Live-Feed 1682 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
36300
CVEs gesamt
1682
Aktiv ausgenutzt (KEV)
306
Ransomware-Bezug
6242
Kritisch
Zeige 351 bis 400 von 36300
- CVE-2026-18967 MittelScore 38 CVSS 6.4 EPSS 0.14%
Keycloak – Kontrolldefizit im SAML-Broker bei IdP-Initiated Flow
- CVE-2026-19006 MittelScore 38 CVSS 6.3 EPSS 0.21%
openclaw-cn Ggateway Exec Approval Flow: Schwachstelle in bash-tools.exec.ts
- CVE-2026-19020 MittelScore 38 CVSS 6.3 EPSS 0.20%
itsourcecode Hospital Management System 1.0: Schwachstelle in /servicetype.php
- CVE-2026-18974 MittelScore 32 CVSS 5.3 EPSS 0.31%
heshengtao super-agent-party – Schwachstelle in get_file_content (execute_tool_manually)
- CVE-2025-13394 MittelScore 32 CVSS 5.4 EPSS 0.11%
Carbon-Konsole – CSRF im Ajax-Prozessor durch Nutzung von HTTP GET
- CVE-2026-19011 MittelScore 32 CVSS 5.3 EPSS 0.42%
TinyAGI 0.0.20: Datei-Inklusion in der Funktion buildSystemPrompt
- CVE-2026-18915 MittelScore 30 CVSS 5 EPSS 0.10%
TÜBİTAK BİLGEM eta-otp-lock: Offenlegung sensibler Informationen bei Prozessaufruf
- CVE-2026-19019 MittelScore 29 CVSS 4.8 EPSS 0.30%
poco-ai poco-agent: Schwachstelle in WorkspaceManager._setup_session_persistence
- CVE-2026-18909 MittelScore 28 CVSS 4.7 EPSS 0.08%
ELAN Smart-Pad (ETDSMBus.sys) unter Windows – Stack-based Buffer Overflow
- CVE-2026-18968 MittelScore 26 CVSS 4.3 EPSS 0.26%
ttttonyhe OBlog: Schwachstelle bei der Verarbeitung von /tags.php
- CVE-2026-18995 MittelScore 26 CVSS 4.3 EPSS 0.28%
LobsterAI (netease-youdao) 2026.6.10: Schwachstelle im MEDIA Path Handler
- CVE-2025-11850 MittelScore 26 CVSS 4.3 EPSS 0.21%
Ruby: Implicit-Association-Resolver umgeht primären User Store bei sekundären Stores
- CVE-2025-13909 MittelScore 26 CVSS 4.3 EPSS 0.20%
Unzureichende Mandantentrennung bei Email-OTP-, SMS-OTP- und Magic-Link-Authentifizierung
- CVE-2026-0637 MittelScore 26 CVSS 4.4 EPSS 0.11%
Event Publisher Output Adapter – unzureichend validierte Protokollierung von Eigenschaften
- CVE-2025-13736 NiedrigScore 22 CVSS 3.7 EPSS 0.17%
Multi-Attribute Login: Preisgabe der Existenz von Benutzerkonten
- CVE-2025-12627 NiedrigScore 14 CVSS 2.4 EPSS 0.13%
WSO2 Identity Server – Refresh-Token-Verwaltung im Impersonation-Flow
- CVE-2023-54377 MittelScore 0
Rockwell Automation: CVE-ID zurückgezogen (ersetzt durch korrekte Jahres-ID)
- CVE-2023-54381 MittelScore 0
Rockwell Automation: CVE-ID zurückgezogen (ersetzt durch korrekte Jahres-ID)
- CVE-2023-54385 MittelScore 0
Rockwell Automation: CVE-ID zurückgezogen (falsches Jahr, nie zugewiesen)
- CVE-2023-54389 MittelScore 0
Rockwell Automation: CVE-ID zurückgezogen (falsches Jahr, nie zugewiesen)
- CVE-2026-19027 MittelScore 0 EPSS 0.13%
HDF5: Fehlende Grenzprüfung bei der nbit-Dekompression (H5Znbit.c)
- CVE-2026-67871 MittelScore 0 EPSS 0.27%
Systerel S2OPC: Pufferüberlauf-Schwachstelle in der Knotenverwaltung (AddNodes)
- CVE-2023-54375 MittelScore 0
CVE-2023-54375: Von NVD zurückgezogen – ersetzt durch CVE mit korrektem Jahr
- CVE-2023-54376 MittelScore 0
Rockwell Automation: CVE-ID zurückgezogen (ersetzt durch korrekte Jahres-ID)
- CVE-2023-54380 MittelScore 0
CVE-2023-54380: Von NVD zurückgezogen – ersetzt durch CVE mit korrektem Jahr
