Live-Feed 1682 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch

Zeige 251 bis 300 von 36300

  1. CVE-2026-15790 Mittel
    Score 38 CVSS 6.4 EPSS 0.20%

    Youtube Showcase – Stored XSS über Shortcode 'emd_mb_meta'

  2. CVE-2026-16758 Mittel
    Score 38 CVSS 6.4 EPSS 0.19%

    Snippet Shortcodes (WordPress): Stored XSS über Shortcode-Attribute

  3. CVE-2026-16775 Mittel
    Score 38 CVSS 6.4 EPSS 0.19%

    Smash Balloon Social Post Feed (WordPress-Plugin) – Stored XSS über Shortcode-Attribut „id“

  4. CVE-2026-18402 Mittel
    Score 38 CVSS 6.4 EPSS 0.19%

    SureDash für WordPress: Stored XSS über Shortcode-Attribut draweropenverposition

  5. CVE-2026-19934 Mittel
    Score 38 CVSS 6.3 EPSS 0.20%

    itsourcecode Hospital Management System 1.0: SQL Injection über Parameter delid in /vieworder.php

  6. CVE-2026-19956 Mittel
    Score 38 CVSS 6.3 EPSS 0.21%

    gomarble-ai facebook-ads-mcp-server – Schwachstelle in fetch_pagination_url

  7. CVE-2026-19957 Mittel
    Score 38 CVSS 6.3 EPSS 0.27%

    graphlit-mcp-server 1.0.1: Schwachstelle in fetch-Funktion (ssrf-test Endpoint)

  8. CVE-2026-19958 Mittel
    Score 38 CVSS 6.3 EPSS 0.23%

    pptr-mcp – Schwachstelle in executeCode (vm-executor.ts, Execute Tool)

  9. CVE-2026-2357 Mittel
    Score 38 CVSS 6.4 EPSS 0.19%

    Bold Page Builder – Stored XSS über Shortcode 'bt_bb_shortcode'

  10. CVE-2026-12998 Mittel
    Score 32 CVSS 5.3 EPSS 0.30%

    Forminator Forms (WordPress): Insecure Direct Object Reference bis 1.55.0.2

  11. CVE-2026-74764 Kritisch
    Score 60 CVSS 10 EPSS 0.40%

    Pandora – Path Traversal bei TAR-Archivextraktion

  12. CVE-2026-16142 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    TrueBooker (WordPress) – Account Takeover durch unauthentifizierten AJAX-Handler

  13. CVE-2026-19598 Kritisch
    Score 59 CVSS 9.8 EPSS 0.43%

    WordPress Pods Plugin – Privilege Escalation via Authorization Bypass

  14. CVE-2026-73046 Kritisch
    Score 59 CVSS 9.8 EPSS 0.43%

    SiYuan – Unzureichende Begrenzung von Authentifizierungsversuchen in CheckAuth()

  15. CVE-2026-8452 Kritisch Aktiv ausgenutzt
    Score 100 CVSS 9.8 EPSS 1.61%

    Citrix NetScaler ADC/Gateway: Speicherüberlauf ermöglicht Denial of Service

  16. CVE-2026-73570 Hoch Aktiv ausgenutzt
    Score 100 CVSS 8.9 EPSS 20.53%

    Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

  17. CVE-2026-15413 Kritisch
    Score 60 CVSS 10 EPSS 0.29%

    Link Factory WordPress-Plugin – Backdoor mit REST-API

  18. CVE-2026-27544 Kritisch
    Score 60 CVSS 10 EPSS 0.59%

    QA Analytics ≤ 5.2.0.0 – Unauthenticated Remote Code Execution (RCE)

  19. CVE-2026-59500 Kritisch
    Score 60 CVSS 10 EPSS 0.30%

    Unzureichende Authentifizierung (CWE-287)

  20. CVE-2026-61962 Kritisch
    Score 60 CVSS 10 EPSS 0.48%

    WP BASE Booking (<= 6.3.0) – Unauthenticated Arbitrary Code Execution

  21. CVE-2026-72851 Kritisch
    Score 60 CVSS 10 EPSS 0.29%

    Budibase – Unauthenticated SQL Injection in Webhook-Automationen

  22. CVE-2026-72842 Kritisch
    Score 59 CVSS 9.9 EPSS 0.42%

    OpenWrt luci-app-lxc: ACL-Inkonsistenz erlaubt Zugriff auf Container-Verwaltung

  23. CVE-2026-73656 Kritisch
    Score 59 CVSS 9.9 EPSS 0.34%

    Trigger.dev – Schwachstelle im Endpoint /api/v1/deployments/:deploymentId/background-workers

