Live-Feed 1649 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

23639
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
296
Ransomware-Bezug
4866
Kritisch

Zeige 4251 bis 4300 von 23639

  1. CVE-2026-53805 Kritisch
    Score 59 CVSS 9.8 EPSS 0.69%

    NVIDIA GEN3C: Unauthentifizierte Remote Code Execution im Inference-API-Server

  2. CVE-2026-53873 Kritisch
    Score 59 CVSS 9.8 EPSS 0.46%

    picklescan: Unvollständige Blocklist erlaubt Codeausführung über profile.run()

  3. CVE-2026-53874 Kritisch
    Score 59 CVSS 9.8 EPSS 0.52%

    picklescan: Unsichere Deserialisierung erlaubt Codeausführung

  4. CVE-2026-54194 Kritisch
    Score 59 CVSS 9.8 EPSS 0.39%

    Fusion Builder: PHP Object Injection durch Benutzer mit Contributor-Rechten

  5. CVE-2026-54803 Kritisch
    Score 59 CVSS 9.8 EPSS 0.45%

    SMS Alert Order Notifications: Rechteausweitung ab Subscriber-Rolle

  6. CVE-2026-54806 Kritisch
    Score 59 CVSS 9.8 EPSS 0.59%

    WP Activity Log: unauthentifizierte PHP Object Injection

  7. CVE-2026-54807 Kritisch
    Score 59 CVSS 9.8 EPSS 0.45%

    Registration Form for WooCommerce: nicht authentifizierte Rechteausweitung

  8. CVE-2026-12440 Kritisch
    Score 58 CVSS 9.6 EPSS 0.25%

    Google Chrome unter Windows: Use-after-free in DigitalCredentials ermöglicht Sandbox-Ausbruch

  9. CVE-2026-46786 Kritisch
    Score 58 CVSS 9.6 EPSS 0.21%

    Oracle WebCenter Content (Content Server): leicht ausnutzbare Schwachstelle in 14.1.2.0.0

  10. CVE-2026-46789 Kritisch
    Score 58 CVSS 9.6 EPSS 0.42%

    Oracle WebCenter Content (Content Server): Leicht ausnutzbare Schwachstelle in Version 14.1.2.0.0

  11. CVE-2026-46853 Kritisch
    Score 58 CVSS 9.6 EPSS 0.48%

    Oracle Enterprise Manager Base Platform: Schwachstelle im Metadata Plugin

  12. CVE-2026-46856 Kritisch
    Score 58 CVSS 9.6 EPSS 0.47%

    Oracle Enterprise Manager Base Platform: Schwachstelle in der Metadata-Plugin-Komponente

  13. CVE-2026-46861 Kritisch
    Score 58 CVSS 9.6 EPSS 0.36%

    Oracle MySQL NDB Cluster: Schwachstelle im NDB Operator

  14. CVE-2026-46899 Kritisch
    Score 58 CVSS 9.6 EPSS 0.34%

    Oracle E-Business Suite: Schwachstelle im Enterprise Command Center Framework

  15. CVE-2026-46906 Kritisch
    Score 58 CVSS 9.6 EPSS 0.34%

    Oracle JD Edwards EnterpriseOne Tools: Schwachstelle in Enterprise Infrastructure Security

  16. CVE-2026-46911 Kritisch
    Score 58 CVSS 9.6 EPSS 0.26%

    Oracle JD Edwards EnterpriseOne Project Costing: Schwachstelle in Job Costing (Version 9.2)

  17. CVE-2026-55743 Kritisch
    Score 58 CVSS 9.6 EPSS 0.70%

    OpenHuman Desktop Agent: Umgehung der Shell-Kommando-Allowlist

  18. CVE-2025-59554 Kritisch
    Score 56 CVSS 9.3 EPSS 0.38%

    WordPress-Plugin Advanced Ads – Tracking: Nicht authentifizierte SQL-Injection

  19. CVE-2026-22332 Kritisch
    Score 56 CVSS 9.3 EPSS 0.28%

    WordPress-Plugin Tutor LMS Pro: Nicht authentifizierte SQL-Injection

  20. CVE-2026-22340 Kritisch
    Score 56 CVSS 9.3 EPSS 0.37%

    WPJobster: unauthentifizierte SQL-Injection in Versionen bis 6.3.5

  21. CVE-2026-35305 Kritisch
    Score 56 CVSS 9.3 EPSS 0.34%

    Oracle Coherence (Fusion Middleware): Schwachstelle in zentralisierten Drittanbieter-JARs

