Critical Infrastructure Vulnerability Intelligence

Advisories for Industrial Defenders

Compiled, structured vulnerability reports for operational technology and industrial control system security teams.

144
KEV Listed
154
Exploited
11
EPSS-Imminent
585
Total Advisories
Filter by Sector
ChemicalCommercialCommunicationsManufacturingDamsDefense IndustrialEmergency SvcsEnergyFinancial SvcsFood & AgGovernmentHealthcareInfo TechnologyNuclearTransportationWater
Filter by Status
FromToShow
UpdatedAdvisory IDTitleCVSSStatus
2026-09-27CVE-2026-84388Fortinet FortiPAM Chrome Extension All 8.0 and 7.4 Versions Improperly Restricts Rendered UI Layers, Potentially Enabling Clickjacking Attacks Against Users of the PAM Interface9.6 CriticalNew
2026-09-26CVE-2026-80152Lantronix SLC8000, SLC9000, EMG, and SLB Series Set Script Schedule Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root9.1 CriticalNew
2026-09-26CVE-2026-80151Lantronix SLC8000, SLC9000, EMG, and SLB Series Set NFS Download Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root9.1 CriticalNew
2026-09-26CVE-2026-80146Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root9.9 CriticalNew
2026-09-26CVE-2026-67279MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 286.5 MediumKEV
2026-09-25CVE-2026-93616Path Traversal Across Check Point Management and Log Server Infrastructure Missed the September 25th CISA KEV Window; Covered Organizations Are Now Out of Compliance9.8 CriticalKEV
2026-09-25CVE-2026-85046Google Chromium V8's Type Confusion Allows Remote Attackers to Execute Arbitrary Code or Escape the Browser Sandbox via a Crafted Web Page8.8 HighKEV
2026-09-25CVE-2026-81578PaperCut NG/MF's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Perform Administrative Actions Without Logging In; CISA's September 14th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-25CVE-2026-76461Cisco Secure Email Gateway's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Compromise the Email Security Platform9.8 CriticalKEV
2026-09-25CVE-2026-76460Cisco Identity Services Engine's Incorrect Use of Privileged APIs Allows Unauthenticated Remote Attackers to Gain Full Administrative Control; CISA's September 19th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-25CVE-2026-75650Adobe Commerce and Magento's Template Engine Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Server-Side Code on the E-Commerce Platform10.0 CriticalKEV
2026-09-25CVE-2026-98123Linux Kernel SCTP ASCONF-ACK Parameter Walk Loops Indefinitely on an Unpadded Short Parameter Due to SCTP_PAD4 Rounding, Causing a Soft Lockup—New
2026-09-25CVE-2026-98044Linux Kernel BPF Verifier Fails to Reject Legacy Packet Loads from Callback Subprograms, Which Can Model a Failed BPF_LD_ABS as an Implicit Zero Return Causing Incorrect Program Behavior—New
2026-09-25CVE-2026-93815Linux Kernel au1000 Ethernet Driver Calls free_irq While Holding a Spinlock with Interrupts Disabled, Which Can Sleep and Deadlock on Platforms Without Threaded IRQs—New
2026-09-25CVE-2026-93804Linux Kernel mac80211 IBSS Leave Path Flushes Stations and Turns Off the Carrier Without Waiting for In-Flight TX to Complete, Leading to Use-After-Free on Concurrent Packet Transmission—New
2026-09-25CVE-2026-67278MikroTik RouterOS Accepts Malformed RSA/PKCS#1 v1.5 Signatures Across TLS and SSH, and Its Trust Store Includes an e=3 Root CA, Letting a Network Attacker Forge Valid Signatures Without the Private Key9.1 CriticalUpdated
2026-09-25CVE-2026-5430WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 2710.0 CriticalKEV
2026-09-24CVE-2026-9203MarkLogic SSRF Flaw Exposes Cloud Instance Credentials to Low-Privilege Users8.5 HighUpdated
