Live-Feed 1649 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
23012
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
296
Ransomware-Bezug
4809
Kritisch
Zeige 3751 bis 3800 von 23012
- CVE-2026-10561 KritischScore 60 CVSS 10 EPSS 0.50%
IBM Langflow OSS: Authentifizierungsumgehung und unzureichende Python-Isolation
- CVE-2026-49468 KritischScore 59 CVSS 9.8 EPSS 0.56%
LiteLLM: Host-Header-Verarbeitungsfehler im Proxy (AI Gateway)
- CVE-2026-7664 KritischScore 59 CVSS 9.8 EPSS 0.28%
IBM Langflow OSS: Fehlende Autorisierung erlaubt Zugriff auf geschützte MCP-Projektressourcen
- CVE-2026-6653 KritischScore 59 CVSS 9.8 EPSS 0.29%
Use-after-free in libxml2 (xmlParseInternalSubset)
- CVE-2026-10789 KritischScore 58 CVSS 9.6 EPSS 0.38%
Autodesk Fusion Desktop: Codeausführung über die MCP-Erweiterung
- CVE-2026-28381 KritischScore 58 CVSS 9.6 EPSS 0.21%
Grafana: Snowflake-Datenquelle erlaubt Datei-Lese- und Schreibzugriffe per GET/PUT
- CVE-2026-11373 KritischScore 55 CVSS 9.1 EPSS 0.35%
Perl-Modul Net::Statsite::Client: Metric Injection durch nicht entfernte Zeilenumbrüche
- CVE-2026-12628 KritischScore 55 CVSS 9.1 EPSS 0.36%
IBM Storage Protect Client: Authentifizierungsumgehung durch fest codierte Zugangsdaten
- CVE-2026-48509 KritischScore 55 CVSS 9.1 EPSS 0.24%
MessagePack for C#: Unsichere Standard-Serializer-Optionen (MessagePackInputFormatter)
- CVE-2026-48746 KritischScore 55 CVSS 9.1 EPSS 1.01%
CVE-2026-48746 – Schwachstelle in vLLM über ASGI-/Starlette-Vertrauensstellung
- CVE-2026-56348 KritischScore 55 CVSS 9.1 EPSS 0.26%
n8n – Credential-Exfiltration über den dynamic-node-parameters-Endpunkt
- CVE-2026-12249 KritischScore 54 CVSS 9 EPSS 0.11%
Canonical ADSys: Schwachstelle beim AD-CS-Zertifikats-Auto-Enrollment
- CVE-2026-44272 HochScore 53 CVSS 8.8 EPSS 0.25%
Dell Wyse Management Suite: SQL-Injection
- CVE-2026-54099 HochScore 53 CVSS 8.8 EPSS 0.07%
Red Hat OpenShift: Schwachstelle im Windows Machine Config Operator (CSR-Auto-Approver)
- CVE-2026-54100 HochScore 50 CVSS 8.3 EPSS 0.18%
Red Hat OpenShift WMCO – fehlende SSH-Host-Key-Verifizierung
- CVE-2025-66336 HochScore 49 CVSS 8.1 EPSS 0.38%
Apache Doris MCP Server – SQL-Injection im Metadaten-Abfragepfad
- CVE-2026-44271 HochScore 49 CVSS 8.1 EPSS 0.25%
SQL-Injection in Dell Wyse Management Suite (WMS)
- CVE-2026-9072 HochScore 49 CVSS 8.1 EPSS 0.41%
IBM WebSphere Application Server – Remote Code Execution (Intelligent Management Plug-in)
- CVE-2026-44274 HochScore 47 CVSS 7.8 EPSS 0.13%
Dell Wyse Management Suite – Improper Link Resolution Before File Access
- CVE-2026-42129 HochScore 46 CVSS 7.7 EPSS 0.39%
Grafana Loki-Datenquelle – Path Traversal ermöglicht Zugriff auf Admin-Endpunkte
- CVE-2025-66389 HochScore 45 CVSS 7.5 EPSS 0.85%
GitHub Copilot: Dateizugriff ausserhalb des Workspace über fetch_webpage
- CVE-2026-42127 HochScore 45 CVSS 7.5 EPSS 0.43%
Grafana – fehlende Begrenzung der Request-Body-Grösse im Public-Dashboard-Endpunkt
- CVE-2026-53539 HochScore 45 CVSS 7.5 EPSS 0.26%
Python-Multipart – fehlerhafte Trennzeichensuche beim Parsen von x-www-form-urlencoded
- CVE-2026-53571 HochScore 45 CVSS 7.5 EPSS 0.39%
Vite: von server.fs.deny geschützte Dateien unter Windows abrufbar