  22. CVE-2026-35306 Kritisch
    Score 56 CVSS 9.3 EPSS 0.35%

    Oracle Coherence: Schwachstelle in Centralized Third Party Jars

  23. CVE-2026-39438 Kritisch
    Score 56 CVSS 9.3 EPSS 0.37%

    ListingPro: Nicht authentifizierte SQL-Injection

  24. CVE-2026-39596 Kritisch
    Score 56 CVSS 9.3 EPSS 0.37%

    Blocksy Companion Pro: unauthentifizierte SQL-Injection vor Version 2.1.29

  25. CVE-2026-46785 Kritisch
    Score 56 CVSS 9.3 EPSS 0.20%

    Oracle WebCenter Content: Schwachstelle im Content Server

  26. CVE-2026-46795 Kritisch
    Score 56 CVSS 9.3 EPSS 0.39%

    Oracle WebCenter Content: Schwachstelle in der Komponente Content Server

  27. CVE-2026-46805 Kritisch
    Score 56 CVSS 9.3 EPSS 0.39%

    Oracle WebCenter Content: Schwachstelle im Content Server (Version 14.1.2.0.0)

  28. CVE-2026-46912 Kritisch
    Score 56 CVSS 9.3 EPSS 0.26%

    Oracle JD Edwards EnterpriseOne Tools: leicht ausnutzbare Schwachstelle in Web Runtime Security

  29. CVE-2026-46913 Kritisch
    Score 56 CVSS 9.3 EPSS 0.14%

    Oracle JD Edwards EnterpriseOne Tools: Schwachstelle in der Komponente Installation Security

  30. CVE-2026-48616 Kritisch
    Score 56 CVSS 9.3 EPSS 0.30%

    Rocket.Chat: Fehlerhafte Zugriffskontrolle bei Livechat-Dateien

  31. CVE-2026-48745 Kritisch
    Score 56 CVSS 9.3 EPSS 0.32%

    Traccar Client: Präparierter Deep Link kompromittiert die GPS-Tracking-App

  32. CVE-2026-48875 Kritisch
    Score 56 CVSS 9.3 EPSS 0.37%

    JetSmartFilters: unauthentifizierte SQL-Injection in Versionen bis 3.8.1

  33. CVE-2026-49076 Kritisch
    Score 56 CVSS 9.3 EPSS 0.37%

    JetEngine: Unauthentifizierte SQL-Injection

  34. CVE-2026-49079 Kritisch
    Score 56 CVSS 9.3 EPSS 0.35%

    JetSearch (WordPress): Nicht authentifizierte SQL-Injection

  35. CVE-2026-49080 Kritisch
    Score 56 CVSS 9.3 EPSS 0.31%

    wpDataTables: Nicht authentifizierte SQL-Injection

  36. CVE-2026-49084 Kritisch
    Score 56 CVSS 9.3 EPSS 0.28%

    JetEngine: Unauthentifizierte SQL-Injection

  37. CVE-2026-54186 Kritisch
    Score 56 CVSS 9.3 EPSS 0.30%

    JobSearch: Unauthentifizierte SQL-Injection

  38. CVE-2026-54187 Kritisch
    Score 56 CVSS 9.3 EPSS 0.29%

    WordPress-Plugin JetEngine: Nicht authentifizierte SQL-Injection

  39. CVE-2026-54808 Kritisch
    Score 56 CVSS 9.3 EPSS 0.32%

    WP Travel Gutenberg Blocks: Blind SQL Injection

  40. CVE-2026-54809 Kritisch
    Score 56 CVSS 9.3 EPSS 0.24%

    VillaTheme GIFT4U: Blind SQL Injection

  41. CVE-2026-54811 Kritisch
    Score 56 CVSS 9.3 EPSS 0.29%

    WP eMember: Nicht authentifizierte SQL-Injection

  42. CVE-2026-54812 Kritisch
    Score 56 CVSS 9.3 EPSS 0.29%

    StylemixThemes Motors: Blind SQL Injection

  43. CVE-2026-54815 Kritisch
    Score 56 CVSS 9.3 EPSS 0.24%

    Cargo RD Cargo Shipping Location for WooCommerce: Blind SQL Injection

  44. CVE-2026-54819 Kritisch
    Score 56 CVSS 9.3 EPSS 0.24%

    Webilia Listdom: Blind-SQL-Injection

  45. CVE-2026-20181 Kritisch
    Score 55 CVSS 9.1 EPSS 0.75%

    Cisco ISE und ISE-PIC: Befehlsausführung auf dem zugrunde liegenden Betriebssystem

  46. CVE-2026-20266 Kritisch
    Score 55 CVSS 9.1 EPSS 0.47%

    Splunk AI Toolkit – Ausführung beliebiger Betriebssystembefehle durch Admin-Rolle

  47. CVE-2026-24611 Kritisch
    Score 55 CVSS 9.1 EPSS 0.44%

    MetForm Pro: unauthentifizierte Umgehung der Zugriffskontrolle bis Version 3.9.1

  48. CVE-2026-30803 Kritisch
    Score 55 CVSS 9.1 EPSS 0.30%

    RTI Connext Micro: Integer Underflow in den Core Libraries ermöglicht Buffer Overread

  49. CVE-2026-32967 Kritisch
    Score 55 CVSS 9.1 EPSS 0.34%

    Apache DolphinScheduler: Fehlerhafte Autorisierung der experimentellen /v2-Schnittstelle

  50. CVE-2026-35270 Kritisch
    Score 55 CVSS 9.1 EPSS 0.49%

    Oracle WebCenter Content: Schwachstelle im Content Server

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.