Live-Feed 1649 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

23993
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
295
Ransomware-Bezug
4878
Kritisch

Zeige 4651 bis 4700 von 23993

  1. CVE-2026-12455 Hoch
    Score 45 CVSS 7.5 EPSS 0.23%

    Google Chrome: Use-after-free im Tab Strip

  2. CVE-2026-12462 Hoch
    Score 45 CVSS 7.5 EPSS 0.27%

    Google Chrome (Media) – Use-after-free ermöglicht Codeausführung

  3. CVE-2026-20190 Hoch
    Score 45 CVSS 7.5 EPSS 0.41%

    Cisco ISE / ISE-PIC: Fehlerhafte Autorisierung ermöglicht Zugriff auf sensible Informationen

  4. CVE-2026-22283 Hoch
    Score 45 CVSS 7.5 EPSS 0.21%

    Dell PowerFlex Manager: Einbindung von Funktionen aus nicht vertrauenswürdiger Quelle

  5. CVE-2026-35269 Hoch
    Score 45 CVSS 7.5 EPSS 0.35%

    Oracle Fusion Middleware Identity Manager – Schwachstelle in REST WebServices

  6. CVE-2026-35275 Hoch
    Score 45 CVSS 7.5 EPSS 0.12%

    Oracle VM VirtualBox – Schwachstelle in der Shared-Folders-Komponente

  7. CVE-2026-46862 Hoch
    Score 45 CVSS 7.5 EPSS 0.46%

    Oracle MySQL Router (Router: General) – Schwachstelle beeinträchtigt Verfügbarkeit

  8. CVE-2026-46863 Hoch
    Score 45 CVSS 7.5 EPSS 0.47%

    Oracle MySQL Server / MySQL Cluster: Schwachstelle im Connection Handling

  9. CVE-2026-46873 Hoch
    Score 45 CVSS 7.5 EPSS 0.11%

    Oracle VM VirtualBox: Schwachstelle in der VMSVGA-Komponente

  10. CVE-2026-46974 Hoch
    Score 45 CVSS 7.5 EPSS 0.14%

    Oracle VM VirtualBox: Schwachstelle in der Core-Komponente (Version 7.2.8)

  11. CVE-2026-47774 Hoch
    Score 45 CVSS 7.5 EPSS 0.81%

    Envoy: Schwachstelle in der HTTP/2-Downstream-Verarbeitung

  12. CVE-2026-6734 Hoch
    Score 45 CVSS 7.5 EPSS 0.36%

    Node.js undici – Wiederverwendung des Verbindungspools über Origins hinweg

  13. CVE-2026-12151 Hoch
    Score 45 CVSS 7.5 EPSS 0.79%

    undici (Node.js) – Denial of Service durch unbegrenzte Anzahl WebSocket-Fragmente

  14. CVE-2026-48294 Hoch
    Score 44 CVSS 7.4 EPSS 0.72%

    Adobe Acrobat PDF Extension (Chrome): UXSS-Cross-Origin-Datenoffenlegung

  15. CVE-2026-49502 Hoch
    Score 44 CVSS 7.4 EPSS 0.21%

    Dell PowerFlex Manager: Improper Authentication ermöglicht Zugriff aus benachbartem Netzwerk

  16. CVE-2026-9697 Hoch
    Score 44 CVSS 7.4 EPSS 0.48%

    undici (Node.js) – requestTls wird bei SOCKS5-Proxy stillschweigend verworfen

  17. CVE-2026-35066 Hoch
    Score 43 CVSS 7.1 EPSS 0.18%

    Dell PowerFlex Manager – Improper Access Control

  18. CVE-2026-0083 Hoch
    Score 42 CVSS 7 EPSS 0.12%

    Android: Use-after-free in Nfc::eventCallback() ermöglicht lokale Rechteausweitung

  19. CVE-2026-35291 Mittel
    Score 40 CVSS 6.6 EPSS 0.35%

    Oracle WebLogic Server (Fusion Middleware) – Schwachstelle in der Console-Komponente

  20. CVE-2024-47477 Mittel
    Score 39 CVSS 6.5 EPSS 0.12%

    Dell PowerFlex Manager – Unzureichende Zertifikatsprüfung

  21. CVE-2026-12450 Mittel
    Score 39 CVSS 6.5 EPSS 0.18%

    Google Chrome: Auslesen sensibler Informationen in Media

  22. CVE-2026-12461 Mittel
    Score 39 CVSS 6.5 EPSS 0.24%

    Google Chrome (Windows) – Out-of-Bounds-Read in WebRTC

  23. CVE-2026-32682 Mittel
    Score 39 CVSS 6.5 EPSS 0.29%

    NGINX Gateway Fabric – Denial of Service der Control Plane über GRPCRoutes

  24. CVE-2026-42357 Mittel
    Score 39 CVSS 6.5 EPSS 0.31%

    Apache DolphinScheduler – Fehlerhafte Autorisierung

  25. CVE-2026-46810 Mittel
    Score 39 CVSS 6.5 EPSS 0.27%

    Oracle Identity Manager (Fusion Middleware) – Schwachstelle im End-User-Self-Service

