Live-Feed 1649 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
23639
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
296
Ransomware-Bezug
4866
Kritisch
Zeige 4251 bis 4300 von 23639
- CVE-2026-53805 KritischScore 59 CVSS 9.8 EPSS 0.69%
NVIDIA GEN3C: Unauthentifizierte Remote Code Execution im Inference-API-Server
- CVE-2026-53873 KritischScore 59 CVSS 9.8 EPSS 0.46%
picklescan: Unvollständige Blocklist erlaubt Codeausführung über profile.run()
- CVE-2026-53874 KritischScore 59 CVSS 9.8 EPSS 0.52%
picklescan: Unsichere Deserialisierung erlaubt Codeausführung
- CVE-2026-54194 KritischScore 59 CVSS 9.8 EPSS 0.39%
Fusion Builder: PHP Object Injection durch Benutzer mit Contributor-Rechten
- CVE-2026-54803 KritischScore 59 CVSS 9.8 EPSS 0.45%
SMS Alert Order Notifications: Rechteausweitung ab Subscriber-Rolle
- CVE-2026-54806 KritischScore 59 CVSS 9.8 EPSS 0.59%
WP Activity Log: unauthentifizierte PHP Object Injection
- CVE-2026-54807 KritischScore 59 CVSS 9.8 EPSS 0.45%
Registration Form for WooCommerce: nicht authentifizierte Rechteausweitung
- CVE-2026-12440 KritischScore 58 CVSS 9.6 EPSS 0.25%
Google Chrome unter Windows: Use-after-free in DigitalCredentials ermöglicht Sandbox-Ausbruch
- CVE-2026-46786 KritischScore 58 CVSS 9.6 EPSS 0.21%
Oracle WebCenter Content (Content Server): leicht ausnutzbare Schwachstelle in 14.1.2.0.0
- CVE-2026-46789 KritischScore 58 CVSS 9.6 EPSS 0.42%
Oracle WebCenter Content (Content Server): Leicht ausnutzbare Schwachstelle in Version 14.1.2.0.0
- CVE-2026-46853 KritischScore 58 CVSS 9.6 EPSS 0.48%
Oracle Enterprise Manager Base Platform: Schwachstelle im Metadata Plugin
- CVE-2026-46856 KritischScore 58 CVSS 9.6 EPSS 0.47%
Oracle Enterprise Manager Base Platform: Schwachstelle in der Metadata-Plugin-Komponente
- CVE-2026-46861 KritischScore 58 CVSS 9.6 EPSS 0.36%
Oracle MySQL NDB Cluster: Schwachstelle im NDB Operator
- CVE-2026-46899 KritischScore 58 CVSS 9.6 EPSS 0.34%
Oracle E-Business Suite: Schwachstelle im Enterprise Command Center Framework
- CVE-2026-46906 KritischScore 58 CVSS 9.6 EPSS 0.34%
Oracle JD Edwards EnterpriseOne Tools: Schwachstelle in Enterprise Infrastructure Security
- CVE-2026-46911 KritischScore 58 CVSS 9.6 EPSS 0.26%
Oracle JD Edwards EnterpriseOne Project Costing: Schwachstelle in Job Costing (Version 9.2)
- CVE-2026-55743 KritischScore 58 CVSS 9.6 EPSS 0.70%
OpenHuman Desktop Agent: Umgehung der Shell-Kommando-Allowlist
- CVE-2025-59554 KritischScore 56 CVSS 9.3 EPSS 0.38%
WordPress-Plugin Advanced Ads – Tracking: Nicht authentifizierte SQL-Injection
- CVE-2026-22332 KritischScore 56 CVSS 9.3 EPSS 0.28%
WordPress-Plugin Tutor LMS Pro: Nicht authentifizierte SQL-Injection
- CVE-2026-22340 KritischScore 56 CVSS 9.3 EPSS 0.37%
WPJobster: unauthentifizierte SQL-Injection in Versionen bis 6.3.5
- CVE-2026-35305 KritischScore 56 CVSS 9.3 EPSS 0.34%
Oracle Coherence (Fusion Middleware): Schwachstelle in zentralisierten Drittanbieter-JARs
- CVE-2026-35306 KritischScore 56 CVSS 9.3 EPSS 0.35%
Oracle Coherence: Schwachstelle in Centralized Third Party Jars
- CVE-2026-39438 KritischScore 56 CVSS 9.3 EPSS 0.37%
ListingPro: Nicht authentifizierte SQL-Injection
- CVE-2026-39596 KritischScore 56 CVSS 9.3 EPSS 0.37%