- CVE-2026-8858 HochScore 45 CVSS 7.5 EPSS 0.26%
IBM WebSphere: Remote Code Execution und DoS im Web-Server-Plug-in
- CVE-2026-9071 HochScore 45 CVSS 7.5 EPSS 0.31%
IBM WebSphere Application Server: Denial of Service über präparierte Anfrage
- CVE-2026-10845 HochScore 44 CVSS 7.3 EPSS 0.34%
IBM WebSphere Application Server: Authentifizierungsumgehung für JAX-WS-Anwendungen
- CVE-2026-8646 HochScore 44 CVSS 7.4 EPSS 0.34%
IBM WebSphere Application Server: HTTP Request Smuggling
- CVE-2026-9006 HochScore 44 CVSS 7.4 EPSS 0.22%
IBM WebSphere Application Server: Server-Side Request Forgery über den Ajax-Proxy
- CVE-2026-9029 HochScore 44 CVSS 7.3 EPSS 0.25%
Grafana: Stored Cross-Site-Scripting über das Attributionsfeld eines Geomap-Panels
- CVE-2026-44913 HochScore 43 CVSS 7.2 EPSS 0.39%
Apache NiFi: SQL-Injection im CaptureChangeMySQL-Processor durch fehlerhaftes Escaping von Tabellennamen
- CVE-2026-44914 HochScore 43 CVSS 7.2 EPSS 0.39%
Apache NiFi: Fehlende Autorisierung beim Ersetzen von Process Groups
- CVE-2024-51454 MittelScore 39 CVSS 6.5 EPSS 0.18%
IBM Engineering Workflow Management: HTTP-Header-Injection
- CVE-2024-54178 MittelScore 39 CVSS 6.5 EPSS 0.24%
IBM Db2 (Cloud Pak for Data): Denial of Service beim Anlegen neuer Datenbanken
- CVE-2026-44911 MittelScore 38 CVSS 6.3 EPSS 0.33%
Apache NiFi: Fehlerhafte Autorisierung bei Konfigurationsprüfungsanfragen
- CVE-2026-8059 MittelScore 37 CVSS 6.1 EPSS 0.17%
IBM Datacap / Datacap Navigator: Cross-Site-Scripting
- CVE-2025-2669 MittelScore 36 CVSS 6 EPSS 0.20%
IBM Db2 (Cloud Pak for Data): Informationsoffenlegung durch privilegierten Nutzer
- CVE-2026-44273 MittelScore 36 CVSS 6 EPSS 0.10%
Dell Wyse Management Suite – Verwendung von Standard-Anmeldedaten
- CVE-2026-10852 MittelScore 35 CVSS 5.9 EPSS 0.27%
IBM WebSphere Application Server: Denial of Service im WebServer-Plug-in
- CVE-2026-12725 MittelScore 35 CVSS 5.9 EPSS 0.40%
dnsmasq – Heap-Buffer-Overflow bei aktivierter DNSSEC-Validierung
- CVE-2026-9320 MittelScore 35 CVSS 5.9 EPSS 0.32%
IBM WebSphere Application Server – Denial of Service durch präparierte Anfrage
- CVE-2026-8636 MittelScore 33 CVSS 5.5 EPSS 0.15%
IBM Datacap – Auslesen von Passwörtern und Schlüsseln aus dem Speicher
- CVE-2023-33854 MittelScore 32 CVSS 5.3 EPSS 0.19%
IBM Db2 on Cloud Pak for Data: Umgehung clientseitiger Validierung
- CVE-2025-33128 MittelScore 32 CVSS 5.4 EPSS 0.14%
IBM Engineering Workflow Management: Cross-Site-Scripting
- CVE-2025-62198 MittelScore 32 CVSS 5.4 EPSS 0.32%
Apache Atlas – Authentifiziertes Cross-Site-Scripting (XSS)
- CVE-2026-10601 MittelScore 32 CVSS 5.4 EPSS 0.26%
Grafana: Zugriff auf unbeabsichtigte Backend-Endpunkte über Tempo- und Loki-Plugins
- CVE-2026-11372 MittelScore 32 CVSS 5.4 EPSS 0.17%
IBM TRIRIGA Application Platform – Cross-Site-Scripting (XSS)
- CVE-2026-54665 MittelScore 32 CVSS 5.3 EPSS 0.27%
Apache NiFi: Ungeprüfte HTTP-Header bei der URL-Bildung
- CVE-2026-7253 MittelScore 32 CVSS 5.3 EPSS 0.20%
IBM Sterling File Gateway: Server-Side Request Forgery (SSRF)
- CVE-2026-12549 MittelScore 29 CVSS 4.8 EPSS 0.33%
Regression der CVE-2026-2443-Behebung ermöglicht Overflow bei Range-Requests
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.