Live-Feed 1649 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

23639
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
296
Ransomware-Bezug
4866
Kritisch

Zeige 4301 bis 4350 von 23639

  1. CVE-2026-35298 Kritisch
    Score 55 CVSS 9.1 EPSS 0.45%

    Oracle WebLogic Server: Schwachstelle in der Core-Komponente

  2. CVE-2026-36418 Kritisch
    Score 55 CVSS 9.1 EPSS 0.47%

    JimuReport: Remote Code Execution über Aviator-Ausdrücke in /jmreport/executeSelectApi

  3. CVE-2026-3894 Kritisch
    Score 55 CVSS 9.1 EPSS 0.20%

    RTI Connext Professional: Out-of-bounds Read in den Core Libraries

  4. CVE-2026-46777 Kritisch
    Score 55 CVSS 9.1 EPSS 0.43%

    Oracle WebCenter Content (Content Server): leicht ausnutzbare Schwachstelle in 12.2.1.4.0 und 14.1.2.0.0

  5. CVE-2026-46784 Kritisch
    Score 55 CVSS 9.1 EPSS 0.43%

    Oracle WebCenter Content: Imaging: Leicht ausnutzbare Schwachstelle in der Core-Komponente

  6. CVE-2026-46809 Kritisch
    Score 55 CVSS 9.1 EPSS 0.40%

    Oracle WebCenter Sites: Leicht ausnutzbare Schwachstelle in Oracle Fusion Middleware

  7. CVE-2026-46858 Kritisch
    Score 55 CVSS 9.1 EPSS 0.45%

    Oracle Enterprise Manager APM: Schwachstelle in JVM Diagnostics (JADM)

  8. CVE-2026-46875 Kritisch
    Score 55 CVSS 9.1 EPSS 0.45%

    Oracle Enterprise Manager Base Platform – Schwachstelle in der Deployment Library

  9. CVE-2026-46892 Kritisch
    Score 55 CVSS 9.1 EPSS 0.40%

    Oracle JD Edwards EnterpriseOne Human Resources: Schwachstelle in Version 9.2

  10. CVE-2026-46896 Kritisch
    Score 55 CVSS 9.1 EPSS 0.45%

    CVE-2026-46896 – Schwachstelle im Oracle Enterprise Command Center Framework (Oracle E-Business Suite)

  11. CVE-2026-46910 Kritisch
    Score 55 CVSS 9.1 EPSS 0.35%

    Oracle JD Edwards EnterpriseOne Tools – Schwachstelle in Enterprise Infrastructure Security

  12. CVE-2026-46930 Kritisch
    Score 55 CVSS 9.1 EPSS 0.40%

    Oracle E-Business Suite (In-Memory Cost Management) – Schwachstelle in der Komponente Internal Operations

  13. CVE-2026-46944 Kritisch
    Score 55 CVSS 9.1 EPSS 0.45%

    Oracle iSupport (E-Business Suite) – Schwachstelle in Internal Operations

  14. CVE-2026-46945 Kritisch
    Score 55 CVSS 9.1 EPSS 0.46%

    Oracle E-Business Suite (iSupport): Leicht ausnutzbare Schwachstelle in Internal Operations

  15. CVE-2026-46946 Kritisch
    Score 55 CVSS 9.1 EPSS 0.46%

    Oracle E-Business Suite (iSupport): Kritische Schwachstelle in Internal Operations

  16. CVE-2026-46949 Kritisch
    Score 55 CVSS 9.1 EPSS 0.40%

    Oracle E-Business Suite – Schwachstelle in Advanced Outbound Telephony

  17. CVE-2026-48814 Kritisch
    Score 55 CVSS 9.1 EPSS 0.30%

    Network-AI – Unauthentifizierte MCP-Tool-Aufrufe durch leeres Standard-Secret

  18. CVE-2026-49268 Kritisch
    Score 55 CVSS 9.1 EPSS 0.49%

    LDAP-Injection in DefaultLdapRealm über nicht bereinigten Benutzernamen

  19. CVE-2026-50203 Kritisch
    Score 55 CVSS 9.1 EPSS 0.63%

    Apache Airflow SFTP-Provider – Path Traversal

  20. CVE-2026-54387 Kritisch
    Score 55 CVSS 9.1 EPSS 0.44%

    Tinyproxy – HTTP-Request-Smuggling durch widersprüchliche Header

  21. CVE-2026-54388 Kritisch
    Score 55 CVSS 9.1 EPSS 0.44%

    Tinyproxy – Request Smuggling durch mehrfache Content-Length-Header

  22. CVE-2026-55196 Kritisch
    Score 55 CVSS 9.1 EPSS 0.58%

    Hermes WebUI: Authentifizierungsumgehung bei der Passkey-Registrierung

  23. CVE-2026-35320 Kritisch
    Score 54 CVSS 9 EPSS 0.37%

    CVE-2026-35320 – Schwachstelle in Oracle WebCenter Content (Content Server)

