Live-Feed 1649 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

23328
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
295
Ransomware-Bezug
4831
Kritisch

Zeige 3951 bis 4000 von 23328

  1. CVE-2026-12773 Hoch
    Score 44 CVSS 7.3 EPSS 0.61%

    BerriAI litellm – fehlerhafte Authentifizierung im MCP Proxy

  2. CVE-2026-48908 Kritisch Aktiv ausgenutzt
    Score 100 CVSS 9.8 EPSS 1.57%

    SP Page Builder für Joomla: Unauthentifizierter Datei-Upload mit Codeausführung

  3. CVE-2026-48939 Kritisch Aktiv ausgenutzt
    Score 100 CVSS 9.8 EPSS 1.50%

    Joomla-Erweiterung iCagenda: Upload beliebiger Dateien führt zu PHP-Code-Ausführung

  4. CVE-2019-25763 Kritisch
    Score 59 CVSS 9.8 EPSS 0.43%

    WordPress Ultimate Addons for Beaver Builder: Authentifizierungsumgehung

  5. CVE-2022-50972 Kritisch
    Score 59 CVSS 9.8 EPSS 0.63%

    WooCommerce 7.1.0: Remote Code Execution über den Parameter product-type

  6. CVE-2024-58351 Kritisch
    Score 59 CVSS 9.8 EPSS 0.65%

    Flowise: Konfigurations-Injection über overrideConfig

  7. CVE-2026-11551 Kritisch
    Score 59 CVSS 9.8 EPSS 0.63%

    WordPress-Plugin Branda bis 3.4.29: Privilege Escalation durch Account-Übernahme

  8. CVE-2026-5366 Kritisch
    Score 59 CVSS 9.9 EPSS 0.87%

    Prefect 3.6.23: Remote Code Execution über commit_sha in GitRepository

  9. CVE-2026-9265 Kritisch
    Score 55 CVSS 9.1 EPSS 0.35%

    Crypt::OpenSSL::PKCS12 (Perl) – Heap-Out-of-bounds-Read im UTF8STRING-Pfad

  10. CVE-2026-45480 Kritisch
    Score 60 CVSS 10 EPSS 0.56%

    Azure Active Directory: fehlerhafte Authentifizierung ermöglicht Rechteausweitung

  11. CVE-2026-48772 Kritisch
    Score 60 CVSS 10 EPSS 0.18%

    ProxySQL: MySQL-Frontend akzeptiert gefälschte PROXY-Protokoll-Frames

  12. CVE-2026-50242 Kritisch
    Score 60 CVSS 10 EPSS 0.42%

    JetBrains Hub: Authentifizierungsumgehung über direkten Datenbankzugriff

  13. CVE-2026-40624 Kritisch
    Score 59 CVSS 9.8 EPSS 0.62%

    AVer PTC-Kameras: Remote Code Execution durch unzureichende Eingabevalidierung

  14. CVE-2026-48584 Kritisch
    Score 59 CVSS 9.9 EPSS 0.50%

    Azure Synapse: Rechteausweitung durch Ausführung mit unnötigen Privilegien

  15. CVE-2026-48773 Kritisch
    Score 59 CVSS 9.8 EPSS 0.36%

    ProxySQL: Heap-Speicherkorruption vor der Authentifizierung im MySQL- und PostgreSQL-Protokoll

  16. CVE-2026-51843 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    Tenda AC7: Stack-Buffer-Overflow in /goform/AdvSetMacMtuWan

  17. CVE-2026-51844 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    Tenda AC7: Stack-Buffer-Overflow in /goform/AdvSetMacMtuWan

  18. CVE-2026-51845 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    Tenda AC7 v15.03.06.44: Stack-Buffer-Overflow in /goform/AdvSetMacMtuWan

  19. CVE-2026-51846 Kritisch
    Score 59 CVSS 9.8 EPSS 0.58%

    Tenda AC7: Stack-Buffer-Overflow im wanSpeed-Parameter von /goform/AdvSetMacMtuWan

  20. CVE-2026-54414 Kritisch
    Score 59 CVSS 9.8 EPSS 0.72%

    FileRise: Path Traversal im Shared-Folder-Upload führt zur Übernahme des Admin-Kontos

  21. CVE-2026-56141 Kritisch
    Score 59 CVSS 9.8 EPSS 0.36%

    JetBrains Hub: Account-Übernahme durch vorhersagbare Wiederherstellungscodes

  22. CVE-2026-56142 Kritisch
    Score 59 CVSS 9.9 EPSS 0.42%

    JetBrains Hub – Rechteausweitung durch Anhängen von Authentifizierungsdaten an Konten

