Live-Feed 1644 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
22387
CVEs gesamt
1644
Aktiv ausgenutzt (KEV)
290
Ransomware-Bezug
4549
Kritisch
Zeige 3501 bis 3550 von 22387
- CVE-2026-35267 HochScore 53 CVSS 8.8 EPSS 0.43%
Schwachstelle in Oracle Identity Manager (REST-Webservices)
- CVE-2026-35299 HochScore 53 CVSS 8.8 EPSS 0.40%
Oracle WebLogic Server: Schwachstelle in der Console-Komponente
- CVE-2026-35303 HochScore 53 CVSS 8.8 EPSS 0.40%
Schwachstelle in der Console von Oracle WebLogic Server
- CVE-2026-35311 HochScore 53 CVSS 8.8 EPSS 0.40%
Oracle WebLogic Server (Fusion Middleware): Leicht ausnutzbare Schwachstelle in der Core-Komponente
- CVE-2026-35258 HochScore 52 CVSS 8.7 EPSS 0.33%
Oracle WebLogic Server: Schwachstelle in der Console-Komponente
- CVE-2026-35271 HochScore 52 CVSS 8.7 EPSS 0.34%
Schwachstelle in Oracle PeopleSoft PT PeopleTools (Weblogic)
- CVE-2026-46870 HochScore 51 CVSS 8.5 EPSS 0.31%
Schwachstelle in Oracle MySQL Shell for VS Code
- CVE-2026-12437 HochScore 50 CVSS 8.3 EPSS 0.28%
Use-after-free in Google Chrome für Windows (WebShare)
- CVE-2026-12438 HochScore 50 CVSS 8.3 EPSS 0.21%
Google Chrome: Fehlerhafte Implementierung in WebView (Android)
- CVE-2026-12451 HochScore 50 CVSS 8.3 EPSS 0.17%
Use-after-free in DigitalCredentials von Google Chrome
- CVE-2026-12454 HochScore 50 CVSS 8.3 EPSS 0.15%
Google Chrome (macOS): Race Condition in Safe Browsing (Sandbox-Ausbruch)
- CVE-2026-12464 HochScore 50 CVSS 8.3 EPSS 0.22%
Google Chrome: Use-after-free in Browser
- CVE-2026-12465 HochScore 50 CVSS 8.3 EPSS 0.24%
Object-Lifecycle-Fehler in Metrics (Google Chrome)
- CVE-2026-12467 HochScore 50 CVSS 8.3 EPSS 0.22%
Google Chrome: Sandbox-Escape durch Use-after-free in Extensions
- CVE-2026-12468 HochScore 50 CVSS 8.3 EPSS 0.14%
Google Chrome unter macOS: Race Condition im Updater ermöglicht Sandbox-Escape
- CVE-2026-35272 HochScore 50 CVSS 8.4 EPSS 0.20%
Schwachstelle in Oracle PeopleSoft PeopleTools (Deployment Package)
- CVE-2026-35302 HochScore 50 CVSS 8.3 EPSS 0.30%
Oracle WebLogic Server (Console) – Schwachstelle in Oracle Fusion Middleware
- CVE-2026-11311 HochScore 49 CVSS 8.1 EPSS 0.57%
NGINX Gateway Fabric: Injection im Konfigurationsgenerator
- CVE-2026-30802 HochScore 49 CVSS 8.2 EPSS 0.25%
RTI Connext Micro – Out-of-bounds Read in den Core Libraries
- CVE-2026-32804 HochScore 49 CVSS 8.1 EPSS 0.22%
Dell PowerFlex Manager: Authentifizierungsumgehung über benachbartes Netzwerk
- CVE-2026-35274 HochScore 49 CVSS 8.2 EPSS 0.39%
Oracle PeopleSoft PeopleTools (Deployment Package): leicht ausnutzbare Schwachstelle
- CVE-2026-35276 HochScore 49 CVSS 8.1 EPSS 0.44%
Oracle PeopleSoft PeopleTools – Schwachstelle im Application Server
- CVE-2026-35279 HochScore 49 CVSS 8.1 EPSS 0.39%
Oracle PeopleSoft PeopleTools (Performance Monitor): schwer ausnutzbare Schwachstelle
- CVE-2026-35288 HochScore 49 CVSS 8.2 EPSS 0.19%
Oracle PeopleSoft PeopleTools – Schwachstelle in Deployment Package
- CVE-2026-35289 HochScore 49 CVSS 8.1 EPSS 0.41%
Oracle PeopleSoft PeopleTools – Schwachstelle in Deployment Package