2026-09-24CVE-2026-9195Crafted Links Let Attackers Hijack MarkLogic Administrator Sessions Through Query Console XSS9.3 CriticalUpdated
2026-09-24CVE-2026-9193Low-Privilege Hadoop Role Escalates to Full Control of MarkLogic's Security Database9.9 CriticalUpdated
2026-09-24CVE-2026-9192Unauthenticated Attackers Can Impersonate Any MarkLogic User Through ODBC Authentication Bypass9.8 CriticalUpdated
2026-09-24CVE-2026-9190HTTP Request Smuggling Bypasses MarkLogic Authentication and Hijacks Sessions9.1 CriticalUpdated
2026-09-24CVE-2026-9089ConnectWise Automate agent trusts unverified plugin and update downloads, fixed in 2026.58.8 HighUpdated
2026-09-24CVE-2026-8709MarkLogic's REST document-patch API lets low-privileged users seize administrator control9.9 CriticalUpdated
2026-09-24CVE-2026-7557Unauthenticated attackers impersonate any MarkLogic administrator through a SAML signature flaw9.1 CriticalUpdated
2026-09-24CVE-2026-7329MarkLogic's SQL, SPARQL, and Optic query interfaces open a path from low-privileged access to full admin9.9 CriticalUpdated
2026-09-24CVE-2026-7327MarkLogic's document-processing pipeline lets an administrative REST role escalate further, exposing server-side data8.1 HighUpdated
2026-09-24CVE-2026-7326A CSRF flaw in MarkLogic's Admin UI lets attackers hijack lured administrators for configuration changes7.5 HighUpdated
2026-09-24CVE-2026-71474Red Hat insights-client logs a long-lived OpenShift pull-secret token that local pod-log access can expose7.1 HighUpdated
2026-09-24CVE-2026-68981Apache NiFi's gzip request handling bypasses size limits, opening a memory-exhaustion path, fixed in 2.11.07.5 HighUpdated
2026-09-24CVE-2026-68980Apache NiFi's asset-deletion API skips ownership checks across Parameter Contexts, fixed in 2.11.09.1 CriticalUpdated
2026-09-24CVE-2026-68979Missing authorization on Apache NiFi's Parameter Context updates can trigger code execution, fixed in 2.11.09.8 CriticalUpdated
2026-09-24CVE-2026-68060Pre-authentication attackers can exhaust memory in Apache Qpid Broker-J via oversized type handling, fixed in 10.1.07.5 HighUpdated
2026-09-24CVE-2026-67589Apache Qpid ProtonJ2 lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.2.07.5 HighUpdated
2026-09-24CVE-2026-67588Unbounded symbol caching in Apache Qpid ProtonJ2 lets pre-authentication attackers exhaust memory, fixed in 1.2.07.5 HighUpdated
2026-09-24CVE-2026-67551Apache Qpid Proton-Dotnet lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.1.07.5 HighUpdated
2026-09-24CVE-2026-67465Unbounded symbol caching in Apache Qpid Proton-Dotnet lets pre-authentication attackers exhaust memory, fixed in 1.1.07.5 HighUpdated
2026-09-24CVE-2026-66756A critical alternate-path flaw in Apache Tika precedes the 4.0.0-beta-1 fix, CVSS 9.89.8 CriticalUpdated
2026-09-24CVE-2026-66755Apache Tika's ISA-Tab parser lets crafted filenames leak arbitrary file contents into extracted text, fixed in 3.3.27.5 HighUpdated
2026-09-24CVE-2026-66273Apache Qpid Proton-J lets pre-authentication attackers trigger oversized memory allocations, fixed in 0.35.07.5 HighUpdated
2026-09-24CVE-2026-66257Unbounded symbol caching in Apache Qpid Proton-J lets pre-authentication attackers exhaust memory, fixed in 0.35.07.5 HighUpdated
2026-09-24CVE-2026-66015A JFrog Platform privilege-escalation flaw grants temporary admin access under admin-provisioned accounts7.2 HighNew
2026-09-24CVE-2026-66014An authentication weakness in JFrog Artifactory's internal request processing lets attackers escalate access8.8 HighNew
2026-09-24CVE-2026-65922Limited-access JFrog Artifactory users can write to restricted internal metadata under specific conditions7.1 HighNew
