Live-Feed 1649 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
24147
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
295
Ransomware-Bezug
4889
Kritisch
Zeige 4701 bis 4750 von 24147
- CVE-2026-55706 MittelScore 35 CVSS 5.8 EPSS 0.21%
OpenBSD: Authentifizierungsumgehung in sppp_pap_input
- CVE-2026-35067 MittelScore 34 CVSS 5.7 EPSS 0.15%
Dell PowerFlex Manager: Fehlerhafte Zugriffskontrolle
- CVE-2026-35069 MittelScore 34 CVSS 5.7 EPSS 0.23%
Dell PowerFlex Manager: SQL-Injection
- CVE-2026-0064 MittelScore 33 CVSS 5.5 EPSS 0.12%
Android/Chrome: Persistenter DoS durch Ressourcenerschöpfung
- CVE-2026-12444 MittelScore 33 CVSS 5.5 EPSS 0.14%
Google Chrome – Out-of-bounds-Read in Chromoting
- CVE-2026-28575 MittelScore 33 CVSS 5.5 EPSS 0.13%
Android PackageInstaller – Speichererschöpfung durch Logikfehler
- CVE-2026-28576 MittelScore 33 CVSS 5.5 EPSS 0.15%
Android Contacts Provider: SQL-Injection ermöglicht lokalen Informationsabfluss
- CVE-2026-28587 MittelScore 33 CVSS 5.5 EPSS 0.11%
Android MmsSmsProvider: Lokale Informationspreisgabe durch fehlende Berechtigungsprüfung
- CVE-2026-12528 MittelScore 32 CVSS 5.4 EPSS 0.23%
389 Directory Server – Heap-Buffer-Overflow bei fehlerhafter ACI
- CVE-2026-40641 MittelScore 29 CVSS 4.8 EPSS 0.10%
Dell PowerFlex Manager – Verwendung eines unsicheren kryptografischen Algorithmus
- CVE-2026-41280 MittelScore 29 CVSS 4.9 EPSS 0.44%
Apache DolphinScheduler: Fehlerhafte Autorisierung ermöglicht Löschen fremder Task-Definitionen
- CVE-2026-48142 MittelScore 29 CVSS 4.8 EPSS 0.40%
NGINX: Schwachstelle im ngx_http_charset_module
- CVE-2026-10741 MittelScore 29 CVSS 4.9 EPSS 0.26%
Sonatype Nexus Repository Manager vor 3.93.0 – Autorisierungsfehler in der Proxy-Repository-Konfiguration
- CVE-2026-12463 MittelScore 28 CVSS 4.7 EPSS 0.13%
CVE-2026-12463 – Universal XSS in Views (Google Chrome/Linux)
- CVE-2025-32748 MittelScore 26 CVSS 4.3 EPSS 0.15%
Dell PowerFlex Manager: Host-Header-Injection
- CVE-2025-48571 MittelScore 26 CVSS 4.3 EPSS 0.19%
CVE-2025-48571 – Logikfehler ermöglicht SMS-Interception (Android)
- CVE-2026-12446 MittelScore 26 CVSS 4.3 EPSS 0.19%
Google Chrome Passwords – Leck von Cross-Origin-Daten
- CVE-2026-12469 MittelScore 26 CVSS 4.3 EPSS 0.19%
Google Chrome für Android – Uninitialisierte Speichernutzung in der GPU
- CVE-2026-20178 MittelScore 26 CVSS 4.3 EPSS 0.20%
Cisco Webex App (Browser-Version): Umleitung auf bösartige Webseite
- CVE-2026-35162 MittelScore 26 CVSS 4.3 EPSS 0.21%
Dell PowerFlex Manager: Unzureichende Zugriffskontrolle
- CVE-2026-12453 MittelScore 25 CVSS 4.2 EPSS 0.18%
Google Chrome: Umgehung der Same-Origin-Policy in der Input-Komponente
- CVE-2026-12456 MittelScore 25 CVSS 4.2 EPSS 0.14%
Google Chrome: Umgehung der Same-Origin-Policy über Extensions
- CVE-2026-12457 MittelScore 25 CVSS 4.2 EPSS 0.14%
Google Chrome: Umgehung der Site-Isolation über die Extensions-Komponente
- CVE-2026-12460 MittelScore 25 CVSS 4.2 EPSS 0.15%
Google Chrome: Umgehung der Site-Isolation über File System Access
- CVE-2026-35068 NiedrigScore 21 CVSS 3.5 EPSS 0.19%
Dell PowerFlex Manager: SQL-Injection
