Live-Feed 1649 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
23380
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
295
Ransomware-Bezug
4837
Kritisch
Zeige 4001 bis 4050 von 23380
- CVE-2026-49230 KritischScore 55 CVSS 9.1 EPSS 0.22%
Apache APISIX – Authentifizierungsumgehung im jwe-decrypt-Plugin
- CVE-2026-56081 KritischScore 55 CVSS 9.1 EPSS 0.35%
Cap-go – Fehler in der Authentifizierungslogik ermöglicht Kontoübernahme
- CVE-2026-8713 KritischScore 55 CVSS 9.1 EPSS 1.19%
WordPress Avada (Fusion) Builder – Beliebiges Löschen von Dateien
- CVE-2026-9142 KritischScore 55 CVSS 9.1 EPSS 0.31%
NI grpc-device – Unsichere Standard-Zugangsdaten ohne TLS-Konfiguration
- CVE-2026-12045 KritischScore 54 CVSS 9 EPSS 0.48%
pgAdmin 4 (AI Assistant): Umgehung des Read-Only-Modus ermöglicht beliebiges SQL
- CVE-2026-12046 KritischScore 54 CVSS 9 EPSS 0.71%
pgAdmin 4 – Schwachstelle in zustandsändernden SQL-Editor-Endpunkten
- CVE-2026-39998 HochScore 53 CVSS 8.8 EPSS 0.40%
Apache APISIX: Improper Input Validation im forward-auth-Plugin
- CVE-2026-47645 HochScore 53 CVSS 8.8 EPSS 0.41%
Open Redirect in Microsoft 365 Copilot Business Chat
- CVE-2026-47339 HochScore 49 CVSS 8.1 EPSS 0.29%
Fehlerhafte Autorisierung in Apache APISIX (authz-casdoor-Plugin)
- CVE-2026-49872 HochScore 49 CVSS 8.1 EPSS 0.32%
Apache APISIX – fehlerhafte Authentifizierung im cas-auth-Plugin
- CVE-2016-20094 HochScore 47 CVSS 7.8 EPSS 0.18%
AnyDesk 2.5.0: Codeausführung mit SYSTEM-Rechten über ungequoteten Dienstpfad
- CVE-2026-46461 HochScore 47 CVSS 7.8 EPSS 0.10%
Dell Server Hardware Manager – Improper Access Control (vor Version 3.2.2)
- CVE-2026-52908 HochScore 47 CVSS 7.8 EPSS 0.13%
Linux-Kernel: Inkompatible REREG_ACCESS-Prüfung bei RDMA rereg_mr
- CVE-2026-52909 HochScore 47 CVSS 7.8 EPSS 0.12%
Linux Kernel: Fehlendes netns_immutable am Fallback-Device in ip6_vti
- CVE-2026-52910 HochScore 47 CVSS 7.8 EPSS 0.10%
Linux-Kernel: Use-after-free bei reuseport-cBPF-Programmen (bpf)
- CVE-2026-3195 HochScore 44 CVSS 7.4 EPSS 0.13%
QEMU – fehlende Puffergrössenprüfung im virtio-snd-Eingabecallback
- CVE-2026-48895 HochScore 43 CVSS 7.2 EPSS 0.41%
Apache APISIX – Open Redirect auf nicht vertrauenswürdige Seite
- CVE-2026-56209 HochScore 43 CVSS 7.1 EPSS 0.27%
libaom – Schreiben an beliebige Adresse durch fehlende Bereichsprüfung
- CVE-2026-56210 HochScore 43 CVSS 7.1 EPSS 0.24%
libaom – Heap-Buffer-Overflow-Read in der SVC-Layer-ID-Steuerfunktion
- CVE-2026-56211 HochScore 43 CVSS 7.1 EPSS 0.41%
libaom – Remote Code Execution im AV1-Encoder (SVC-Layer-ID)
- CVE-2026-27878 MittelScore 39 CVSS 6.5 EPSS 0.24%
Grafana Tempo – Denial of Service durch TraceQL-Query
- CVE-2026-42895 MittelScore 39 CVSS 6.5 EPSS 0.40%
Microsoft Copilot: Command Injection ermöglicht Manipulation über das Netzwerk
- CVE-2026-47341 MittelScore 39 CVSS 6.5 EPSS 0.43%
Apache APISIX: Authentifizierungsumgehung durch Token-Replay in hmac-auth
- CVE-2026-50519 MittelScore 39 CVSS 6.5 EPSS 0.51%
GitHub Copilot / Visual Studio Code: Unsichere Standardinitialisierung
- CVE-2026-44915 MittelScore 37 CVSS 6.1 EPSS 0.40%
Apache APISIX – Open Redirect in der cas-auth-Konfiguration
