Live-Feed 1649 aktiv ausgenutzt
Priorisierte Schwachstellen
Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.
24291
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
295
Ransomware-Bezug
4903
Kritisch
Zeige 4851 bis 4900 von 24291
- CVE-2026-0144 MittelScore 39 CVSS 6.5 EPSS 0.25%
Android AocAudioCodec Out-of-Bounds Denial of Service (writeAocCommand)
- CVE-2026-9258 MittelScore 39 CVSS 6.5 EPSS 0.27%
Canon EOS Network Setting Tool: Fehlerhafte Prüfung von SSH-Hostschlüsseln
- CVE-2026-9259 MittelScore 39 CVSS 6.5 EPSS 0.19%
Canon EOS Network Setting Tool: Unzureichende Server-Zertifikatsprüfung
- CVE-2026-9262 MittelScore 39 CVSS 6.5 EPSS 0.26%
Canon EOS Network Setting Tool – Unsicheres Protokoll als Standard-FTP-Konfiguration
- CVE-2026-9260 MittelScore 37 CVSS 6.2 EPSS 0.23%
Canon EOS Network Setting Tool: Fest codierte kryptografische Schlüssel (≤ 1.5.0)
- CVE-2026-0165 MittelScore 34 CVSS 5.7 EPSS 0.17%
RTCP-Paket-Decoder: Out-of-bounds-Read durch fehlende Bereichsprüfung
- CVE-2026-1764 MittelScore 34 CVSS 5.6 EPSS 0.21%
GNOME localsearch: Fehlende Bereichsprüfung im MP3-Extractor
- CVE-2026-1766 MittelScore 34 CVSS 5.6 EPSS 0.16%
GNOME localsearch – Heap-Buffer-Overflow im MP3-Extractor
- CVE-2026-1767 MittelScore 34 CVSS 5.6 EPSS 0.25%
GNOME localsearch: Heap-Buffer-Overflow im MP3-Extractor
- CVE-2026-47927 MittelScore 33 CVSS 5.5 EPSS 0.17%
Adobe DNG SDK: Out-of-bounds-Read ermöglicht Offenlegung von Speicherinhalten
- CVE-2026-47934 MittelScore 33 CVSS 5.5 EPSS 0.17%
Adobe DNG SDK: Out-of-bounds-Read mit möglicher Preisgabe von Speicherinhalten
- CVE-2026-47963 MittelScore 33 CVSS 5.5 EPSS 0.17%
Adobe DNG SDK: Informationsoffenlegung durch Out-of-bounds-Read
- CVE-2026-46448 MittelScore 32 CVSS 5.4 EPSS 0.27%
OpenStack Nova: Server-Create-API entfernt bestimmte Hint-Daten nicht
- CVE-2026-0140 MittelScore 26 CVSS 4.3 EPSS 0.18%
Out-of-Bounds-Read in RtpPacket::decodePacket
- CVE-2026-0141 MittelScore 26 CVSS 4.3 EPSS 0.20%
Android: OOB-Lesezugriff in decodeAppPacket (RtcpAppPacket)
- CVE-2026-0155 MittelScore 26 CVSS 4.3 EPSS 0.17%
Android: Out-of-bounds-Read in ImsMediaBitReader::ReadByteBuffer
- CVE-2026-0157 MittelScore 26 CVSS 4.3 EPSS 0.17%
Android/ChromeOS – Out-of-Bounds-Read in RtcpHeader::decodeRtcpHeader
- CVE-2026-0129 NiedrigScore 21 CVSS 3.5 EPSS 0.17%
CVE-2026-0129 – Fehlende Bounds-Prüfung in RtcpByePacket (Android/Chrome)
- CVE-2026-0130 NiedrigScore 21 CVSS 3.5 EPSS 0.17%
Out-of-Bounds-Read in RtcpChunk::decodeRtcpChunk
- CVE-2026-0134 NiedrigScore 20 CVSS 3.3 EPSS 0.07%
Android Recovery: Datenpersistenz nach Werksreset (Informationspreisgabe)
- CVE-2026-0142 NiedrigScore 20 CVSS 3.3 EPSS 0.07%
Android: Out-of-Bounds-Read in iavb_parse_key_data (avb_rsa.c)
- CVE-2026-0145 NiedrigScore 20 CVSS 3.3 EPSS 0.07%
Android keymint: Berechtigungsumgehung durch Logikfehler
- CVE-2026-0158 NiedrigScore 20 CVSS 3.3 EPSS 0.06%
Android: Unbefugter Fotozugriff in der Kamera-Komponente
- CVE-2026-20262 Mittel Aktiv ausgenutztScore 100 CVSS 6.5 EPSS 7.68%
Cisco Catalyst SD-WAN Manager: Beliebiges Schreiben/Überschreiben von Dateien
- CVE-2026-54420 Hoch Aktiv ausgenutztScore 100 CVSS 8.5 EPSS 1.26%
