Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 301 bis 350 von 36300
- CVE-2026-19361 NiedrigScore 22 CVSS 3.7 EPSS 0.28%
macrozheng mall – Schwachstelle in sso/getAuthCode (mall-portal-Modul)
- CVE-2026-17017 MittelScore 0 EPSS 0.22%
WordPress-Plugin „CubeWP Framework“ – SQL-Injection über AJAX-Aktion
- CVE-2026-17044 MittelScore 0 EPSS 0.26%
Iptanus File Upload (WordPress-Plugin) – SQL-Injection vor Version 5.1.8
- CVE-2026-18032 MittelScore 0 EPSS 0.26%
WP Data Access (WordPress-Plugin) – fehlende Validierung von Spaltennamen in AJAX-Aktion
- CVE-2026-18037 MittelScore 0 EPSS 0.16%
Create (WordPress-Plugin): Fehlende Autorisierungsprüfung in REST-API-Route
- CVE-2026-18357 MittelScore 0 EPSS 0.26%
WordPress-Plugin „WPC Order Tip for WooCommerce“ – fehlende Autorisierungs-/Nonce-Prüfung in Reporting-Funktion
- CVE-2026-18464 MittelScore 0 EPSS 0.30%
WP MAPS PRO (WordPress-Plugin) – Fehlende Capability-Prüfung in AJAX-Aktion
- CVE-2026-18465 MittelScore 0 EPSS 0.25%
WP MAPS PRO (WordPress-Plugin) – fehlende Berechtigungsprüfung in AJAX-Aktion
- CVE-2026-18473 MittelScore 0 EPSS 0.28%
WP Directory Kit (WordPress-Plugin): SQL-Injection durch unauthentifizierte Angreifer
- CVE-2026-18603 MittelScore 0 EPSS 0.24%
WordPress-Plugin „PiWeb Cancel order / Refund request for WooCommerce“ – fehlende Berechtigungsprüfung beim Warenkorb
- CVE-2022-4995 KritischScore 59 CVSS 9.8
Weaver E-cology Datei-Upload-Schwachstelle
- CVE-2026-14205 KritischScore 59 CVSS 9.8 EPSS 0.27%
WordPress-Plugin WP Events Manager: Preisberechnung durch manipulierbare Bestellmenge
- CVE-2026-16258 KritischScore 59 CVSS 9.8 EPSS 0.47%
Ajax Search Lite (WordPress): PHP Object Injection durch unsichere Deserialisierung
- CVE-2026-19264 KritischScore 59 CVSS 9.8 EPSS 0.77%
Path Traversal beim Ausliefern lokal gespeicherter Medien
- CVE-2026-61808 KritischScore 59 CVSS 9.8 EPSS 0.34%
LightRAG API-Server: Authentifizierung standardmässig deaktiviert bei Bindung an alle Netzwerkschnittstellen
- CVE-2026-64637 KritischScore 59 CVSS 9.9
Plesk: Rechteausweitung über XML-RPC-API (Reseller zu Root)
- CVE-2026-71558 KritischScore 59 CVSS 9.8 EPSS 0.21%
Apache Fory C++: Heap-Type-Confusion in der Deserialisierung
- CVE-2026-46409 KritischScore 58 CVSS 9.6 EPSS 0.36%
OpenYak Desktop: Unsicher gebundene lokale HTTP-API vor Version 1.1.3
- CVE-2026-50540 KritischScore 58 CVSS 9.6 EPSS 0.40%
Kata Containers: Schwachstelle in kata-runtime vor Version 4.0.0
- CVE-2026-16038 KritischScore 55 CVSS 9.1 EPSS 0.24%
WordPress-Plugin MStore API: Fehlende Zahlungsverifikation bei Bestell-Endpunkten
- CVE-2026-48039 KritischScore 55 CVSS 9.1
Meta Ads MCP: Schwachstelle in AuthInjectionMiddleware.dispatch() vor Version 1.0.109
- CVE-2026-48170 KritischScore 55 CVSS 9.1 EPSS 0.25%
scim-patch – Prototype Pollution bei SCIM-PATCH-Operationen
- CVE-2026-71560 KritischScore 55 CVSS 9.1 EPSS 0.18%
Apache Fory C++ Out-of-Bounds Read bei der Deserialisierung
- CVE-2026-71851 KritischScore 54 CVSS 9
crypto-js: Unsichere Zufallszahlengenerierung in WordArray.random()
- CVE-2026-15215 HochScore 53 CVSS 8.8 EPSS 0.35%
Subscriptions for WooCommerce: Fehlende Berechtigungsprüfung bei der Plugin-Installation
- CVE-2026-16263 HochScore 53 CVSS 8.8 EPSS 0.33%