  23. CVE-2026-7515 Kritisch
    Score 59 CVSS 9.8 EPSS 0.89%

    BetterDocs Pro (WordPress): Local File Inclusion über den Parameter doc_style

  24. CVE-2026-48582 Kritisch
    Score 58 CVSS 9.6 EPSS 0.39%

    Microsoft Exchange Online: Fehlende Autorisierung ermöglicht Rechteausweitung

  25. CVE-2026-12048 Kritisch
    Score 56 CVSS 9.3 EPSS 0.21%

    pgAdmin 4: Stored Cross-Site-Scripting in Fehler- und Plan-Node-Darstellung

  26. CVE-2026-49871 Kritisch
    Score 56 CVSS 9.3 EPSS 0.26%

    cas-auth-Plugin: Cross-Site Request Forgery in der Standardkonfiguration

  27. CVE-2026-56073 Kritisch
    Score 56 CVSS 9.4 EPSS 0.19%

    Cap-go: Umgehung der OTP-basierten E-Mail-Verifizierung

  28. CVE-2025-62821 Kritisch
    Score 55 CVSS 9.1 EPSS 0.82%

    Microsoft HEIF Image Extensions: Out-of-bounds Read bei der Ermittlung der Datengrösse

  29. CVE-2026-39999 Kritisch
    Score 55 CVSS 9.1 EPSS 0.39%

    Apache APISIX: Authentifizierungsumgehung über das jwt-auth-Plugin

  30. CVE-2026-44087 Kritisch
    Score 55 CVSS 9.1 EPSS 0.21%

    Apache APISIX: Identitäts-Spoofing im openid-connect-Plugin

  31. CVE-2026-48137 Kritisch
    Score 55 CVSS 9.1 EPSS 0.55%

    NI grpc-device – Untrusted Pointer Dereference in der Sideband-Streaming-API

  32. CVE-2026-49230 Kritisch
    Score 55 CVSS 9.1 EPSS 0.22%

    Apache APISIX – Authentifizierungsumgehung im jwe-decrypt-Plugin

  33. CVE-2026-56081 Kritisch
    Score 55 CVSS 9.1 EPSS 0.35%

    Cap-go – Fehler in der Authentifizierungslogik ermöglicht Kontoübernahme

  34. CVE-2026-8713 Kritisch
    Score 55 CVSS 9.1 EPSS 1.19%

    WordPress Avada (Fusion) Builder – Beliebiges Löschen von Dateien

  35. CVE-2026-9142 Kritisch
    Score 55 CVSS 9.1 EPSS 0.31%

    NI grpc-device – Unsichere Standard-Zugangsdaten ohne TLS-Konfiguration

  36. CVE-2026-12045 Kritisch
    Score 54 CVSS 9 EPSS 0.48%

    pgAdmin 4 (AI Assistant): Umgehung des Read-Only-Modus ermöglicht beliebiges SQL

  37. CVE-2026-12046 Kritisch
    Score 54 CVSS 9 EPSS 0.71%

    pgAdmin 4 – Schwachstelle in zustandsändernden SQL-Editor-Endpunkten

  38. CVE-2026-39998 Hoch
    Score 53 CVSS 8.8 EPSS 0.40%

    Apache APISIX: Improper Input Validation im forward-auth-Plugin

  39. CVE-2026-47645 Hoch
    Score 53 CVSS 8.8 EPSS 0.41%

    Open Redirect in Microsoft 365 Copilot Business Chat

  40. CVE-2026-47339 Hoch
    Score 49 CVSS 8.1 EPSS 0.29%

    Fehlerhafte Autorisierung in Apache APISIX (authz-casdoor-Plugin)

  41. CVE-2026-49872 Hoch
    Score 49 CVSS 8.1 EPSS 0.32%

    Apache APISIX – fehlerhafte Authentifizierung im cas-auth-Plugin

  42. CVE-2016-20094 Hoch
    Score 47 CVSS 7.8 EPSS 0.18%

    AnyDesk 2.5.0: Codeausführung mit SYSTEM-Rechten über ungequoteten Dienstpfad

  43. CVE-2026-46461 Hoch
    Score 47 CVSS 7.8 EPSS 0.10%

    Dell Server Hardware Manager – Improper Access Control (vor Version 3.2.2)

  44. CVE-2026-52908 Hoch
    Score 47 CVSS 7.8 EPSS 0.13%

    Linux-Kernel: Inkompatible REREG_ACCESS-Prüfung bei RDMA rereg_mr

  45. CVE-2026-52909 Hoch
    Score 47 CVSS 7.8 EPSS 0.12%

    Linux Kernel: Fehlendes netns_immutable am Fallback-Device in ip6_vti

  46. CVE-2026-52910 Hoch
    Score 47 CVSS 7.8 EPSS 0.10%

    Linux-Kernel: Use-after-free bei reuseport-cBPF-Programmen (bpf)

  47. CVE-2026-3195 Hoch
    Score 44 CVSS 7.4 EPSS 0.13%

    QEMU – fehlende Puffergrössenprüfung im virtio-snd-Eingabecallback

  48. CVE-2026-48895 Hoch
    Score 43 CVSS 7.2 EPSS 0.41%

    Apache APISIX – Open Redirect auf nicht vertrauenswürdige Seite

  49. CVE-2026-56209 Hoch
    Score 43 CVSS 7.1 EPSS 0.27%

    libaom – Schreiben an beliebige Adresse durch fehlende Bereichsprüfung

  50. CVE-2026-56210 Hoch
    Score 43 CVSS 7.1 EPSS 0.24%

    libaom – Heap-Buffer-Overflow-Read in der SVC-Layer-ID-Steuerfunktion

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.