- CVE-2026-42055 HochScore 49 CVSS 8.1 EPSS 3.55%
Schwachstelle in NGINX Plus und NGINX Open Source (HTTP/2-Proxy- und gRPC-Module)
- CVE-2026-42530 HochScore 49 CVSS 8.1 EPSS 3.23%
NGINX Open Source – Schwachstelle im HTTP/3-Modul (ngx_http_v3_module)
- CVE-2026-46849 HochScore 49 CVSS 8.1 EPSS 0.38%
Oracle PeopleSoft CS Student Financials – Schwachstelle
- CVE-2026-46851 HochScore 49 CVSS 8.1 EPSS 0.46%
Oracle PeopleSoft Enterprise CS Campus Community – Schwachstelle in der Security-Komponente
- CVE-2026-50107 HochScore 49 CVSS 8.1 EPSS 0.49%
Injection-Schwachstelle im Konfigurationsgenerator von NGINX Gateway Fabric
- CVE-2026-55200 HochScore 49 CVSS 8.1 EPSS 0.73%
libssh2: Out-of-bounds-Write in ssh2_transport_read()
- CVE-2025-48640 HochScore 48 CVSS 8 EPSS 0.09%
Android – Rechteausweitung durch fehlende Berechtigungsprüfung bei Passkey-Pairing
- CVE-2025-48617 HochScore 47 CVSS 7.8 EPSS 0.08%
Android CarrierConfigLoader: Rechteausweitung durch UID-Prüfungsumgehung
- CVE-2025-48643 HochScore 47 CVSS 7.8 EPSS 0.08%
Android – Provisioning-Bypass durch fehlerhafte Eingabeprüfung
- CVE-2026-0019 HochScore 47 CVSS 7.8 EPSS 0.08%
Android SettingsLib – Rechteausweitung durch Logikfehler
- CVE-2026-0063 HochScore 47 CVSS 7.8 EPSS 0.15%
Android: Umgehung von Carrier-Restriktionen (setAllowedCarriers)
- CVE-2026-0068 HochScore 47 CVSS 7.8 EPSS 0.12%
Android PackageInstallerService: Entfernen einer DPC-App ohne DO-Zustimmung
- CVE-2026-0071 HochScore 47 CVSS 7.8 EPSS 0.15%
Android/ChromeOS – Fehlende Berechtigungsprüfung in SettingsLib
- CVE-2026-0081 HochScore 47 CVSS 7.8 EPSS 0.15%
Android NFC: Rechteausweitung durch Spoofing eines NFC-Ereignisses
- CVE-2026-0082 HochScore 47 CVSS 7.8 EPSS 0.17%
Android – Rechteausweitung über NfcDispatcher (unsicherer Standardwert)
- CVE-2026-12449 HochScore 47 CVSS 7.8 EPSS 0.11%
Google Chrome (Windows): Rechteausweitung durch Use-after-free in Chromoting
- CVE-2026-28615 HochScore 47 CVSS 7.8 EPSS 0.12%
Android Telecomm: Rechteausweitung durch unautorisierten Telefonanruf
- CVE-2026-32652 HochScore 47 CVSS 7.8 EPSS 0.10%
Dell AIOps Collector – Verwendung von Standard-Zugangsdaten
- CVE-2026-46848 HochScore 47 CVSS 7.9 EPSS 0.15%
Oracle WebLogic Server – Schwachstelle in der Console
- CVE-2026-12445 HochScore 45 CVSS 7.5 EPSS 0.16%
Google Chrome – Use-after-free in Extensions
- CVE-2026-12455 HochScore 45 CVSS 7.5 EPSS 0.23%
Google Chrome: Use-after-free im Tab Strip
- CVE-2026-12462 HochScore 45 CVSS 7.5 EPSS 0.27%
Google Chrome (Media) – Use-after-free ermöglicht Codeausführung
- CVE-2026-20190 HochScore 45 CVSS 7.5 EPSS 0.41%
Cisco ISE / ISE-PIC: Fehlerhafte Autorisierung ermöglicht Zugriff auf sensible Informationen
- CVE-2026-22283 HochScore 45 CVSS 7.5 EPSS 0.21%
Dell PowerFlex Manager: Einbindung von Funktionen aus nicht vertrauenswürdiger Quelle
- CVE-2026-35269 HochScore 45 CVSS 7.5 EPSS 0.35%
Oracle Fusion Middleware Identity Manager – Schwachstelle in REST WebServices
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.