  24. CVE-2026-46872 Kritisch
    Score 54 CVSS 9 EPSS 0.28%

    Oracle Enterprise Manager Base Platform – Schwachstelle in der Komponente Install

  25. CVE-2026-52705 Kritisch
    Score 54 CVSS 9 EPSS 0.29%

    SigmaForms Pro – AI Generated Forms: Nicht authentifiziertes Hochladen beliebiger Dateien

  26. CVE-2026-12439 Hoch
    Score 53 CVSS 8.8 EPSS 0.32%

    CVE-2026-12439 – Use-after-free in Digital Credentials (Google Chrome)

  27. CVE-2026-12441 Hoch
    Score 53 CVSS 8.8 EPSS 0.30%

    Google Chrome – Use-after-free in File Input

  28. CVE-2026-12442 Hoch
    Score 53 CVSS 8.8 EPSS 0.39%

    Google Chrome für Android (Passwords) – Use-after-free ermöglicht Codeausführung

  29. CVE-2026-12443 Hoch
    Score 53 CVSS 8.8 EPSS 0.60%

    Google Chrome – Use-after-free in Web Authentication

  30. CVE-2026-12447 Hoch
    Score 53 CVSS 8.8 EPSS 0.42%

    Google Chrome: Heap-Buffer-Overflow in WebRTC ermöglicht Code-Ausführung

  31. CVE-2026-12448 Hoch
    Score 53 CVSS 8.8 EPSS 0.26%

    Google Chrome (Android): Fehlerhafte Implementierung in WebView ermöglicht Rechteausweitung

  32. CVE-2026-12452 Hoch
    Score 53 CVSS 8.8 EPSS 0.26%

    Google Chrome auf Android – Use-after-free in Downloads

  33. CVE-2026-12466 Hoch
    Score 53 CVSS 8.8 EPSS 0.43%

    Google Chrome unter Windows: Heap-Buffer-Overflow in WebRTC

  34. CVE-2026-35065 Hoch
    Score 53 CVSS 8.8 EPSS 0.33%

    Fehlende Authentifizierung in Dell PowerFlex Manager

  35. CVE-2026-35259 Hoch
    Score 53 CVSS 8.8 EPSS 0.42%

    Oracle WebLogic Server: Schwachstelle in der Console-Komponente

  36. CVE-2026-35265 Hoch
    Score 53 CVSS 8.8 EPSS 0.43%

    Oracle Identity Manager – Leicht ausnutzbare Schwachstelle in der Komponente Security

  37. CVE-2026-35267 Hoch
    Score 53 CVSS 8.8 EPSS 0.43%

    Schwachstelle in Oracle Identity Manager (REST-Webservices)

  38. CVE-2026-35299 Hoch
    Score 53 CVSS 8.8 EPSS 0.40%

    Oracle WebLogic Server: Schwachstelle in der Console-Komponente

  39. CVE-2026-35303 Hoch
    Score 53 CVSS 8.8 EPSS 0.40%

    Schwachstelle in der Console von Oracle WebLogic Server

  40. CVE-2026-35311 Hoch
    Score 53 CVSS 8.8 EPSS 0.40%

    Oracle WebLogic Server (Fusion Middleware): Leicht ausnutzbare Schwachstelle in der Core-Komponente

  41. CVE-2026-35258 Hoch
    Score 52 CVSS 8.7 EPSS 0.33%

    Oracle WebLogic Server: Schwachstelle in der Console-Komponente

  42. CVE-2026-35271 Hoch
    Score 52 CVSS 8.7 EPSS 0.34%

    Schwachstelle in Oracle PeopleSoft PT PeopleTools (Weblogic)

  43. CVE-2026-46870 Hoch
    Score 51 CVSS 8.5 EPSS 0.31%

    Schwachstelle in Oracle MySQL Shell for VS Code

  44. CVE-2026-12437 Hoch
    Score 50 CVSS 8.3 EPSS 0.28%

    Use-after-free in Google Chrome für Windows (WebShare)

  45. CVE-2026-12438 Hoch
    Score 50 CVSS 8.3 EPSS 0.21%

    Google Chrome: Fehlerhafte Implementierung in WebView (Android)

  46. CVE-2026-12451 Hoch
    Score 50 CVSS 8.3 EPSS 0.17%

    Use-after-free in DigitalCredentials von Google Chrome

  47. CVE-2026-12454 Hoch
    Score 50 CVSS 8.3 EPSS 0.15%

    Google Chrome (macOS): Race Condition in Safe Browsing (Sandbox-Ausbruch)

  48. CVE-2026-12464 Hoch
    Score 50 CVSS 8.3 EPSS 0.22%

    Google Chrome: Use-after-free in Browser

  49. CVE-2026-12465 Hoch
    Score 50 CVSS 8.3 EPSS 0.24%

    Object-Lifecycle-Fehler in Metrics (Google Chrome)

  50. CVE-2026-12467 Hoch
    Score 50 CVSS 8.3 EPSS 0.22%

    Google Chrome: Sandbox-Escape durch Use-after-free in Extensions

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.