Live-Feed 1649 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
24248
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
295
Ransomware-Bezug
4900
Kritisch
Zeige 4801 bis 4850 von 24248
- CVE-2026-0135 HochScore 47 CVSS 7.8 EPSS 0.10%
Android Modem – Out-of-Bounds-Read ermöglicht Remote Code Execution
- CVE-2026-0137 HochScore 47 CVSS 7.8 EPSS 0.07%
Android edgetpu-dmabuf: Use-after-free ermöglicht Rechteausweitung
- CVE-2026-0138 HochScore 47 CVSS 7.8 EPSS 0.07%
Android/ChromeOS – Out-of-bounds Write in lwis_io_buffer_write
- CVE-2026-0143 HochScore 47 CVSS 7.8 EPSS 0.07%
Android LWIS: Rechteausweitung durch Use-after-free in lwis_event.c
- CVE-2026-0150 HochScore 47 CVSS 7.8 EPSS 0.07%
Android EdgeTPU-Firmware – Out-of-bounds-Write durch Integer-Überlauf
- CVE-2026-0152 HochScore 47 CVSS 7.8 EPSS 0.07%
Android – Lokale Rechteausweitung durch Logikfehler in pmr_os.c (OSMMapPMRGeneric)
- CVE-2026-0153 HochScore 47 CVSS 7.8 EPSS 0.07%
Out-of-Bounds-Write in msg_to_host_buffer.cc ermöglicht Rechteausweitung
- CVE-2026-24155 HochScore 47 CVSS 7.8 EPSS 0.19%
NVIDIA NeMo Framework: Code-Injection-Schwachstelle
- CVE-2026-24228 HochScore 47 CVSS 7.8 EPSS 0.16%
NVIDIA NeMo Framework (Linux) – Deserialisierung nicht vertrauenswürdiger Daten
- CVE-2026-46331 HochScore 47 CVSS 7.8 EPSS 0.32%
Linux-Kernel: Page-Cache-Korruption durch fehlerhaftes pedit-COW (net/sched)
- CVE-2026-47964 HochScore 47 CVSS 7.8 EPSS 0.20%
Adobe DNG SDK: Heap-basierter Pufferüberlauf ermöglicht Codeausführung
- CVE-2026-0156 HochScore 45 CVSS 7.5 EPSS 0.21%
Android: Fehlende NULL-Prüfung in RtpSession ermöglicht Denial of Service
- CVE-2026-0131 HochScore 44 CVSS 7.3 EPSS 0.07%
RtpPacket::decodePacket: Integer-Überlauf ermöglicht lokale Rechteausweitung
- CVE-2026-0125 HochScore 42 CVSS 7 EPSS 0.07%
Android: Use-after-Free durch Race Condition in vpu_ioctl.c
- CVE-2026-9261 MittelScore 41 CVSS 6.8 EPSS 0.18%
Canon EOS Network Setting Tool: Schwache SSH-Kryptoalgorithmen
- CVE-2024-22447 MittelScore 40 CVSS 6.7 EPSS 0.10%
Dell Peripheral Manager: Unkontrolliertes Search-Path-Element ermöglicht DLL-Preloading
- CVE-2024-22451 MittelScore 40 CVSS 6.7 EPSS 0.10%
Dell Peripheral Manager: Uncontrolled Search Path Element
- CVE-2026-0127 MittelScore 39 CVSS 6.5 EPSS 0.25%
Android/ChromeOS: Out-of-Bounds-Read im NRMM-Decoder (Remote-DoS)
- CVE-2026-0128 MittelScore 39 CVSS 6.5 EPSS 0.18%
Out-of-Bounds-Read durch Integer-Überlauf in RtcpFbPacket::decodeRtcpFbPacket
- CVE-2026-0136 MittelScore 39 CVSS 6.5 EPSS 0.25%
Modem-Komponente: Out-of-Bounds-Read (Remote DoS)
- CVE-2026-0144 MittelScore 39 CVSS 6.5 EPSS 0.25%
Android AocAudioCodec Out-of-Bounds Denial of Service (writeAocCommand)
- CVE-2026-9258 MittelScore 39 CVSS 6.5 EPSS 0.27%
Canon EOS Network Setting Tool: Fehlerhafte Prüfung von SSH-Hostschlüsseln
- CVE-2026-9259 MittelScore 39 CVSS 6.5 EPSS 0.19%
Canon EOS Network Setting Tool: Unzureichende Server-Zertifikatsprüfung
- CVE-2026-9262 MittelScore 39 CVSS 6.5 EPSS 0.26%
Canon EOS Network Setting Tool – Unsicheres Protokoll als Standard-FTP-Konfiguration
- CVE-2026-9260 MittelScore 37 CVSS 6.2 EPSS 0.23%