LiteSpeed cPanel-Plugin: Symlink-Following-Schwachstelle unter UNIX
- CVE-2026-40772 KritischScore 60 CVSS 10 EPSS 0.35%
GeekyBot <= 1.2.2 – Unauthentifizierter Arbitrary File Upload
- CVE-2026-48836 KritischScore 60 CVSS 10 EPSS 0.57%
Easy Invoice – Unauthenticated Remote Code Execution
- CVE-2026-52704 KritischScore 60 CVSS 10 EPSS 0.31%
WooCommerce PDF Invoice Builder – Code Injection (Remote Code Inclusion)
- CVE-2018-25436 KritischScore 59 CVSS 9.8 EPSS 0.66%
WordPress-Plugin Baggage Freight Shipping Australia 0.1.0 – unbeschränkter Datei-Upload
- CVE-2026-27053 KritischScore 59 CVSS 9.8 EPSS 0.39%
Broadcast Live Video vor 7.1.3: Unauthentifizierte PHP Object Injection
- CVE-2026-30120 KritischScore 59 CVSS 9.8 EPSS 0.81%
Remotion: Remote Code Execution
- CVE-2026-34901 KritischScore 59 CVSS 9.8 EPSS 0.32%
iControlWP bis 5.5.3: Rechteausweitung ohne Authentifizierung
- CVE-2026-36537 KritischScore 59 CVSS 9.8 EPSS 0.51%
ThingsBoard v4.3.0.1: Authentifizierungsumgehung beim OAuth-Code-Austausch
- CVE-2026-38060 KritischScore 59 CVSS 9.8 EPSS 1.05%
Tenda 5G03: Command Injection über den pin-Parameter
- CVE-2026-38061 KritischScore 59 CVSS 9.8 EPSS 1.05%
Tenda 5G03: Command Injection in action_set_volume
- CVE-2026-38062 KritischScore 59 CVSS 9.8 EPSS 1.05%
Tenda 5G03: Command-Injection über den Parameter ratMode
- CVE-2026-38063 KritischScore 59 CVSS 9.8 EPSS 1.05%
Tenda 5G03: Command Injection über den Parameter ia
- CVE-2026-38064 KritischScore 59 CVSS 9.8 EPSS 1.05%
Tenda 5G03: Command Injection über den Parameter dialNumber
- CVE-2026-38065 KritischScore 59 CVSS 9.8 EPSS 1.34%
Tenda 5G03: Command Injection über den Parameter ims_apn
- CVE-2026-38329 KritischScore 59 CVSS 9.8 EPSS 0.63%
Bludit CMS vor 3.18.4: Remote Code Execution über das API-Plugin
- CVE-2026-38812 KritischScore 59 CVSS 9.8 EPSS 0.39%
RuoYi 4.8.2: SQL-Injection über den Endpunkt /tool/gen/createTable
- CVE-2026-39006 KritischScore 59 CVSS 9.8 EPSS 0.52%
SNMP4J-Agent: Code-Ausführung über snmp4jCfgStoragePath
- CVE-2026-39196 KritischScore 59 CVSS 9.8 EPSS 0.32%
Datadog Vector v0.54.0: SQL-Injection in KeyPartitioner::partition
- CVE-2026-39583 KritischScore 59 CVSS 9.8 EPSS 0.36%
Datalogics Ecommerce Delivery: Unauthentifizierte Rechteausweitung
- CVE-2026-39591 KritischScore 59 CVSS 9.9 EPSS 0.46%
WP-BusinessDirectory: beliebiger Datei-Upload durch Abonnenten (<= 4.0.0)
- CVE-2026-48114 KritischScore 59 CVSS 9.8 EPSS 0.37%
Metacat: Nicht authentifizierte SQL-Injection im /harvesterRegistration-Endpunkt
- CVE-2026-49085 KritischScore 59 CVSS 9.8 EPSS 0.48%
WP Insightly: Nicht authentifizierte PHP Object Injection (<= 1.1.4)
- CVE-2026-49104 KritischScore 59 CVSS 9.8 EPSS 0.48%
Integration for Keap/Infusionsoft und Formular-Plugins: Unauthentifizierte PHP Object Injection
- CVE-2026-49105 KritischScore 59 CVSS 9.8 EPSS 0.48%
WP Zendesk für Contact Form 7, WPForms, Elementor, Formidable und Ninja Forms: PHP Object Injection
- CVE-2026-49106 KritischScore 59 CVSS 9.8 EPSS 0.38%
Integration for Contact Form 7 and Constant Contact: unauthentifizierte PHP Object Injection
Diesem Feed folgen, kostenlos
Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.