Live-Feed 1649 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
23328
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
295
Ransomware-Bezug
4831
Kritisch
Zeige 3951 bis 4000 von 23328
- CVE-2026-12773 HochScore 44 CVSS 7.3 EPSS 0.61%
BerriAI litellm – fehlerhafte Authentifizierung im MCP Proxy
- CVE-2026-48908 Kritisch Aktiv ausgenutztScore 100 CVSS 9.8 EPSS 1.57%
SP Page Builder für Joomla: Unauthentifizierter Datei-Upload mit Codeausführung
- CVE-2026-48939 Kritisch Aktiv ausgenutztScore 100 CVSS 9.8 EPSS 1.50%
Joomla-Erweiterung iCagenda: Upload beliebiger Dateien führt zu PHP-Code-Ausführung
- CVE-2019-25763 KritischScore 59 CVSS 9.8 EPSS 0.43%
WordPress Ultimate Addons for Beaver Builder: Authentifizierungsumgehung
- CVE-2022-50972 KritischScore 59 CVSS 9.8 EPSS 0.63%
WooCommerce 7.1.0: Remote Code Execution über den Parameter product-type
- CVE-2024-58351 KritischScore 59 CVSS 9.8 EPSS 0.65%
Flowise: Konfigurations-Injection über overrideConfig
- CVE-2026-11551 KritischScore 59 CVSS 9.8 EPSS 0.63%
WordPress-Plugin Branda bis 3.4.29: Privilege Escalation durch Account-Übernahme
- CVE-2026-5366 KritischScore 59 CVSS 9.9 EPSS 0.87%
Prefect 3.6.23: Remote Code Execution über commit_sha in GitRepository
- CVE-2026-9265 KritischScore 55 CVSS 9.1 EPSS 0.35%
Crypt::OpenSSL::PKCS12 (Perl) – Heap-Out-of-bounds-Read im UTF8STRING-Pfad
- CVE-2026-45480 KritischScore 60 CVSS 10 EPSS 0.56%
Azure Active Directory: fehlerhafte Authentifizierung ermöglicht Rechteausweitung
- CVE-2026-48772 KritischScore 60 CVSS 10 EPSS 0.18%
ProxySQL: MySQL-Frontend akzeptiert gefälschte PROXY-Protokoll-Frames
- CVE-2026-50242 KritischScore 60 CVSS 10 EPSS 0.42%
JetBrains Hub: Authentifizierungsumgehung über direkten Datenbankzugriff
- CVE-2026-40624 KritischScore 59 CVSS 9.8 EPSS 0.62%
AVer PTC-Kameras: Remote Code Execution durch unzureichende Eingabevalidierung
- CVE-2026-48584 KritischScore 59 CVSS 9.9 EPSS 0.50%
Azure Synapse: Rechteausweitung durch Ausführung mit unnötigen Privilegien
- CVE-2026-48773 KritischScore 59 CVSS 9.8 EPSS 0.36%
ProxySQL: Heap-Speicherkorruption vor der Authentifizierung im MySQL- und PostgreSQL-Protokoll
- CVE-2026-51843 KritischScore 59 CVSS 9.8 EPSS 0.38%
Tenda AC7: Stack-Buffer-Overflow in /goform/AdvSetMacMtuWan
- CVE-2026-51844 KritischScore 59 CVSS 9.8 EPSS 0.38%
Tenda AC7: Stack-Buffer-Overflow in /goform/AdvSetMacMtuWan
- CVE-2026-51845 KritischScore 59 CVSS 9.8 EPSS 0.38%
Tenda AC7 v15.03.06.44: Stack-Buffer-Overflow in /goform/AdvSetMacMtuWan
- CVE-2026-51846 KritischScore 59 CVSS 9.8 EPSS 0.58%
Tenda AC7: Stack-Buffer-Overflow im wanSpeed-Parameter von /goform/AdvSetMacMtuWan
- CVE-2026-54414 KritischScore 59 CVSS 9.8 EPSS 0.72%
FileRise: Path Traversal im Shared-Folder-Upload führt zur Übernahme des Admin-Kontos
- CVE-2026-56141 KritischScore 59 CVSS 9.8 EPSS 0.36%
JetBrains Hub: Account-Übernahme durch vorhersagbare Wiederherstellungscodes
- CVE-2026-56142 KritischScore 59 CVSS 9.9 EPSS 0.42%
JetBrains Hub – Rechteausweitung durch Anhängen von Authentifizierungsdaten an Konten
- CVE-2026-7515 KritischScore 59 CVSS 9.8 EPSS 0.89%
BetterDocs Pro (WordPress): Local File Inclusion über den Parameter doc_style
- CVE-2026-48582 KritischScore 58 CVSS 9.6 EPSS 0.39%