  26. CVE-2026-46869 Mittel
    Score 39 CVSS 6.5 EPSS 0.18%

    Oracle MySQL Shell: Schwachstelle in der Dump-and-Load-Komponente

  27. CVE-2026-46871 Mittel
    Score 39 CVSS 6.5 EPSS 0.26%

    Oracle MySQL Shell (Shell for VS Code): Schwachstelle

  28. CVE-2026-46979 Mittel
    Score 39 CVSS 6.5 EPSS 0.29%

    Oracle PeopleSoft Campus Community: Schwachstelle in Integration/Interfaces

  29. CVE-2026-47340 Mittel
    Score 39 CVSS 6.5 EPSS 0.43%

    Apache DolphinScheduler: Unberechtigter Zugriff auf Alert-Instanzen

  30. CVE-2026-20220 Mittel
    Score 38 CVSS 6.3 EPSS 0.25%

    Cisco Crosswork Network Controller: Command Injection im Management-Interface

  31. CVE-2026-12459 Mittel
    Score 37 CVSS 6.1 EPSS 0.18%

    Google Chrome: UXSS durch fehlerhafte Implementierung in der Serial-Komponente

  32. CVE-2026-20246 Mittel
    Score 36 CVSS 6 EPSS 0.10%

    Cisco Umbrella Virtual Appliance: Rechteausweitung über die vmadmin-CLI

  33. CVE-2026-46768 Mittel
    Score 36 CVSS 6 EPSS 0.15%

    Oracle VM VirtualBox: Schwachstelle in der VMSVGA-Komponente

  34. CVE-2026-46825 Mittel
    Score 36 CVSS 6 EPSS 0.16%

    Oracle VM VirtualBox – Schwachstelle in der VMSVGA-Komponente

  35. CVE-2026-46877 Mittel
    Score 36 CVSS 6 EPSS 0.17%

    Oracle VM VirtualBox: Schwachstelle in der VMSVGA-Gerätekomponente

  36. CVE-2026-55706 Mittel
    Score 35 CVSS 5.8 EPSS 0.21%

    OpenBSD: Authentifizierungsumgehung in sppp_pap_input

  37. CVE-2026-35067 Mittel
    Score 34 CVSS 5.7 EPSS 0.15%

    Dell PowerFlex Manager: Fehlerhafte Zugriffskontrolle

  38. CVE-2026-35069 Mittel
    Score 34 CVSS 5.7 EPSS 0.23%

    Dell PowerFlex Manager: SQL-Injection

  39. CVE-2026-0064 Mittel
    Score 33 CVSS 5.5 EPSS 0.12%

    Android/Chrome: Persistenter DoS durch Ressourcenerschöpfung

  40. CVE-2026-12444 Mittel
    Score 33 CVSS 5.5 EPSS 0.14%

    Google Chrome – Out-of-bounds-Read in Chromoting

  41. CVE-2026-28575 Mittel
    Score 33 CVSS 5.5 EPSS 0.13%

    Android PackageInstaller – Speichererschöpfung durch Logikfehler

  42. CVE-2026-28576 Mittel
    Score 33 CVSS 5.5 EPSS 0.15%

    Android Contacts Provider: SQL-Injection ermöglicht lokalen Informationsabfluss

  43. CVE-2026-28587 Mittel
    Score 33 CVSS 5.5 EPSS 0.11%

    Android MmsSmsProvider: Lokale Informationspreisgabe durch fehlende Berechtigungsprüfung

  44. CVE-2026-12528 Mittel
    Score 32 CVSS 5.4 EPSS 0.23%

    389 Directory Server – Heap-Buffer-Overflow bei fehlerhafter ACI

  45. CVE-2026-40641 Mittel
    Score 29 CVSS 4.8 EPSS 0.10%

    Dell PowerFlex Manager – Verwendung eines unsicheren kryptografischen Algorithmus

  46. CVE-2026-41280 Mittel
    Score 29 CVSS 4.9 EPSS 0.44%

    Apache DolphinScheduler: Fehlerhafte Autorisierung ermöglicht Löschen fremder Task-Definitionen

  47. CVE-2026-48142 Mittel
    Score 29 CVSS 4.8 EPSS 0.40%

    NGINX: Schwachstelle im ngx_http_charset_module

  48. CVE-2026-10741 Mittel
    Score 29 CVSS 4.9 EPSS 0.26%

    Sonatype Nexus Repository Manager vor 3.93.0 – Autorisierungsfehler in der Proxy-Repository-Konfiguration

  49. CVE-2026-12463 Mittel
    Score 28 CVSS 4.7 EPSS 0.13%

    CVE-2026-12463 – Universal XSS in Views (Google Chrome/Linux)

  50. CVE-2025-32748 Mittel
    Score 26 CVSS 4.3 EPSS 0.15%

    Dell PowerFlex Manager: Host-Header-Injection

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.