- CVE-2023-54382 MittelScore 0
Rockwell Automation: CVE-ID zurückgezogen (ersetzt durch korrekte Jahres-ID)
- CVE-2023-54386 MittelScore 0
CVE-2023-54386: Von NVD zurückgezogen – fälschlich im falschen Jahr reserviert, nie vergeben
- CVE-2023-54387 MittelScore 0
Rockwell Automation: CVE-ID zurückgezogen (falsches Jahr, nie zugewiesen)
- CVE-2026-67872 MittelScore 0 EPSS 0.25%
Systerel S2OPC 1.7.3: Denial of Service über Resize-Handling der Event-Monitored-Item-Queue
- CVE-2026-67870 MittelScore 0 EPSS 0.27%
open62541: Unvollständige Validierung bei AddReferences für nicht-lokale ExpandedNodeIds
- CVE-2023-54379 MittelScore 0
Rockwell Automation: CVE-ID zurückgezogen (ersetzt durch korrekte Jahres-ID)
- CVE-2023-54383 MittelScore 0
Rockwell Automation: CVE-ID nie zugewiesen (fälschlich reserviert)
- CVE-2025-15678 MittelScore 0 EPSS 0.14%
Nexter Blocks WordPress-Plugin vor 5.0.2 – ungefilterter SVG-Upload
- CVE-2026-11588 MittelScore 0 EPSS 0.16%
EONSR AEO Agent: Fehlende Autorisierung und deaktivierte HTML-Bereinigung in REST-Route
- CVE-2026-12713 MittelScore 0 EPSS 0.26%
WPCargo Track & Trace (WordPress-Plugin): SQL-Injection vor Version 8.0.4
- CVE-2026-13153 MittelScore 0 EPSS 0.26%
Gutenberg Essential Blocks WordPress-Plugin: Offengelegte WooCommerce-Verkaufszahlen über öffentliche REST-Route (vor 6.4.0)
- CVE-2026-13154 MittelScore 0 EPSS 0.26%
Gutenberg Essential Blocks WordPress-Plugin vor 6.4.0 – fehlende Prüfung des Post-Typ-Status in REST-Route
- CVE-2026-13703 MittelScore 0 EPSS 0.14%
SEO Redirection Plugin: Fehlende Berechtigungsprüfung bei authentifizierter AJAX-Aktion
- CVE-2026-14204 MittelScore 0 EPSS 0.12%
Google Authenticator (WordPress-Plugin): Fehlende CSRF-Prüfung beim Speichern der 2FA-Einrichtung
- CVE-2026-14240 MittelScore 0 EPSS 0.21%
tourmaster WordPress-Plugin: Vorhersagbarer Exportdateipfad ohne Zugriffskontrolle (vor 5.4.9)
- CVE-2026-14313 MittelScore 0 EPSS 0.12%
PeproDev WooCommerce Receipt Uploader bis 2.8.0 – Schwachstelle (Details unvollständig)
- CVE-2026-14314 MittelScore 0 EPSS 0.24%
PeproDev WooCommerce Receipt Uploader: Zugriff auf fremde Anhänge ohne Authentifizierung
- CVE-2026-14547 MittelScore 0 EPSS 0.18%
Estatik Real Estate Plugin (WordPress): Umgehung der Anti-Spam-Prüfung vor Version 4.3.3
- CVE-2026-14829 MittelScore 0 EPSS 0.19%
Checkimate WordPress-Plugin: Unzureichender Zugriffsschutz der Lizenzverwaltung (bis 1.0.13)
- CVE-2026-16054 MittelScore 0 EPSS 0.27%
Drag and Drop Multiple File Upload for WooCommerce vor 1.1.8 – Nonce-Leak ermöglicht Datei-Löschung
- CVE-2026-16065 MittelScore 0 EPSS 0.23%
Welcart e-Commerce: SQL-Injection über CSV-Import
- CVE-2026-16268 MittelScore 0 EPSS 0.44%
Newsletters (WordPress-Plugin): Ungeprüfte serverseitige URL-Anfrage vor Version 4.16
- CVE-2026-16290 MittelScore 0 EPSS 0.21%
ProfileGrid WordPress-Plugin: Unautorisierter Zugriff auf Gruppen-Mitgliederlisten (vor 6.0.0.0)
- CVE-2026-16537 MittelScore 0 EPSS 0.13%
Slick Slider WordPress-Plugin vor 0.5.3 – fehlende Bereinigung eines Shortcode-Attributs
- CVE-2026-16734 MittelScore 0 EPSS 0.20%
Stripe Payment Forms by WP Full Pay: Fehlende Eigentümerprüfung bei Zahlungsvorgängen
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.