Live-Feed 1649 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

24147
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
295
Ransomware-Bezug
4889
Kritisch

Zeige 4701 bis 4750 von 24147

  1. CVE-2026-55706 Mittel
    Score 35 CVSS 5.8 EPSS 0.21%

    OpenBSD: Authentifizierungsumgehung in sppp_pap_input

  2. CVE-2026-35067 Mittel
    Score 34 CVSS 5.7 EPSS 0.15%

    Dell PowerFlex Manager: Fehlerhafte Zugriffskontrolle

  3. CVE-2026-35069 Mittel
    Score 34 CVSS 5.7 EPSS 0.23%

    Dell PowerFlex Manager: SQL-Injection

  4. CVE-2026-0064 Mittel
    Score 33 CVSS 5.5 EPSS 0.12%

    Android/Chrome: Persistenter DoS durch Ressourcenerschöpfung

  5. CVE-2026-12444 Mittel
    Score 33 CVSS 5.5 EPSS 0.14%

    Google Chrome – Out-of-bounds-Read in Chromoting

  6. CVE-2026-28575 Mittel
    Score 33 CVSS 5.5 EPSS 0.13%

    Android PackageInstaller – Speichererschöpfung durch Logikfehler

  7. CVE-2026-28576 Mittel
    Score 33 CVSS 5.5 EPSS 0.15%

    Android Contacts Provider: SQL-Injection ermöglicht lokalen Informationsabfluss

  8. CVE-2026-28587 Mittel
    Score 33 CVSS 5.5 EPSS 0.11%

    Android MmsSmsProvider: Lokale Informationspreisgabe durch fehlende Berechtigungsprüfung

  9. CVE-2026-12528 Mittel
    Score 32 CVSS 5.4 EPSS 0.23%

    389 Directory Server – Heap-Buffer-Overflow bei fehlerhafter ACI

  10. CVE-2026-40641 Mittel
    Score 29 CVSS 4.8 EPSS 0.10%

    Dell PowerFlex Manager – Verwendung eines unsicheren kryptografischen Algorithmus

  11. CVE-2026-41280 Mittel
    Score 29 CVSS 4.9 EPSS 0.44%

    Apache DolphinScheduler: Fehlerhafte Autorisierung ermöglicht Löschen fremder Task-Definitionen

  12. CVE-2026-48142 Mittel
    Score 29 CVSS 4.8 EPSS 0.40%

    NGINX: Schwachstelle im ngx_http_charset_module

  13. CVE-2026-10741 Mittel
    Score 29 CVSS 4.9 EPSS 0.26%

    Sonatype Nexus Repository Manager vor 3.93.0 – Autorisierungsfehler in der Proxy-Repository-Konfiguration

  14. CVE-2026-12463 Mittel
    Score 28 CVSS 4.7 EPSS 0.13%

    CVE-2026-12463 – Universal XSS in Views (Google Chrome/Linux)

  15. CVE-2025-32748 Mittel
    Score 26 CVSS 4.3 EPSS 0.15%

    Dell PowerFlex Manager: Host-Header-Injection

  16. CVE-2025-48571 Mittel
    Score 26 CVSS 4.3 EPSS 0.19%

    CVE-2025-48571 – Logikfehler ermöglicht SMS-Interception (Android)