Canon EOS Network Setting Tool: Fest codierte kryptografische Schlüssel (≤ 1.5.0)
- CVE-2026-0165 MittelScore 34 CVSS 5.7 EPSS 0.17%
RTCP-Paket-Decoder: Out-of-bounds-Read durch fehlende Bereichsprüfung
- CVE-2026-1764 MittelScore 34 CVSS 5.6 EPSS 0.21%
GNOME localsearch: Fehlende Bereichsprüfung im MP3-Extractor
- CVE-2026-1766 MittelScore 34 CVSS 5.6 EPSS 0.16%
GNOME localsearch – Heap-Buffer-Overflow im MP3-Extractor
- CVE-2026-1767 MittelScore 34 CVSS 5.6 EPSS 0.25%
GNOME localsearch: Heap-Buffer-Overflow im MP3-Extractor
- CVE-2026-47927 MittelScore 33 CVSS 5.5 EPSS 0.17%
Adobe DNG SDK: Out-of-bounds-Read ermöglicht Offenlegung von Speicherinhalten
- CVE-2026-47934 MittelScore 33 CVSS 5.5 EPSS 0.17%
Adobe DNG SDK: Out-of-bounds-Read mit möglicher Preisgabe von Speicherinhalten
- CVE-2026-47963 MittelScore 33 CVSS 5.5 EPSS 0.17%
Adobe DNG SDK: Informationsoffenlegung durch Out-of-bounds-Read
- CVE-2026-46448 MittelScore 32 CVSS 5.4 EPSS 0.27%
OpenStack Nova: Server-Create-API entfernt bestimmte Hint-Daten nicht
- CVE-2026-0140 MittelScore 26 CVSS 4.3 EPSS 0.18%
Out-of-Bounds-Read in RtpPacket::decodePacket
- CVE-2026-0141 MittelScore 26 CVSS 4.3 EPSS 0.20%
Android: OOB-Lesezugriff in decodeAppPacket (RtcpAppPacket)
- CVE-2026-0155 MittelScore 26 CVSS 4.3 EPSS 0.17%
Android: Out-of-bounds-Read in ImsMediaBitReader::ReadByteBuffer
- CVE-2026-0157 MittelScore 26 CVSS 4.3 EPSS 0.17%
Android/ChromeOS – Out-of-Bounds-Read in RtcpHeader::decodeRtcpHeader
- CVE-2026-0129 NiedrigScore 21 CVSS 3.5 EPSS 0.17%
CVE-2026-0129 – Fehlende Bounds-Prüfung in RtcpByePacket (Android/Chrome)
- CVE-2026-0130 NiedrigScore 21 CVSS 3.5 EPSS 0.17%
Out-of-Bounds-Read in RtcpChunk::decodeRtcpChunk
- CVE-2026-0134 NiedrigScore 20 CVSS 3.3 EPSS 0.07%
Android Recovery: Datenpersistenz nach Werksreset (Informationspreisgabe)
- CVE-2026-0142 NiedrigScore 20 CVSS 3.3 EPSS 0.07%
Android: Out-of-Bounds-Read in iavb_parse_key_data (avb_rsa.c)
- CVE-2026-0145 NiedrigScore 20 CVSS 3.3 EPSS 0.07%
Android keymint: Berechtigungsumgehung durch Logikfehler
- CVE-2026-0158 NiedrigScore 20 CVSS 3.3 EPSS 0.06%
Android: Unbefugter Fotozugriff in der Kamera-Komponente
- CVE-2026-20262 Mittel Aktiv ausgenutztScore 100 CVSS 6.5 EPSS 7.68%
Cisco Catalyst SD-WAN Manager: Beliebiges Schreiben/Überschreiben von Dateien
- CVE-2026-54420 Hoch Aktiv ausgenutztScore 100 CVSS 8.5 EPSS 1.26%
LiteSpeed cPanel-Plugin: Symlink-Following-Schwachstelle unter UNIX
- CVE-2026-40772 KritischScore 60 CVSS 10 EPSS 0.35%
GeekyBot <= 1.2.2 – Unauthentifizierter Arbitrary File Upload
- CVE-2026-48836 KritischScore 60 CVSS 10 EPSS 0.57%
Easy Invoice – Unauthenticated Remote Code Execution
- CVE-2026-52704 KritischScore 60 CVSS 10 EPSS 0.31%
WooCommerce PDF Invoice Builder – Code Injection (Remote Code Inclusion)
- CVE-2018-25436 KritischScore 59 CVSS 9.8 EPSS 0.66%
WordPress-Plugin Baggage Freight Shipping Australia 0.1.0 – unbeschränkter Datei-Upload
- CVE-2026-27053 KritischScore 59 CVSS 9.8 EPSS 0.39%
Broadcast Live Video vor 7.1.3: Unauthentifizierte PHP Object Injection
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.