Blocksy Companion Pro: unauthentifizierte SQL-Injection vor Version 2.1.29
- CVE-2026-46785 KritischScore 56 CVSS 9.3 EPSS 0.20%
Oracle WebCenter Content: Schwachstelle im Content Server
- CVE-2026-46795 KritischScore 56 CVSS 9.3 EPSS 0.39%
Oracle WebCenter Content: Schwachstelle in der Komponente Content Server
- CVE-2026-46805 KritischScore 56 CVSS 9.3 EPSS 0.39%
Oracle WebCenter Content: Schwachstelle im Content Server (Version 14.1.2.0.0)
- CVE-2026-46912 KritischScore 56 CVSS 9.3 EPSS 0.26%
Oracle JD Edwards EnterpriseOne Tools: leicht ausnutzbare Schwachstelle in Web Runtime Security
- CVE-2026-46913 KritischScore 56 CVSS 9.3 EPSS 0.14%
Oracle JD Edwards EnterpriseOne Tools: Schwachstelle in der Komponente Installation Security
- CVE-2026-48616 KritischScore 56 CVSS 9.3 EPSS 0.30%
Rocket.Chat: Fehlerhafte Zugriffskontrolle bei Livechat-Dateien
- CVE-2026-48745 KritischScore 56 CVSS 9.3 EPSS 0.32%
Traccar Client: Präparierter Deep Link kompromittiert die GPS-Tracking-App
- CVE-2026-48875 KritischScore 56 CVSS 9.3 EPSS 0.37%
JetSmartFilters: unauthentifizierte SQL-Injection in Versionen bis 3.8.1
- CVE-2026-49076 KritischScore 56 CVSS 9.3 EPSS 0.37%
JetEngine: Unauthentifizierte SQL-Injection
- CVE-2026-49079 KritischScore 56 CVSS 9.3 EPSS 0.35%
JetSearch (WordPress): Nicht authentifizierte SQL-Injection
- CVE-2026-49080 KritischScore 56 CVSS 9.3 EPSS 0.31%
wpDataTables: Nicht authentifizierte SQL-Injection
- CVE-2026-49084 KritischScore 56 CVSS 9.3 EPSS 0.28%
JetEngine: Unauthentifizierte SQL-Injection
- CVE-2026-54186 KritischScore 56 CVSS 9.3 EPSS 0.30%
JobSearch: Unauthentifizierte SQL-Injection
- CVE-2026-54187 KritischScore 56 CVSS 9.3 EPSS 0.29%
WordPress-Plugin JetEngine: Nicht authentifizierte SQL-Injection
- CVE-2026-54808 KritischScore 56 CVSS 9.3 EPSS 0.32%
WP Travel Gutenberg Blocks: Blind SQL Injection
- CVE-2026-54809 KritischScore 56 CVSS 9.3 EPSS 0.24%
VillaTheme GIFT4U: Blind SQL Injection
- CVE-2026-54811 KritischScore 56 CVSS 9.3 EPSS 0.29%
WP eMember: Nicht authentifizierte SQL-Injection
- CVE-2026-54812 KritischScore 56 CVSS 9.3 EPSS 0.29%
StylemixThemes Motors: Blind SQL Injection
- CVE-2026-54815 KritischScore 56 CVSS 9.3 EPSS 0.24%
Cargo RD Cargo Shipping Location for WooCommerce: Blind SQL Injection
- CVE-2026-54819 KritischScore 56 CVSS 9.3 EPSS 0.24%
Webilia Listdom: Blind-SQL-Injection
- CVE-2026-20181 KritischScore 55 CVSS 9.1 EPSS 0.75%
Cisco ISE und ISE-PIC: Befehlsausführung auf dem zugrunde liegenden Betriebssystem
- CVE-2026-20266 KritischScore 55 CVSS 9.1 EPSS 0.47%
Splunk AI Toolkit – Ausführung beliebiger Betriebssystembefehle durch Admin-Rolle
- CVE-2026-24611 KritischScore 55 CVSS 9.1 EPSS 0.44%
MetForm Pro: unauthentifizierte Umgehung der Zugriffskontrolle bis Version 3.9.1
- CVE-2026-30803 KritischScore 55 CVSS 9.1 EPSS 0.30%
RTI Connext Micro: Integer Underflow in den Core Libraries ermöglicht Buffer Overread
- CVE-2026-32967 KritischScore 55 CVSS 9.1 EPSS 0.34%
Apache DolphinScheduler: Fehlerhafte Autorisierung der experimentellen /v2-Schnittstelle
- CVE-2026-35270 KritischScore 55 CVSS 9.1 EPSS 0.49%
Oracle WebCenter Content: Schwachstelle im Content Server
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.