- CVE-2026-0057 NiedrigScore 20 CVSS 3.3 EPSS 0.07%
Android Contacts Provider: Zugriff auf Anrufnummer ohne Berechtigung
- CVE-2026-12458 NiedrigScore 19 CVSS 3.1 EPSS 0.19%
Google Chrome: Cross-Origin-Datenleck in der Passwortverwaltung
- CVE-2026-46815 NiedrigScore 19 CVSS 3.2 EPSS 0.16%
Oracle VM VirtualBox: Schwachstelle in der VMSVGA-Device-Komponente
- CVE-2026-46816 NiedrigScore 19 CVSS 3.2 EPSS 0.16%
Oracle VM VirtualBox: Schwachstelle in der VMSVGA-Komponente
- CVE-2026-46874 NiedrigScore 19 CVSS 3.2 EPSS 0.13%
Oracle VM VirtualBox: Schwachstelle in der Core-Komponente
- CVE-2026-46977 NiedrigScore 19 CVSS 3.2 EPSS 0.16%
Oracle VM VirtualBox: Informationsoffenlegung in der VMSVGA-Komponente
- CVE-2026-0092 MittelScore 0 EPSS 0.22%
Android: Umgehung des Device-Lock-Controllers im Package Manager
- CVE-2026-0126 KritischScore 59 CVSS 9.8 EPSS 0.28%
WC-Radio: Out-of-bounds-Write ermöglicht Remote Code Execution
- CVE-2026-12293 KritischScore 59 CVSS 9.8 EPSS 0.30%
Firefox und Thunderbird: Use-after-free in der WebGPU-Komponente
- CVE-2026-40750 KritischScore 59 CVSS 9.9 EPSS 0.27%
Kids Online Store (WordPress) – Upload gefährlicher Dateitypen ermöglicht Web-Shell
- CVE-2026-49774 KritischScore 59 CVSS 9.9 EPSS 0.28%
RD Station – Code Injection (Remote Code Inclusion)
- CVE-2026-12294 KritischScore 58 CVSS 9.6 EPSS 0.36%
Firefox und Thunderbird: Sandbox-Ausbruch in der Komponente DOM: Workers
- CVE-2026-12295 KritischScore 58 CVSS 9.6 EPSS 0.39%
Firefox/Thunderbird: Sandbox-Escape in der Komponente DOM: Navigation
- CVE-2026-12296 KritischScore 58 CVSS 9.6 EPSS 0.39%
Firefox und Thunderbird: Sandbox-Escape im Process Sandboxing
- CVE-2026-12297 KritischScore 58 CVSS 9.6 EPSS 0.39%
Firefox und Thunderbird – Sandbox-Ausbruch durch falsche Grenzwertbedingungen in der Networking-Komponente
- CVE-2026-39574 KritischScore 56 CVSS 9.3 EPSS 0.23%
WordPress-Plugin InPost Gallery: Nicht authentifizierte SQL-Injection
- CVE-2026-49772 KritischScore 56 CVSS 9.3 EPSS 0.23%
The Events Calendar (Liquid Web / StellarWP): Blind SQL Injection
- CVE-2026-52715 KritischScore 56 CVSS 9.3 EPSS 0.25%
GEO my WordPress: Nicht authentifizierte SQL-Injection
- CVE-2026-12304 KritischScore 55 CVSS 9.1 EPSS 0.19%
Mozilla Firefox/Thunderbird – Same-Origin-Policy-Umgehung bei Cookies
- CVE-2026-12315 KritischScore 55 CVSS 9.1 EPSS 0.25%
Mozilla Firefox/Thunderbird: Umgehung einer Schutzmassnahme in der Komponente DOM: Security
- CVE-2026-12316 KritischScore 55 CVSS 9.1 EPSS 0.24%
Firefox und Thunderbird: Umgehung einer Schutzmassnahme in DOM: Security
- CVE-2026-22313 KritischScore 55 CVSS 9.1 EPSS 0.92%
OS-Command-Injection in der REST-API des Geräte-Webservers
- CVE-2026-53776 KritischScore 55 CVSS 9.1 EPSS 0.36%
Perry – JWT-Validierungsschwachstelle (Umgehung des Token-Ablaufs)
- CVE-2026-0132 HochScore 53 CVSS 8.8 EPSS 0.29%
Modem – Heap-Buffer-Overflow ermöglicht Remote Code Execution
- CVE-2026-0139 HochScore 53 CVSS 8.8 EPSS 0.28%
Android (Modem) – Out-of-bounds-Write ermöglicht Remote Code Execution
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.