WordPress-Plugin WP Maps: Fehlende Berechtigungsprüfung ermöglicht File Inclusion
- CVE-2026-48169 HochScore 53 CVSS 8.8 EPSS 0.26%
PraisonAI Platform API: Zwei Autorisierungsfehler brechen Workspace-Isolation
- CVE-2026-9169 HochScore 53 CVSS 8.8 EPSS 0.14%
LUCID Vision Labs Arena SDK – DLL Search Order Hijacking unter Windows
- CVE-2026-48026 HochScore 52 CVSS 8.7 EPSS 0.22%
lakeFS Web UI – Schwachstelle beim Rendering
- CVE-2026-48120 HochScore 52 CVSS 8.6 EPSS 0.14%
Kakoune: autorestore.kak-Skript anfällig für bösartige Backup-Dateien
- CVE-2026-65400 Kritisch Aktiv ausgenutztScore 100 CVSS 9.8 EPSS 9.90%
Apple macOS – Improper Authentication Vulnerability
- CVE-2026-5430 KritischScore 60 CVSS 10 EPSS 0.22%
Craft CMS: JWT-Authentifizierung akzeptiert Token mit nicht konfiguriertem Signaturalgorithmus
- CVE-2026-1728 KritischScore 59 CVSS 9.8 EPSS 0.30%
Unzureichend eingeschränkte Tokens ermöglichen Zugriff auf Admin-REST-APIs
- CVE-2025-15039 KritischScore 56 CVSS 9.4 EPSS 0.39%
Adaptive Authentication: Unzureichende Durchsetzung mehrstufiger Anmeldeschritte
- CVE-2026-15991 HochScore 53 CVSS 8.8 EPSS 0.61%
File Manager (WordPress) – Beliebiges Löschen von Dateien durch unzureichende Pfadvalidierung
- CVE-2026-15459 HochScore 49 CVSS 8.1 EPSS 0.51%
WPMU DEV Dashboard Plugin für WordPress: Authentifizierungsumgehung
- CVE-2026-67869 HochScore 45 CVSS 7.5 EPSS 0.47%
open62541: Pufferüberlauf in Service_Call durch unzureichende Eingabevalidierung
- CVE-2026-18970 HochScore 44 CVSS 7.3 EPSS 0.25%
Rongzhitong Visual Integrated Command and Dispatch Platform – Schwachstelle in /dm/dispatch/user/findAll
- CVE-2026-18973 HochScore 44 CVSS 7.3 EPSS 0.30%
heshengtao super-agent-party: Schwachstelle in sanitize_proxy_url (extension_proxy)
- CVE-2026-19000 HochScore 44 CVSS 7.3 EPSS 0.29%
JeecgBoot bis Version 3.9.2: Schwachstelle im Anonymous Chat Attachment Parser
- CVE-2026-19009 HochScore 44 CVSS 7.3 EPSS 0.39%
TinyAGI 0.0.20: Schwachstelle in der Funktion collectFiles (Message API Endpoint)
- CVE-2026-19010 HochScore 44 CVSS 7.3 EPSS 0.37%
TinyAGI 0.0.20: Sicherheitslücke in der Funktion processMessage (Message API Endpoint)
- CVE-2026-19021 HochScore 44 CVSS 7.3 EPSS 0.26%
SourceCodester Computer Repair Shop Management System 1.0 – Schwachstelle in /classes/Master.php
- CVE-2026-16636 HochScore 43 CVSS 7.2 EPSS 0.31%
FluentSMTP (WordPress) – Gespeichertes Cross-Site-Scripting über den Empfänger-Anzeigenamen
- CVE-2026-18325 HochScore 43 CVSS 7.2 EPSS 0.28%
WordPress Forminator Forms: Stored Cross-Site Scripting über gefälschten Upload-Datensatz
- CVE-2026-18510 HochScore 43 CVSS 7.2 EPSS 0.24%
TranslatePress: Gespeichertes Cross-Site Scripting über Kommentarinhalte
- CVE-2026-18996 MittelScore 38 CVSS 6.3 EPSS 0.24%
cosmicstack-labs mercury-agent: Schwachstelle in PermissionManager.checkShellCommand
- CVE-2026-18997 MittelScore 38 CVSS 6.3 EPSS 0.21%
cosmicstack-labs mercury-agent bis 1.1.12: Schwachstelle in Agent.handleBgCommand (bg Command Handler)
- CVE-2026-18998 MittelScore 38 CVSS 6.3 EPSS 0.21%
cosmicstack-labs mercury-agent: Schwachstelle in SubAgent.run (delegate_task Tool)
- CVE-2026-18400 MittelScore 38 CVSS 6.4 EPSS 0.25%
MetaSlider WordPress-Plugin: Stored XSS über die 'delay'-Post-Meta-Einstellung
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.