Live-Feed 1649 aktiv ausgenutzt

Priorisierte Schwachstellen

Aktiv ausgenutzte und priorisierte CVEs, stündlich aktualisiert und nach NIS2/CRA-Relevanz gefiltert. Standardmässig die neuesten zuerst – umschaltbar nach Priorität (KEV, Severity, EPSS). Kostenlos & offen für alle.

24343
CVEs gesamt
1649
Aktiv ausgenutzt (KEV)
295
Ransomware-Bezug
4903
Kritisch

Zeige 4901 bis 4950 von 24343

  1. CVE-2026-9259 Mittel
    Score 39 CVSS 6.5 EPSS 0.19%

    Canon EOS Network Setting Tool: Unzureichende Server-Zertifikatsprüfung

  2. CVE-2026-9262 Mittel
    Score 39 CVSS 6.5 EPSS 0.26%

    Canon EOS Network Setting Tool – Unsicheres Protokoll als Standard-FTP-Konfiguration

  3. CVE-2026-9260 Mittel
    Score 37 CVSS 6.2 EPSS 0.23%

    Canon EOS Network Setting Tool: Fest codierte kryptografische Schlüssel (≤ 1.5.0)

  4. CVE-2026-0165 Mittel
    Score 34 CVSS 5.7 EPSS 0.17%

    RTCP-Paket-Decoder: Out-of-bounds-Read durch fehlende Bereichsprüfung

  5. CVE-2026-1764 Mittel
    Score 34 CVSS 5.6 EPSS 0.21%

    GNOME localsearch: Fehlende Bereichsprüfung im MP3-Extractor

  6. CVE-2026-1766 Mittel
    Score 34 CVSS 5.6 EPSS 0.16%

    GNOME localsearch – Heap-Buffer-Overflow im MP3-Extractor

  7. CVE-2026-1767 Mittel
    Score 34 CVSS 5.6 EPSS 0.25%

    GNOME localsearch: Heap-Buffer-Overflow im MP3-Extractor

  8. CVE-2026-47927 Mittel
    Score 33 CVSS 5.5 EPSS 0.17%

    Adobe DNG SDK: Out-of-bounds-Read ermöglicht Offenlegung von Speicherinhalten

  9. CVE-2026-47934 Mittel
    Score 33 CVSS 5.5 EPSS 0.17%

    Adobe DNG SDK: Out-of-bounds-Read mit möglicher Preisgabe von Speicherinhalten

  10. CVE-2026-47963 Mittel
    Score 33 CVSS 5.5 EPSS 0.17%

    Adobe DNG SDK: Informationsoffenlegung durch Out-of-bounds-Read

  11. CVE-2026-46448 Mittel
    Score 32 CVSS 5.4 EPSS 0.27%

    OpenStack Nova: Server-Create-API entfernt bestimmte Hint-Daten nicht

  12. CVE-2026-0140 Mittel
    Score 26 CVSS 4.3 EPSS 0.18%

    Out-of-Bounds-Read in RtpPacket::decodePacket

  13. CVE-2026-0141 Mittel
    Score 26 CVSS 4.3 EPSS 0.20%

    Android: OOB-Lesezugriff in decodeAppPacket (RtcpAppPacket)

  14. CVE-2026-0155 Mittel
    Score 26 CVSS 4.3 EPSS 0.17%

    Android: Out-of-bounds-Read in ImsMediaBitReader::ReadByteBuffer

  15. CVE-2026-0157 Mittel
    Score 26 CVSS 4.3 EPSS 0.17%

    Android/ChromeOS – Out-of-Bounds-Read in RtcpHeader::decodeRtcpHeader

  16. CVE-2026-0129 Niedrig
    Score 21 CVSS 3.5 EPSS 0.17%

    CVE-2026-0129 – Fehlende Bounds-Prüfung in RtcpByePacket (Android/Chrome)

  17. CVE-2026-0130 Niedrig
    Score 21 CVSS 3.5 EPSS 0.17%

    Out-of-Bounds-Read in RtcpChunk::decodeRtcpChunk

  18. CVE-2026-0134 Niedrig
    Score 20 CVSS 3.3 EPSS 0.07%

    Android Recovery: Datenpersistenz nach Werksreset (Informationspreisgabe)

  19. CVE-2026-0142 Niedrig
    Score 20 CVSS 3.3 EPSS 0.07%

    Android: Out-of-Bounds-Read in iavb_parse_key_data (avb_rsa.c)

  20. CVE-2026-0145 Niedrig
    Score 20 CVSS 3.3 EPSS 0.07%

    Android keymint: Berechtigungsumgehung durch Logikfehler

  21. CVE-2026-0158 Niedrig
    Score 20 CVSS 3.3 EPSS 0.06%

    Android: Unbefugter Fotozugriff in der Kamera-Komponente

  22. CVE-2026-20262 Mittel Aktiv ausgenutzt
    Score 100 CVSS 6.5 EPSS 7.68%

    Cisco Catalyst SD-WAN Manager: Beliebiges Schreiben/Überschreiben von Dateien

  23. CVE-2026-54420 Hoch Aktiv ausgenutzt
    Score 100 CVSS 8.5 EPSS 1.26%

    LiteSpeed cPanel-Plugin: Symlink-Following-Schwachstelle unter UNIX

  24. CVE-2026-40772 Kritisch
    Score 60 CVSS 10 EPSS 0.35%

    GeekyBot <= 1.2.2 – Unauthentifizierter Arbitrary File Upload

  25. CVE-2026-48836 Kritisch
    Score 60 CVSS 10 EPSS 0.57%

    Easy Invoice – Unauthenticated Remote Code Execution

  26. CVE-2026-52704 Kritisch
    Score 60 CVSS 10 EPSS 0.31%

    WooCommerce PDF Invoice Builder – Code Injection (Remote Code Inclusion)