- CVE-2026-44046 MittelScore 35 CVSS 5.8 EPSS 0.31%
Apache APISIX – Log-Manipulation über das wolf-rbac-Plugin
- CVE-2026-49231 MittelScore 32 CVSS 5.4 EPSS 0.36%
Apache: Authentifizierungsumgehung durch Spoofing im OPA-Plugin
- CVE-2026-12569 Kritisch Aktiv ausgenutztScore 100 CVSS 9.8 EPSS 1.25%
PTC Windchill PDMLink und FlexPLM: RCE durch Deserialisierung nicht vertrauenswürdiger Daten
- CVE-2026-49257 KritischScore 60 CVSS 10 EPSS 0.50%
mcp-pinot – MCP-Server ohne Authentifizierung an 0.0.0.0:8080 gebunden
- CVE-2026-38714 KritischScore 59 CVSS 9.8 EPSS 1.32%
InHand Networks IR912/IR915: Command Injection in der Python-Konfigurationsfunktion
- CVE-2026-38715 KritischScore 59 CVSS 9.8 EPSS 1.32%
InHand Networks IR912/IR915: Command-Injection in der Log-Anzeige
- CVE-2026-38716 KritischScore 59 CVSS 9.8 EPSS 1.32%
InHand Networks IR912/IR915: Command Injection in der Python-Export-Funktion
- CVE-2026-38717 KritischScore 59 CVSS 9.8 EPSS 1.32%
InHand Networks IR912/IR915: Command Injection in der Datei-Upload-Funktion
- CVE-2026-47647 KritischScore 59 CVSS 9.9 EPSS 0.43%
Microsoft Dynamics 365 – fehlerhafte Zugriffskontrolle ermöglicht Rechteausweitung
- CVE-2026-47846 KritischScore 59 CVSS 9.8 EPSS 0.34%
Bitnami Cassandra Container Images: verbleibender Standard-Superuser
- CVE-2026-49252 KritischScore 59 CVSS 9.9 EPSS 0.27%
deepstream: Prototype Pollution in Versionen vor 10.0.5
- CVE-2026-54103 KritischScore 59 CVSS 9.8 EPSS 0.43%
GAO EPDS und CBCA EDS: fehlende Passwortprüfung bei der Authentifizierung
- CVE-2026-54130 KritischScore 59 CVSS 9.8 EPSS 0.58%
Microsoft 365 Copilot: fehlende Authentifizierung bei kritischer Funktion
- CVE-2026-54390 KritischScore 59 CVSS 9.8 EPSS 0.33%
JTL Shop 5.2.0 bis 5.7.1: Server-Side Template Injection ohne Authentifizierung
- CVE-2026-54419 KritischScore 59 CVSS 9.8 EPSS 0.59%
PIAF-HMS: Mehrere unauthentifizierte SQL-Injection-Schwachstellen
- CVE-2026-55740 KritischScore 59 CVSS 9.8 EPSS 0.37%
Nur-Alam39 bus-ticket: unauthentifizierte SQL-Injection in bus_info.php
- CVE-2026-8024 KritischScore 59 CVSS 9.8 EPSS 0.55%
ibaPDA und ibaDatCoordinator: unsichere Deserialisierung ermöglicht vollständigen Systemzugriff
- CVE-2026-9158 KritischScore 59 CVSS 9.8 EPSS 0.30%
Eclipse 4diac FORTE: Dangling Pointer über DELETE-connection-Kommando
- CVE-2026-55742 KritischScore 58 CVSS 9.6 EPSS 0.23%
Cotonti 1.0.0: Cross-Site Request Forgery im Rechte-Handler der Administration
- CVE-2026-48768 KritischScore 56 CVSS 9.3 EPSS 0.27%
TypeBot: Nicht authentifizierter Upload-Endpunkt mit ungeprüftem Dateinamen
- CVE-2026-49454 KritischScore 55 CVSS 9.1 EPSS 0.14%
Relyra (SAML 2.0 Service Provider für Elixir/Phoenix): Akzeptanz gefälschter SAML-Signaturen
- CVE-2026-8461 HochScore 53 CVSS 8.8 EPSS 0.48%
FFmpeg libavcodec – Out-of-bounds Write im MagicYUV-Decoder
- CVE-2026-44688 HochScore 53 CVSS 8.8
Indirekte Prompt-Injection in Eclipse Theia
- CVE-2026-44691 HochScore 53 CVSS 8.8
CVE-2026-44691 – Codeausführung ohne Workspace-Trust in Eclipse Theia
- CVE-2026-46580 HochScore 53 CVSS 8.8
Eclipse Theia: Indirekte Prompt-Injection über Prompt-Template-Dateien
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.