Live-Feed 1649 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
23276
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
295
Ransomware-Bezug
4814
Kritisch
Zeige 3901 bis 3950 von 23276
- CVE-2026-12725 MittelScore 35 CVSS 5.9 EPSS 0.40%
dnsmasq – Heap-Buffer-Overflow bei aktivierter DNSSEC-Validierung
- CVE-2026-9320 MittelScore 35 CVSS 5.9 EPSS 0.32%
IBM WebSphere Application Server – Denial of Service durch präparierte Anfrage
- CVE-2026-8636 MittelScore 33 CVSS 5.5 EPSS 0.15%
IBM Datacap – Auslesen von Passwörtern und Schlüsseln aus dem Speicher
- CVE-2023-33854 MittelScore 32 CVSS 5.3 EPSS 0.19%
IBM Db2 on Cloud Pak for Data: Umgehung clientseitiger Validierung
- CVE-2025-33128 MittelScore 32 CVSS 5.4 EPSS 0.14%
IBM Engineering Workflow Management: Cross-Site-Scripting
- CVE-2025-62198 MittelScore 32 CVSS 5.4 EPSS 0.32%
Apache Atlas – Authentifiziertes Cross-Site-Scripting (XSS)
- CVE-2026-10601 MittelScore 32 CVSS 5.4 EPSS 0.26%
Grafana: Zugriff auf unbeabsichtigte Backend-Endpunkte über Tempo- und Loki-Plugins
- CVE-2026-11372 MittelScore 32 CVSS 5.4 EPSS 0.17%
IBM TRIRIGA Application Platform – Cross-Site-Scripting (XSS)
- CVE-2026-54665 MittelScore 32 CVSS 5.3 EPSS 0.27%
Apache NiFi: Ungeprüfte HTTP-Header bei der URL-Bildung
- CVE-2026-7253 MittelScore 32 CVSS 5.3 EPSS 0.20%
IBM Sterling File Gateway: Server-Side Request Forgery (SSRF)
- CVE-2026-12549 MittelScore 29 CVSS 4.8 EPSS 0.33%
Regression der CVE-2026-2443-Behebung ermöglicht Overflow bei Range-Requests
- CVE-2026-48931 NiedrigScore 22 CVSS 3.7 EPSS 0.37%
Node.js: HTTP-Agent akzeptiert verfrühte Server-Antwort
- CVE-2026-53537 NiedrigScore 22 CVSS 3.7 EPSS 0.18%
python-multipart: Fehlerhaftes Parsen von Content-Disposition-Headern
- CVE-2026-53538 NiedrigScore 22 CVSS 3.7 EPSS 0.18%
Python-Multipart: Fehlerhafte Feldtrennung im QuerystringParser
- CVE-2026-53540 NiedrigScore 22 CVSS 3.7 EPSS 0.22%
python-multipart: Fehlende Content-Length-Validierung im Multipart-Parser
- CVE-2026-9610 NiedrigScore 14 CVSS 2.3 EPSS 0.19%
IBM Datacap: Zugriff auf nicht verlinkte Ressourcen (Forced Browsing)
- CVE-2026-56265 KritischScore 59 CVSS 9.8 EPSS 0.41%
Crawl4AI: Authentifizierungsumgehung durch fest hinterlegten JWT-Signaturschlüssel
- CVE-2026-56395 KritischScore 58 CVSS 9.6 EPSS 0.39%
SiYuan: HTML-/JavaScript-Injektion über Paket-Metadaten im Bazaar-Marktplatz
- CVE-2026-56397 KritischScore 58 CVSS 9.6 EPSS 0.39%
SiYuan: HTML-/JavaScript-Injection über Paket-Metadaten im Bazaar-Marktplatz
- CVE-2026-52911 HochScore 53 CVSS 8.8 EPSS 0.36%
Linux-Kernel: ksmbd – conn->binding-Slowpath auf gebundene Sessions begrenzt
- CVE-2026-12773 HochScore 44 CVSS 7.3 EPSS 0.61%
BerriAI litellm – fehlerhafte Authentifizierung im MCP Proxy
- CVE-2026-48908 Kritisch Aktiv ausgenutztScore 100 CVSS 9.8 EPSS 1.57%
SP Page Builder für Joomla: Unauthentifizierter Datei-Upload mit Codeausführung
- CVE-2026-48939 Kritisch Aktiv ausgenutztScore 100 CVSS 9.8 EPSS 1.50%
Joomla-Erweiterung iCagenda: Upload beliebiger Dateien führt zu PHP-Code-Ausführung
- CVE-2019-25763 KritischScore 59 CVSS 9.8 EPSS 0.43%
WordPress Ultimate Addons for Beaver Builder: Authentifizierungsumgehung
- CVE-2022-50972 KritischScore 59 CVSS 9.8 EPSS 0.63%
WooCommerce 7.1.0: Remote Code Execution über den Parameter product-type