Microsoft Exchange Online: Fehlende Autorisierung ermöglicht Rechteausweitung
- CVE-2026-12048 KritischScore 56 CVSS 9.3 EPSS 0.21%
pgAdmin 4: Stored Cross-Site-Scripting in Fehler- und Plan-Node-Darstellung
- CVE-2026-49871 KritischScore 56 CVSS 9.3 EPSS 0.26%
cas-auth-Plugin: Cross-Site Request Forgery in der Standardkonfiguration
- CVE-2026-56073 KritischScore 56 CVSS 9.4 EPSS 0.19%
Cap-go: Umgehung der OTP-basierten E-Mail-Verifizierung
- CVE-2025-62821 KritischScore 55 CVSS 9.1 EPSS 0.82%
Microsoft HEIF Image Extensions: Out-of-bounds Read bei der Ermittlung der Datengrösse
- CVE-2026-39999 KritischScore 55 CVSS 9.1 EPSS 0.39%
Apache APISIX: Authentifizierungsumgehung über das jwt-auth-Plugin
- CVE-2026-44087 KritischScore 55 CVSS 9.1 EPSS 0.21%
Apache APISIX: Identitäts-Spoofing im openid-connect-Plugin
- CVE-2026-48137 KritischScore 55 CVSS 9.1 EPSS 0.55%
NI grpc-device – Untrusted Pointer Dereference in der Sideband-Streaming-API
- CVE-2026-49230 KritischScore 55 CVSS 9.1 EPSS 0.22%
Apache APISIX – Authentifizierungsumgehung im jwe-decrypt-Plugin
- CVE-2026-56081 KritischScore 55 CVSS 9.1 EPSS 0.35%
Cap-go – Fehler in der Authentifizierungslogik ermöglicht Kontoübernahme
- CVE-2026-8713 KritischScore 55 CVSS 9.1 EPSS 1.19%
WordPress Avada (Fusion) Builder – Beliebiges Löschen von Dateien
- CVE-2026-9142 KritischScore 55 CVSS 9.1 EPSS 0.31%
NI grpc-device – Unsichere Standard-Zugangsdaten ohne TLS-Konfiguration
- CVE-2026-12045 KritischScore 54 CVSS 9 EPSS 0.48%
pgAdmin 4 (AI Assistant): Umgehung des Read-Only-Modus ermöglicht beliebiges SQL
- CVE-2026-12046 KritischScore 54 CVSS 9 EPSS 0.71%
pgAdmin 4 – Schwachstelle in zustandsändernden SQL-Editor-Endpunkten
- CVE-2026-39998 HochScore 53 CVSS 8.8 EPSS 0.40%
Apache APISIX: Improper Input Validation im forward-auth-Plugin
- CVE-2026-47645 HochScore 53 CVSS 8.8 EPSS 0.41%
Open Redirect in Microsoft 365 Copilot Business Chat
- CVE-2026-47339 HochScore 49 CVSS 8.1 EPSS 0.29%
Fehlerhafte Autorisierung in Apache APISIX (authz-casdoor-Plugin)
- CVE-2026-49872 HochScore 49 CVSS 8.1 EPSS 0.32%
Apache APISIX – fehlerhafte Authentifizierung im cas-auth-Plugin
- CVE-2016-20094 HochScore 47 CVSS 7.8 EPSS 0.18%
AnyDesk 2.5.0: Codeausführung mit SYSTEM-Rechten über ungequoteten Dienstpfad
- CVE-2026-46461 HochScore 47 CVSS 7.8 EPSS 0.10%
Dell Server Hardware Manager – Improper Access Control (vor Version 3.2.2)
- CVE-2026-52908 HochScore 47 CVSS 7.8 EPSS 0.13%
Linux-Kernel: Inkompatible REREG_ACCESS-Prüfung bei RDMA rereg_mr
- CVE-2026-52909 HochScore 47 CVSS 7.8 EPSS 0.12%
Linux Kernel: Fehlendes netns_immutable am Fallback-Device in ip6_vti
- CVE-2026-52910 HochScore 47 CVSS 7.8 EPSS 0.10%
Linux-Kernel: Use-after-free bei reuseport-cBPF-Programmen (bpf)
- CVE-2026-3195 HochScore 44 CVSS 7.4 EPSS 0.13%
QEMU – fehlende Puffergrössenprüfung im virtio-snd-Eingabecallback
- CVE-2026-48895 HochScore 43 CVSS 7.2 EPSS 0.41%
Apache APISIX – Open Redirect auf nicht vertrauenswürdige Seite
- CVE-2026-56209 HochScore 43 CVSS 7.1 EPSS 0.27%
libaom – Schreiben an beliebige Adresse durch fehlende Bereichsprüfung
- CVE-2026-56210 HochScore 43 CVSS 7.1 EPSS 0.24%
libaom – Heap-Buffer-Overflow-Read in der SVC-Layer-ID-Steuerfunktion
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.