
CopyEscape: Container-to-Host Arbitrary File Write via docker cp
- CVE-2026-72898 Kritisch Aktiv ausgenutztScore 100 CVSS 10 EPSS 79.22%
Metabase SQL Injection Vulnerability
- CVE-2026-19381 HochScore 47 CVSS 7.8 EPSS 0.11%
Kingston FURY CTRL RGB Control Software – Schwachstelle im Treiber NTIOLib_KSFX.sys
- CVE-2026-19387 HochScore 46 CVSS 7.6 EPSS 0.24%
GStreamer gst-plugins-bad – Heap-Out-of-Bounds-Write im ADPCM-Decoder (adpcmdec)
- CVE-2026-19376 HochScore 44 CVSS 7.3 EPSS 0.35%
Uasoft Badaso – Schwachstelle in der File API (ApiRequest::class)
- CVE-2026-19379 HochScore 44 CVSS 7.3 EPSS 1.66%
EFM ipTIME AX8004M 15.09.0: Schwachstelle in CGI-Endpoint /cgi/d.cgi
- CVE-2026-19384 HochScore 44 CVSS 7.3 EPSS 0.26%
SourceCodester Simple Doctors Appointment System – Schwachstelle in admin/ajax.php (set_appointment)
- CVE-2026-19389 HochScore 43 CVSS 7.1 EPSS 0.26%
GStreamer gst-plugins-ugly – Integer-Overflow im ASF-Demuxer (asfdemux)
- CVE-2026-19378 MittelScore 26 CVSS 4.3 EPSS 0.35%
code-projects Task Management System – Schwachstelle in CommentSave.php
- CVE-2026-19380 NiedrigScore 14 CVSS 2.3 EPSS 0.12%
Mullvad wireguard.sys 0.10.1 – Schwachstelle in AdapterState (IOCTL Handler)
- CVE-2026-19348 KritischScore 59 CVSS 9.8 EPSS 2.46%
Shenzhen Aitemi M300 Wi-Fi Repeater – Schwachstelle in sprintf-Funktion (protocol.csp)
- CVE-2026-19342 HochScore 44 CVSS 7.3 EPSS 0.40%
code-projects Task Management System 1.0: Schwachstelle in Login-Komponente
- CVE-2026-19343 HochScore 44 CVSS 7.3 EPSS 0.26%
code-projects Task Management System – Schwachstelle in admin/AdminLogin.php
- CVE-2026-19344 HochScore 44 CVSS 7.3 EPSS 0.41%
code-projects Task Management System 1.0 – Schwachstelle in comment_count_user.php
- CVE-2026-19345 MittelScore 39 CVSS 6.5 EPSS 0.52%
code-projects Task Management System 1.0 – Schwachstelle in UpdateTaskStatus.php
- CVE-2026-19339 MittelScore 38 CVSS 6.3 EPSS 0.21%
aliyun alibabacloud-dataworks-mcp-server – Schwachstelle in ReadResourceRequestSchema (initResources.ts)
- CVE-2026-19347 MittelScore 38 CVSS 6.3 EPSS 0.20%
itsourcecode Hospital Management System 1.0 – Schwachstelle in viewdoctor.php
- CVE-2026-19350 MittelScore 38 CVSS 6.3 EPSS 0.35%
Dolibarr ERP – Fehlerhafte Funktion fail im TakePOS-Modul (invoice.php)
- CVE-2026-19354 MittelScore 38 CVSS 6.3 EPSS 0.19%
lock-upme OPMS: Schwachstelle in controllers/messages/message.go
- CVE-2026-19364 MittelScore 38 CVSS 6.3 EPSS 0.20%
itsourcecode Hospital Management System – Schwachstelle in viewdoctorconsultancycharge.php
- CVE-2026-19338 MittelScore 32 CVSS 5.3 EPSS 0.14%
automateyournetwork MCPyATS – Schwachstelle in processGenerateRequest (mermaid/index.ts)
- CVE-2026-19365 MittelScore 32 CVSS 5.3 EPSS 0.14%
Ichigo3766 image-gen-mcp 0.1.0 – Schwachstelle in upscale_images (src/index.ts)
- CVE-2026-19369 MittelScore 32 CVSS 5.3 EPSS 0.10%
KS-GEN-AI jira-mcp-server – Schwachstelle in add_attachment_from_public_url (axios.get)
- CVE-2026-19353 MittelScore 30 CVSS 5 EPSS 0.24%
DedeCMS 5.7.118 UTF8SP2: Schwachstelle in Installation Wizard (_4_Setup)
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.