- CVE-2024-58351 KritischScore 59 CVSS 9.8 EPSS 0.65%
Flowise: Konfigurations-Injection über overrideConfig
- CVE-2026-11551 KritischScore 59 CVSS 9.8 EPSS 0.63%
WordPress-Plugin Branda bis 3.4.29: Privilege Escalation durch Account-Übernahme
- CVE-2026-5366 KritischScore 59 CVSS 9.9 EPSS 0.87%
Prefect 3.6.23: Remote Code Execution über commit_sha in GitRepository
- CVE-2026-9265 KritischScore 55 CVSS 9.1 EPSS 0.35%
Crypt::OpenSSL::PKCS12 (Perl) – Heap-Out-of-bounds-Read im UTF8STRING-Pfad
- CVE-2026-45480 KritischScore 60 CVSS 10 EPSS 0.56%
Azure Active Directory: fehlerhafte Authentifizierung ermöglicht Rechteausweitung
- CVE-2026-48772 KritischScore 60 CVSS 10 EPSS 0.18%
ProxySQL: MySQL-Frontend akzeptiert gefälschte PROXY-Protokoll-Frames
- CVE-2026-50242 KritischScore 60 CVSS 10 EPSS 0.42%
JetBrains Hub: Authentifizierungsumgehung über direkten Datenbankzugriff
- CVE-2026-40624 KritischScore 59 CVSS 9.8 EPSS 0.62%
AVer PTC-Kameras: Remote Code Execution durch unzureichende Eingabevalidierung
- CVE-2026-48584 KritischScore 59 CVSS 9.9 EPSS 0.50%
Azure Synapse: Rechteausweitung durch Ausführung mit unnötigen Privilegien
- CVE-2026-48773 KritischScore 59 CVSS 9.8 EPSS 0.36%
ProxySQL: Heap-Speicherkorruption vor der Authentifizierung im MySQL- und PostgreSQL-Protokoll
- CVE-2026-51843 KritischScore 59 CVSS 9.8 EPSS 0.38%
Tenda AC7: Stack-Buffer-Overflow in /goform/AdvSetMacMtuWan
- CVE-2026-51844 KritischScore 59 CVSS 9.8 EPSS 0.38%
Tenda AC7: Stack-Buffer-Overflow in /goform/AdvSetMacMtuWan
- CVE-2026-51845 KritischScore 59 CVSS 9.8 EPSS 0.38%
Tenda AC7 v15.03.06.44: Stack-Buffer-Overflow in /goform/AdvSetMacMtuWan
- CVE-2026-51846 KritischScore 59 CVSS 9.8 EPSS 0.58%
Tenda AC7: Stack-Buffer-Overflow im wanSpeed-Parameter von /goform/AdvSetMacMtuWan
- CVE-2026-54414 KritischScore 59 CVSS 9.8 EPSS 0.72%
FileRise: Path Traversal im Shared-Folder-Upload führt zur Übernahme des Admin-Kontos
- CVE-2026-56141 KritischScore 59 CVSS 9.8 EPSS 0.36%
JetBrains Hub: Account-Übernahme durch vorhersagbare Wiederherstellungscodes
- CVE-2026-56142 KritischScore 59 CVSS 9.9 EPSS 0.42%
JetBrains Hub – Rechteausweitung durch Anhängen von Authentifizierungsdaten an Konten
- CVE-2026-7515 KritischScore 59 CVSS 9.8 EPSS 0.89%
BetterDocs Pro (WordPress): Local File Inclusion über den Parameter doc_style
- CVE-2026-48582 KritischScore 58 CVSS 9.6 EPSS 0.39%
Microsoft Exchange Online: Fehlende Autorisierung ermöglicht Rechteausweitung
- CVE-2026-12048 KritischScore 56 CVSS 9.3 EPSS 0.21%
pgAdmin 4: Stored Cross-Site-Scripting in Fehler- und Plan-Node-Darstellung
- CVE-2026-49871 KritischScore 56 CVSS 9.3 EPSS 0.26%
cas-auth-Plugin: Cross-Site Request Forgery in der Standardkonfiguration
- CVE-2026-56073 KritischScore 56 CVSS 9.4 EPSS 0.19%
Cap-go: Umgehung der OTP-basierten E-Mail-Verifizierung
- CVE-2025-62821 KritischScore 55 CVSS 9.1 EPSS 0.82%
Microsoft HEIF Image Extensions: Out-of-bounds Read bei der Ermittlung der Datengrösse
- CVE-2026-39999 KritischScore 55 CVSS 9.1 EPSS 0.39%
Apache APISIX: Authentifizierungsumgehung über das jwt-auth-Plugin
- CVE-2026-44087 KritischScore 55 CVSS 9.1 EPSS 0.21%
Apache APISIX: Identitäts-Spoofing im openid-connect-Plugin
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.