Live-Feed 1649 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
23993
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
295
Ransomware-Bezug
4878
Kritisch
Zeige 4651 bis 4700 von 23993
- CVE-2026-12455 HochScore 45 CVSS 7.5 EPSS 0.23%
Google Chrome: Use-after-free im Tab Strip
- CVE-2026-12462 HochScore 45 CVSS 7.5 EPSS 0.27%
Google Chrome (Media) – Use-after-free ermöglicht Codeausführung
- CVE-2026-20190 HochScore 45 CVSS 7.5 EPSS 0.41%
Cisco ISE / ISE-PIC: Fehlerhafte Autorisierung ermöglicht Zugriff auf sensible Informationen
- CVE-2026-22283 HochScore 45 CVSS 7.5 EPSS 0.21%
Dell PowerFlex Manager: Einbindung von Funktionen aus nicht vertrauenswürdiger Quelle
- CVE-2026-35269 HochScore 45 CVSS 7.5 EPSS 0.35%
Oracle Fusion Middleware Identity Manager – Schwachstelle in REST WebServices
- CVE-2026-35275 HochScore 45 CVSS 7.5 EPSS 0.12%
Oracle VM VirtualBox – Schwachstelle in der Shared-Folders-Komponente
- CVE-2026-46862 HochScore 45 CVSS 7.5 EPSS 0.46%
Oracle MySQL Router (Router: General) – Schwachstelle beeinträchtigt Verfügbarkeit
- CVE-2026-46863 HochScore 45 CVSS 7.5 EPSS 0.47%
Oracle MySQL Server / MySQL Cluster: Schwachstelle im Connection Handling
- CVE-2026-46873 HochScore 45 CVSS 7.5 EPSS 0.11%
Oracle VM VirtualBox: Schwachstelle in der VMSVGA-Komponente
- CVE-2026-46974 HochScore 45 CVSS 7.5 EPSS 0.14%
Oracle VM VirtualBox: Schwachstelle in der Core-Komponente (Version 7.2.8)
- CVE-2026-47774 HochScore 45 CVSS 7.5 EPSS 0.81%
Envoy: Schwachstelle in der HTTP/2-Downstream-Verarbeitung
- CVE-2026-6734 HochScore 45 CVSS 7.5 EPSS 0.36%
Node.js undici – Wiederverwendung des Verbindungspools über Origins hinweg
- CVE-2026-12151 HochScore 45 CVSS 7.5 EPSS 0.79%
undici (Node.js) – Denial of Service durch unbegrenzte Anzahl WebSocket-Fragmente
- CVE-2026-48294 HochScore 44 CVSS 7.4 EPSS 0.72%
Adobe Acrobat PDF Extension (Chrome): UXSS-Cross-Origin-Datenoffenlegung
- CVE-2026-49502 HochScore 44 CVSS 7.4 EPSS 0.21%
Dell PowerFlex Manager: Improper Authentication ermöglicht Zugriff aus benachbartem Netzwerk
- CVE-2026-9697 HochScore 44 CVSS 7.4 EPSS 0.48%
undici (Node.js) – requestTls wird bei SOCKS5-Proxy stillschweigend verworfen
- CVE-2026-35066 HochScore 43 CVSS 7.1 EPSS 0.18%
Dell PowerFlex Manager – Improper Access Control
- CVE-2026-0083 HochScore 42 CVSS 7 EPSS 0.12%
Android: Use-after-free in Nfc::eventCallback() ermöglicht lokale Rechteausweitung
- CVE-2026-35291 MittelScore 40 CVSS 6.6 EPSS 0.35%
Oracle WebLogic Server (Fusion Middleware) – Schwachstelle in der Console-Komponente
- CVE-2024-47477 MittelScore 39 CVSS 6.5 EPSS 0.12%
Dell PowerFlex Manager – Unzureichende Zertifikatsprüfung
- CVE-2026-12450 MittelScore 39 CVSS 6.5 EPSS 0.18%
Google Chrome: Auslesen sensibler Informationen in Media
- CVE-2026-12461 MittelScore 39 CVSS 6.5 EPSS 0.24%
Google Chrome (Windows) – Out-of-Bounds-Read in WebRTC
- CVE-2026-32682 MittelScore 39 CVSS 6.5 EPSS 0.29%
NGINX Gateway Fabric – Denial of Service der Control Plane über GRPCRoutes
- CVE-2026-42357 MittelScore 39 CVSS 6.5 EPSS 0.31%
Apache DolphinScheduler – Fehlerhafte Autorisierung
- CVE-2026-46810 MittelScore 39 CVSS 6.5 EPSS 0.27%