  27. CVE-2018-25436 Kritisch
    Score 59 CVSS 9.8 EPSS 0.66%

    WordPress-Plugin Baggage Freight Shipping Australia 0.1.0 – unbeschränkter Datei-Upload

  28. CVE-2026-27053 Kritisch
    Score 59 CVSS 9.8 EPSS 0.39%

    Broadcast Live Video vor 7.1.3: Unauthentifizierte PHP Object Injection

  29. CVE-2026-30120 Kritisch
    Score 59 CVSS 9.8 EPSS 0.81%

    Remotion: Remote Code Execution

  30. CVE-2026-34901 Kritisch
    Score 59 CVSS 9.8 EPSS 0.32%

    iControlWP bis 5.5.3: Rechteausweitung ohne Authentifizierung

  31. CVE-2026-36537 Kritisch
    Score 59 CVSS 9.8 EPSS 0.51%

    ThingsBoard v4.3.0.1: Authentifizierungsumgehung beim OAuth-Code-Austausch

  32. CVE-2026-38060 Kritisch
    Score 59 CVSS 9.8 EPSS 1.05%

    Tenda 5G03: Command Injection über den pin-Parameter

  33. CVE-2026-38061 Kritisch
    Score 59 CVSS 9.8 EPSS 1.05%

    Tenda 5G03: Command Injection in action_set_volume

  34. CVE-2026-38062 Kritisch
    Score 59 CVSS 9.8 EPSS 1.05%

    Tenda 5G03: Command-Injection über den Parameter ratMode

  35. CVE-2026-38063 Kritisch
    Score 59 CVSS 9.8 EPSS 1.05%

    Tenda 5G03: Command Injection über den Parameter ia

  36. CVE-2026-38064 Kritisch
    Score 59 CVSS 9.8 EPSS 1.05%

    Tenda 5G03: Command Injection über den Parameter dialNumber

  37. CVE-2026-38065 Kritisch
    Score 59 CVSS 9.8 EPSS 1.34%

    Tenda 5G03: Command Injection über den Parameter ims_apn

  38. CVE-2026-38329 Kritisch
    Score 59 CVSS 9.8 EPSS 0.63%

    Bludit CMS vor 3.18.4: Remote Code Execution über das API-Plugin

  39. CVE-2026-38812 Kritisch
    Score 59 CVSS 9.8 EPSS 0.39%

    RuoYi 4.8.2: SQL-Injection über den Endpunkt /tool/gen/createTable

  40. CVE-2026-39006 Kritisch
    Score 59 CVSS 9.8 EPSS 0.52%

    SNMP4J-Agent: Code-Ausführung über snmp4jCfgStoragePath

  41. CVE-2026-39196 Kritisch
    Score 59 CVSS 9.8 EPSS 0.32%

    Datadog Vector v0.54.0: SQL-Injection in KeyPartitioner::partition

  42. CVE-2026-39583 Kritisch
    Score 59 CVSS 9.8 EPSS 0.36%

    Datalogics Ecommerce Delivery: Unauthentifizierte Rechteausweitung

  43. CVE-2026-39591 Kritisch
    Score 59 CVSS 9.9 EPSS 0.46%

    WP-BusinessDirectory: beliebiger Datei-Upload durch Abonnenten (<= 4.0.0)

  44. CVE-2026-48114 Kritisch
    Score 59 CVSS 9.8 EPSS 0.37%

    Metacat: Nicht authentifizierte SQL-Injection im /harvesterRegistration-Endpunkt

  45. CVE-2026-49085 Kritisch
    Score 59 CVSS 9.8 EPSS 0.48%

    WP Insightly: Nicht authentifizierte PHP Object Injection (<= 1.1.4)

  46. CVE-2026-49104 Kritisch
    Score 59 CVSS 9.8 EPSS 0.48%

    Integration for Keap/Infusionsoft und Formular-Plugins: Unauthentifizierte PHP Object Injection

  47. CVE-2026-49105 Kritisch
    Score 59 CVSS 9.8 EPSS 0.48%

    WP Zendesk für Contact Form 7, WPForms, Elementor, Formidable und Ninja Forms: PHP Object Injection

  48. CVE-2026-49106 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    Integration for Contact Form 7 and Constant Contact: unauthentifizierte PHP Object Injection

  49. CVE-2026-49109 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    Integration for Salesforce and Contact Form 7: Unauthentifizierte PHP Object Injection

  50. CVE-2026-49763 Kritisch
    Score 59 CVSS 9.8 EPSS 0.38%

    Integration for Contact Form 7 HubSpot: Nicht authentifizierte PHP Object Injection

Diesem Feed folgen, kostenlos

Per RSS sofort nutzbar: global, pro Kategorie oder pro Produkt. E-Mail und Webhook richten wir auf Anfrage ein. Stündlich aktualisiert, frei zugänglich für alle.