  17. CVE-2026-12446 Mittel
    Score 26 CVSS 4.3 EPSS 0.19%

    Google Chrome Passwords – Leck von Cross-Origin-Daten

  18. CVE-2026-12469 Mittel
    Score 26 CVSS 4.3 EPSS 0.19%

    Google Chrome für Android – Uninitialisierte Speichernutzung in der GPU

  19. CVE-2026-20178 Mittel
    Score 26 CVSS 4.3 EPSS 0.20%

    Cisco Webex App (Browser-Version): Umleitung auf bösartige Webseite

  20. CVE-2026-35162 Mittel
    Score 26 CVSS 4.3 EPSS 0.21%

    Dell PowerFlex Manager: Unzureichende Zugriffskontrolle

  21. CVE-2026-12453 Mittel
    Score 25 CVSS 4.2 EPSS 0.18%

    Google Chrome: Umgehung der Same-Origin-Policy in der Input-Komponente

  22. CVE-2026-12456 Mittel
    Score 25 CVSS 4.2 EPSS 0.14%

    Google Chrome: Umgehung der Same-Origin-Policy über Extensions

  23. CVE-2026-12457 Mittel
    Score 25 CVSS 4.2 EPSS 0.14%

    Google Chrome: Umgehung der Site-Isolation über die Extensions-Komponente

  24. CVE-2026-12460 Mittel
    Score 25 CVSS 4.2 EPSS 0.15%

    Google Chrome: Umgehung der Site-Isolation über File System Access

  25. CVE-2026-35068 Niedrig
    Score 21 CVSS 3.5 EPSS 0.19%

    Dell PowerFlex Manager: SQL-Injection

  26. CVE-2026-0057 Niedrig
    Score 20 CVSS 3.3 EPSS 0.07%

    Android Contacts Provider: Zugriff auf Anrufnummer ohne Berechtigung

  27. CVE-2026-12458 Niedrig
    Score 19 CVSS 3.1 EPSS 0.19%

    Google Chrome: Cross-Origin-Datenleck in der Passwortverwaltung

  28. CVE-2026-46815 Niedrig
    Score 19 CVSS 3.2 EPSS 0.16%

    Oracle VM VirtualBox: Schwachstelle in der VMSVGA-Device-Komponente

  29. CVE-2026-46816 Niedrig
    Score 19 CVSS 3.2 EPSS 0.16%

    Oracle VM VirtualBox: Schwachstelle in der VMSVGA-Komponente

  30. CVE-2026-46874 Niedrig
    Score 19 CVSS 3.2 EPSS 0.13%

    Oracle VM VirtualBox: Schwachstelle in der Core-Komponente

  31. CVE-2026-46977 Niedrig
    Score 19 CVSS 3.2 EPSS 0.16%

    Oracle VM VirtualBox: Informationsoffenlegung in der VMSVGA-Komponente

  32. CVE-2026-0092 Mittel
    Score 0 EPSS 0.22%

    Android: Umgehung des Device-Lock-Controllers im Package Manager

  33. CVE-2026-0126 Kritisch
    Score 59 CVSS 9.8 EPSS 0.28%

    WC-Radio: Out-of-bounds-Write ermöglicht Remote Code Execution

  34. CVE-2026-12293 Kritisch
    Score 59 CVSS 9.8 EPSS 0.30%

    Firefox und Thunderbird: Use-after-free in der WebGPU-Komponente

  35. CVE-2026-40750 Kritisch
    Score 59 CVSS 9.9 EPSS 0.27%

    Kids Online Store (WordPress) – Upload gefährlicher Dateitypen ermöglicht Web-Shell

  36. CVE-2026-49774 Kritisch
    Score 59 CVSS 9.9 EPSS 0.28%

    RD Station – Code Injection (Remote Code Inclusion)

  37. CVE-2026-12294 Kritisch
    Score 58 CVSS 9.6 EPSS 0.36%

    Firefox und Thunderbird: Sandbox-Ausbruch in der Komponente DOM: Workers

  38. CVE-2026-12295 Kritisch
    Score 58 CVSS 9.6 EPSS 0.39%

    Firefox/Thunderbird: Sandbox-Escape in der Komponente DOM: Navigation

  39. CVE-2026-12296 Kritisch
    Score 58 CVSS 9.6 EPSS 0.39%

    Firefox und Thunderbird: Sandbox-Escape im Process Sandboxing

  40. CVE-2026-12297 Kritisch
    Score 58 CVSS 9.6 EPSS 0.39%

    Firefox und Thunderbird – Sandbox-Ausbruch durch falsche Grenzwertbedingungen in der Networking-Komponente

  41. CVE-2026-39574 Kritisch
    Score 56 CVSS 9.3 EPSS 0.23%

    WordPress-Plugin InPost Gallery: Nicht authentifizierte SQL-Injection

  42. CVE-2026-49772 Kritisch
    Score 56 CVSS 9.3 EPSS 0.23%

    The Events Calendar (Liquid Web / StellarWP): Blind SQL Injection

  43. CVE-2026-52715 Kritisch
    Score 56 CVSS 9.3 EPSS 0.25%

    GEO my WordPress: Nicht authentifizierte SQL-Injection

  44. CVE-2026-12304 Kritisch
    Score 55 CVSS 9.1 EPSS 0.19%

    Mozilla Firefox/Thunderbird – Same-Origin-Policy-Umgehung bei Cookies

  45. CVE-2026-12315 Kritisch
    Score 55 CVSS 9.1 EPSS 0.25%

    Mozilla Firefox/Thunderbird: Umgehung einer Schutzmassnahme in der Komponente DOM: Security

  46. CVE-2026-12316 Kritisch
    Score 55 CVSS 9.1 EPSS 0.24%

    Firefox und Thunderbird: Umgehung einer Schutzmassnahme in DOM: Security

  47. CVE-2026-22313 Kritisch
    Score 55 CVSS 9.1 EPSS 0.92%

    OS-Command-Injection in der REST-API des Geräte-Webservers

  48. CVE-2026-53776 Kritisch
    Score 55 CVSS 9.1 EPSS 0.36%

    Perry – JWT-Validierungsschwachstelle (Umgehung des Token-Ablaufs)

  49. CVE-2026-0132 Hoch
    Score 53 CVSS 8.8 EPSS 0.29%

    Modem – Heap-Buffer-Overflow ermöglicht Remote Code Execution

  50. CVE-2026-0139 Hoch
    Score 53 CVSS 8.8 EPSS 0.28%

    Android (Modem) – Out-of-bounds-Write ermöglicht Remote Code Execution

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.