Oracle Identity Manager (Fusion Middleware) – Schwachstelle im End-User-Self-Service
- CVE-2026-46869 MittelScore 39 CVSS 6.5 EPSS 0.18%
Oracle MySQL Shell: Schwachstelle in der Dump-and-Load-Komponente
- CVE-2026-46871 MittelScore 39 CVSS 6.5 EPSS 0.26%
Oracle MySQL Shell (Shell for VS Code): Schwachstelle
- CVE-2026-46979 MittelScore 39 CVSS 6.5 EPSS 0.29%
Oracle PeopleSoft Campus Community: Schwachstelle in Integration/Interfaces
- CVE-2026-47340 MittelScore 39 CVSS 6.5 EPSS 0.43%
Apache DolphinScheduler: Unberechtigter Zugriff auf Alert-Instanzen
- CVE-2026-20220 MittelScore 38 CVSS 6.3 EPSS 0.25%
Cisco Crosswork Network Controller: Command Injection im Management-Interface
- CVE-2026-12459 MittelScore 37 CVSS 6.1 EPSS 0.18%
Google Chrome: UXSS durch fehlerhafte Implementierung in der Serial-Komponente
- CVE-2026-20246 MittelScore 36 CVSS 6 EPSS 0.10%
Cisco Umbrella Virtual Appliance: Rechteausweitung über die vmadmin-CLI
- CVE-2026-46768 MittelScore 36 CVSS 6 EPSS 0.15%
Oracle VM VirtualBox: Schwachstelle in der VMSVGA-Komponente
- CVE-2026-46825 MittelScore 36 CVSS 6 EPSS 0.16%
Oracle VM VirtualBox – Schwachstelle in der VMSVGA-Komponente
- CVE-2026-46877 MittelScore 36 CVSS 6 EPSS 0.17%
Oracle VM VirtualBox: Schwachstelle in der VMSVGA-Gerätekomponente
- CVE-2026-55706 MittelScore 35 CVSS 5.8 EPSS 0.21%
OpenBSD: Authentifizierungsumgehung in sppp_pap_input
- CVE-2026-35067 MittelScore 34 CVSS 5.7 EPSS 0.15%
Dell PowerFlex Manager: Fehlerhafte Zugriffskontrolle
- CVE-2026-35069 MittelScore 34 CVSS 5.7 EPSS 0.23%
Dell PowerFlex Manager: SQL-Injection
- CVE-2026-0064 MittelScore 33 CVSS 5.5 EPSS 0.12%
Android/Chrome: Persistenter DoS durch Ressourcenerschöpfung
- CVE-2026-12444 MittelScore 33 CVSS 5.5 EPSS 0.14%
Google Chrome – Out-of-bounds-Read in Chromoting
- CVE-2026-28575 MittelScore 33 CVSS 5.5 EPSS 0.13%
Android PackageInstaller – Speichererschöpfung durch Logikfehler
- CVE-2026-28576 MittelScore 33 CVSS 5.5 EPSS 0.15%
Android Contacts Provider: SQL-Injection ermöglicht lokalen Informationsabfluss
- CVE-2026-28587 MittelScore 33 CVSS 5.5 EPSS 0.11%
Android MmsSmsProvider: Lokale Informationspreisgabe durch fehlende Berechtigungsprüfung
- CVE-2026-12528 MittelScore 32 CVSS 5.4 EPSS 0.23%
389 Directory Server – Heap-Buffer-Overflow bei fehlerhafter ACI
- CVE-2026-40641 MittelScore 29 CVSS 4.8 EPSS 0.10%
Dell PowerFlex Manager – Verwendung eines unsicheren kryptografischen Algorithmus
- CVE-2026-41280 MittelScore 29 CVSS 4.9 EPSS 0.44%
Apache DolphinScheduler: Fehlerhafte Autorisierung ermöglicht Löschen fremder Task-Definitionen
- CVE-2026-48142 MittelScore 29 CVSS 4.8 EPSS 0.40%
NGINX: Schwachstelle im ngx_http_charset_module
- CVE-2026-10741 MittelScore 29 CVSS 4.9 EPSS 0.26%
Sonatype Nexus Repository Manager vor 3.93.0 – Autorisierungsfehler in der Proxy-Repository-Konfiguration
- CVE-2026-12463 MittelScore 28 CVSS 4.7 EPSS 0.13%
CVE-2026-12463 – Universal XSS in Views (Google Chrome/Linux)
- CVE-2025-32748 MittelScore 26 CVSS 4.3 EPSS 0.15%
Dell PowerFlex Manager: Host-Header-Injection
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.