Live-Feed 1649 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

23380
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
295
Ransomware-Bezug
4837
Kritisch

Zeige 4001 bis 4050 von 23380

  1. CVE-2026-49230 Kritisch
    Score 55 CVSS 9.1 EPSS 0.22%

    Apache APISIX – Authentifizierungsumgehung im jwe-decrypt-Plugin

  2. CVE-2026-56081 Kritisch
    Score 55 CVSS 9.1 EPSS 0.35%

    Cap-go – Fehler in der Authentifizierungslogik ermöglicht Kontoübernahme

  3. CVE-2026-8713 Kritisch
    Score 55 CVSS 9.1 EPSS 1.19%

    WordPress Avada (Fusion) Builder – Beliebiges Löschen von Dateien

  4. CVE-2026-9142 Kritisch
    Score 55 CVSS 9.1 EPSS 0.31%

    NI grpc-device – Unsichere Standard-Zugangsdaten ohne TLS-Konfiguration

  5. CVE-2026-12045 Kritisch
    Score 54 CVSS 9 EPSS 0.48%

    pgAdmin 4 (AI Assistant): Umgehung des Read-Only-Modus ermöglicht beliebiges SQL

  6. CVE-2026-12046 Kritisch
    Score 54 CVSS 9 EPSS 0.71%

    pgAdmin 4 – Schwachstelle in zustandsändernden SQL-Editor-Endpunkten

  7. CVE-2026-39998 Hoch
    Score 53 CVSS 8.8 EPSS 0.40%

    Apache APISIX: Improper Input Validation im forward-auth-Plugin

  8. CVE-2026-47645 Hoch
    Score 53 CVSS 8.8 EPSS 0.41%

    Open Redirect in Microsoft 365 Copilot Business Chat

  9. CVE-2026-47339 Hoch
    Score 49 CVSS 8.1 EPSS 0.29%

    Fehlerhafte Autorisierung in Apache APISIX (authz-casdoor-Plugin)

  10. CVE-2026-49872 Hoch
    Score 49 CVSS 8.1 EPSS 0.32%

    Apache APISIX – fehlerhafte Authentifizierung im cas-auth-Plugin

  11. CVE-2016-20094 Hoch
    Score 47 CVSS 7.8 EPSS 0.18%

    AnyDesk 2.5.0: Codeausführung mit SYSTEM-Rechten über ungequoteten Dienstpfad

  12. CVE-2026-46461 Hoch
    Score 47 CVSS 7.8 EPSS 0.10%

    Dell Server Hardware Manager – Improper Access Control (vor Version 3.2.2)

  13. CVE-2026-52908 Hoch
    Score 47 CVSS 7.8 EPSS 0.13%

    Linux-Kernel: Inkompatible REREG_ACCESS-Prüfung bei RDMA rereg_mr

  14. CVE-2026-52909 Hoch
    Score 47 CVSS 7.8 EPSS 0.12%

    Linux Kernel: Fehlendes netns_immutable am Fallback-Device in ip6_vti

  15. CVE-2026-52910 Hoch
    Score 47 CVSS 7.8 EPSS 0.10%

    Linux-Kernel: Use-after-free bei reuseport-cBPF-Programmen (bpf)

  16. CVE-2026-3195 Hoch
    Score 44 CVSS 7.4 EPSS 0.13%

    QEMU – fehlende Puffergrössenprüfung im virtio-snd-Eingabecallback

  17. CVE-2026-48895 Hoch
    Score 43 CVSS 7.2 EPSS 0.41%

    Apache APISIX – Open Redirect auf nicht vertrauenswürdige Seite

  18. CVE-2026-56209 Hoch
    Score 43 CVSS 7.1 EPSS 0.27%

    libaom – Schreiben an beliebige Adresse durch fehlende Bereichsprüfung

  19. CVE-2026-56210 Hoch
    Score 43 CVSS 7.1 EPSS 0.24%

    libaom – Heap-Buffer-Overflow-Read in der SVC-Layer-ID-Steuerfunktion

  20. CVE-2026-56211 Hoch
    Score 43 CVSS 7.1 EPSS 0.41%

    libaom – Remote Code Execution im AV1-Encoder (SVC-Layer-ID)

  21. CVE-2026-27878 Mittel
    Score 39 CVSS 6.5 EPSS 0.24%

    Grafana Tempo – Denial of Service durch TraceQL-Query

  22. CVE-2026-42895 Mittel
    Score 39 CVSS 6.5 EPSS 0.40%

    Microsoft Copilot: Command Injection ermöglicht Manipulation über das Netzwerk

  23. CVE-2026-47341 Mittel
    Score 39 CVSS 6.5 EPSS 0.43%

    Apache APISIX: Authentifizierungsumgehung durch Token-Replay in hmac-auth

  24. CVE-2026-50519 Mittel
    Score 39 CVSS 6.5 EPSS 0.51%

    GitHub Copilot / Visual Studio Code: Unsichere Standardinitialisierung

  25. CVE-2026-44915 Mittel
    Score 37 CVSS 6.1 EPSS 0.40%

    Apache APISIX – Open Redirect in der cas-auth-Konfiguration

  26. CVE-2026-44046 Mittel
    Score 35 CVSS 5.8 EPSS 0.31%

    Apache APISIX – Log-Manipulation über das wolf-rbac-Plugin

  27. CVE-2026-49231 Mittel
    Score 32 CVSS 5.4 EPSS 0.36%

    Apache: Authentifizierungsumgehung durch Spoofing im OPA-Plugin

  28. CVE-2026-12569 Kritisch Aktiv ausgenutzt
    Score 100 CVSS 9.8 EPSS 1.25%

    PTC Windchill PDMLink und FlexPLM: RCE durch Deserialisierung nicht vertrauenswürdiger Daten