  24. CVE-2026-66384 Mittel Aktiv ausgenutzt
    Score 100 CVSS 5.3 EPSS 0.54%

    JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

  25. CVE-2026-20349 Hoch Aktiv ausgenutzt
    Score 100 CVSS 8.6 EPSS 2.21%

    Cisco Secure Firewall ASA und FTD – Heap Inspection Vulnerability

  26. CVE-2026-68820 Hoch Aktiv ausgenutzt
    Score 100 CVSS 7 EPSS 6.18%

    Microsoft Windows Ancillary Function Driver für WinSock – Use-after-Free

  27. CVE-2026-17106 Mittel
    Score 0 EPSS 0.33%

    CopyEscape: Container-to-Host Arbitrary File Write via docker cp

  28. CVE-2026-72898 Kritisch Aktiv ausgenutzt
    Score 100 CVSS 10 EPSS 79.22%

    Metabase SQL Injection Vulnerability

  29. CVE-2026-19381 Hoch
    Score 47 CVSS 7.8 EPSS 0.11%

    Kingston FURY CTRL RGB Control Software – Schwachstelle im Treiber NTIOLib_KSFX.sys

  30. CVE-2026-19387 Hoch
    Score 46 CVSS 7.6 EPSS 0.24%

    GStreamer gst-plugins-bad – Heap-Out-of-Bounds-Write im ADPCM-Decoder (adpcmdec)

  31. CVE-2026-19376 Hoch
    Score 44 CVSS 7.3 EPSS 0.35%

    Uasoft Badaso – Schwachstelle in der File API (ApiRequest::class)

  32. CVE-2026-19379 Hoch
    Score 44 CVSS 7.3 EPSS 1.66%

    EFM ipTIME AX8004M 15.09.0: Schwachstelle in CGI-Endpoint /cgi/d.cgi

  33. CVE-2026-19384 Hoch
    Score 44 CVSS 7.3 EPSS 0.26%

    SourceCodester Simple Doctors Appointment System – Schwachstelle in admin/ajax.php (set_appointment)

  34. CVE-2026-19389 Hoch
    Score 43 CVSS 7.1 EPSS 0.26%

    GStreamer gst-plugins-ugly – Integer-Overflow im ASF-Demuxer (asfdemux)

  35. CVE-2026-19378 Mittel
    Score 26 CVSS 4.3 EPSS 0.35%

    code-projects Task Management System – Schwachstelle in CommentSave.php

  36. CVE-2026-19380 Niedrig
    Score 14 CVSS 2.3 EPSS 0.12%

    Mullvad wireguard.sys 0.10.1 – Schwachstelle in AdapterState (IOCTL Handler)

  37. CVE-2026-19348 Kritisch
    Score 59 CVSS 9.8 EPSS 2.46%

    Shenzhen Aitemi M300 Wi-Fi Repeater – Schwachstelle in sprintf-Funktion (protocol.csp)

  38. CVE-2026-19342 Hoch
    Score 44 CVSS 7.3 EPSS 0.40%

    code-projects Task Management System 1.0: Schwachstelle in Login-Komponente

  39. CVE-2026-19343 Hoch
    Score 44 CVSS 7.3 EPSS 0.26%

    code-projects Task Management System – Schwachstelle in admin/AdminLogin.php

  40. CVE-2026-19344 Hoch
    Score 44 CVSS 7.3 EPSS 0.41%

    code-projects Task Management System 1.0 – Schwachstelle in comment_count_user.php

  41. CVE-2026-19345 Mittel
    Score 39 CVSS 6.5 EPSS 0.52%

    code-projects Task Management System 1.0 – Schwachstelle in UpdateTaskStatus.php

  42. CVE-2026-19339 Mittel
    Score 38 CVSS 6.3 EPSS 0.21%

    aliyun alibabacloud-dataworks-mcp-server – Schwachstelle in ReadResourceRequestSchema (initResources.ts)

  43. CVE-2026-19347 Mittel
    Score 38 CVSS 6.3 EPSS 0.20%

    itsourcecode Hospital Management System 1.0 – Schwachstelle in viewdoctor.php

  44. CVE-2026-19350 Mittel
    Score 38 CVSS 6.3 EPSS 0.35%

    Dolibarr ERP – Fehlerhafte Funktion fail im TakePOS-Modul (invoice.php)

  45. CVE-2026-19354 Mittel
    Score 38 CVSS 6.3 EPSS 0.19%

    lock-upme OPMS: Schwachstelle in controllers/messages/message.go

  46. CVE-2026-19364 Mittel
    Score 38 CVSS 6.3 EPSS 0.20%

    itsourcecode Hospital Management System – Schwachstelle in viewdoctorconsultancycharge.php

  47. CVE-2026-19338 Mittel
    Score 32 CVSS 5.3 EPSS 0.14%

    automateyournetwork MCPyATS – Schwachstelle in processGenerateRequest (mermaid/index.ts)

  48. CVE-2026-19365 Mittel
    Score 32 CVSS 5.3 EPSS 0.14%

    Ichigo3766 image-gen-mcp 0.1.0 – Schwachstelle in upscale_images (src/index.ts)

  49. CVE-2026-19369 Mittel
    Score 32 CVSS 5.3 EPSS 0.10%

    KS-GEN-AI jira-mcp-server – Schwachstelle in add_attachment_from_public_url (axios.get)

  50. CVE-2026-19353 Mittel
    Score 30 CVSS 5 EPSS 0.24%

    DedeCMS 5.7.118 UTF8SP2: Schwachstelle in Installation Wizard (_4_Setup)

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.