  29. CVE-2026-49257 Kritisch
    Score 60 CVSS 10 EPSS 0.50%

    mcp-pinot – MCP-Server ohne Authentifizierung an 0.0.0.0:8080 gebunden

  30. CVE-2026-38714 Kritisch
    Score 59 CVSS 9.8 EPSS 1.32%

    InHand Networks IR912/IR915: Command Injection in der Python-Konfigurationsfunktion

  31. CVE-2026-38715 Kritisch
    Score 59 CVSS 9.8 EPSS 1.32%

    InHand Networks IR912/IR915: Command-Injection in der Log-Anzeige

  32. CVE-2026-38716 Kritisch
    Score 59 CVSS 9.8 EPSS 1.32%

    InHand Networks IR912/IR915: Command Injection in der Python-Export-Funktion

  33. CVE-2026-38717 Kritisch
    Score 59 CVSS 9.8 EPSS 1.32%

    InHand Networks IR912/IR915: Command Injection in der Datei-Upload-Funktion

  34. CVE-2026-47647 Kritisch
    Score 59 CVSS 9.9 EPSS 0.43%

    Microsoft Dynamics 365 – fehlerhafte Zugriffskontrolle ermöglicht Rechteausweitung

  35. CVE-2026-47846 Kritisch
    Score 59 CVSS 9.8 EPSS 0.34%

    Bitnami Cassandra Container Images: verbleibender Standard-Superuser

  36. CVE-2026-49252 Kritisch
    Score 59 CVSS 9.9 EPSS 0.27%

    deepstream: Prototype Pollution in Versionen vor 10.0.5

  37. CVE-2026-54103 Kritisch
    Score 59 CVSS 9.8 EPSS 0.43%

    GAO EPDS und CBCA EDS: fehlende Passwortprüfung bei der Authentifizierung

  38. CVE-2026-54130 Kritisch
    Score 59 CVSS 9.8 EPSS 0.58%

    Microsoft 365 Copilot: fehlende Authentifizierung bei kritischer Funktion

  39. CVE-2026-54390 Kritisch
    Score 59 CVSS 9.8 EPSS 0.33%

    JTL Shop 5.2.0 bis 5.7.1: Server-Side Template Injection ohne Authentifizierung

  40. CVE-2026-54419 Kritisch
    Score 59 CVSS 9.8 EPSS 0.59%

    PIAF-HMS: Mehrere unauthentifizierte SQL-Injection-Schwachstellen

  41. CVE-2026-55740 Kritisch
    Score 59 CVSS 9.8 EPSS 0.37%

    Nur-Alam39 bus-ticket: unauthentifizierte SQL-Injection in bus_info.php

  42. CVE-2026-8024 Kritisch
    Score 59 CVSS 9.8 EPSS 0.55%

    ibaPDA und ibaDatCoordinator: unsichere Deserialisierung ermöglicht vollständigen Systemzugriff

  43. CVE-2026-9158 Kritisch
    Score 59 CVSS 9.8 EPSS 0.30%

    Eclipse 4diac FORTE: Dangling Pointer über DELETE-connection-Kommando

  44. CVE-2026-55742 Kritisch
    Score 58 CVSS 9.6 EPSS 0.23%

    Cotonti 1.0.0: Cross-Site Request Forgery im Rechte-Handler der Administration

  45. CVE-2026-48768 Kritisch
    Score 56 CVSS 9.3 EPSS 0.27%

    TypeBot: Nicht authentifizierter Upload-Endpunkt mit ungeprüftem Dateinamen

  46. CVE-2026-49454 Kritisch
    Score 55 CVSS 9.1 EPSS 0.14%

    Relyra (SAML 2.0 Service Provider für Elixir/Phoenix): Akzeptanz gefälschter SAML-Signaturen

  47. CVE-2026-8461 Hoch
    Score 53 CVSS 8.8 EPSS 0.48%

    FFmpeg libavcodec – Out-of-bounds Write im MagicYUV-Decoder

  48. CVE-2026-44688 Hoch
    Score 53 CVSS 8.8

    Indirekte Prompt-Injection in Eclipse Theia

  49. CVE-2026-44691 Hoch
    Score 53 CVSS 8.8

    CVE-2026-44691 – Codeausführung ohne Workspace-Trust in Eclipse Theia

  50. CVE-2026-46580 Hoch
    Score 53 CVSS 8.8

    Eclipse Theia: Indirekte Prompt-Injection über Prompt-Template-Dateien

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.