2026-09-24CVE-2026-65617A deserialization flaw in JFrog Artifactory package handling lets low-privileged users compromise confidentiality, integrity, and availability8.8 HighNew
2026-09-24CVE-2026-65616Flawed refresh-token signature validation lets non-admin JFrog users obtain a signed administrator token8.8 HighNew
2026-09-24CVE-2026-62391An incomplete fix for a prior Kyuubi flaw still lets clients bypass the local-directory allowlist via Spark config aliases, fixed in 1.12.08.1 HighUpdated
2026-09-24CVE-2026-61372A path traversal vulnerability in Apache Jena Fuseki is fixed in 6.2.07.5 HighUpdated
2026-09-24CVE-2026-6066ConnectWise Automate's Solution Center allowed unencrypted client-server traffic open to interception, fixed in 2026.47.1 HighUpdated
2026-09-24CVE-2026-60413An information-exposure flaw in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.87.8 HighUpdated
2026-09-24CVE-2026-60412Insecure deserialization in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.87.8 HighUpdated
2026-09-24CVE-2026-60393Unauthenticated network attackers can reach all Oracle Hyperion Infrastructure Technology data over HTTP, CVSS 7.57.5 HighUpdated
2026-09-24CVE-2026-60392Insecure deserialization in Oracle's Outside In PDF Export SDK lets a logged-in attacker take full control, CVSS 7.87.8 HighUpdated
2026-09-24CVE-2026-60391Unauthenticated network attackers can reach all Oracle Hyperion Financial Reporting data over HTTP, CVSS 7.57.5 HighUpdated
2026-09-24CVE-2026-6023Tampered RadFilter state in Telerik UI for ASP.NET AJAX enables server-side remote code execution8.1 HighUpdated
2026-09-24CVE-2026-6022Telerik UI for ASP.NET AJAX chunked upload flaw lets attackers bypass size limits and exhaust disk space7.5 HighUpdated
2026-09-24CVE-2026-5483Red Hat OpenShift AI's odh-dashboard leaks Kubernetes service account tokens through a NodeJS endpoint8.5 HighNew
2026-09-24CVE-2026-54100Red Hat's Windows Machine Config Operator skips SSH host-key checks, letting adjacent attackers capture node bootstrap credentials8.3 HighUpdated
2026-09-24CVE-2026-54099A compromised Windows node can forge a cluster-administrator certificate through WMCO's CSR auto-approver, CVSS 8.88.8 HighUpdated
2026-09-24CVE-2026-52680Path traversal in Apache Kyuubi's REST batch upload lets remote attackers write files outside the intended directory, fixed in 1.12.09.8 CriticalUpdated
2026-09-24CVE-2026-5174Improper input validation in Progress MOVEit Automation opens a path to privilege escalation7.7 HighUpdated
2026-09-24CVE-2026-47629Improper input validation in NVIDIA Triton Inference Server on Linux can trigger denial of service7.5 HighUpdated
2026-09-24CVE-2026-47628Unbounded resource allocation in NVIDIA Triton Inference Server on Linux opens a denial-of-service path7.5 HighUpdated
2026-09-24CVE-2026-47627A critical path-traversal flaw in NVIDIA Triton Inference Server on Linux enables denial of service, CVSS 9.89.8 CriticalUpdated
2026-09-24CVE-2026-4740Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation8.2 HighUpdated
2026-09-24CVE-2026-42017An event-handling flaw in JFrog Artifactory exposes privileged authorization material to lower-privileged users8.8 HighNew
2026-09-24CVE-2026-41724Stored XSS in VMware Cloud Foundation Operations lets privileged users trigger admin actions via injected scripts8.0 HighUpdated
2026-09-24CVE-2026-41723A stored XSS spanning VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts8.0 HighUpdated
2026-09-24CVE-2026-41722Another stored XSS across VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts8.0 HighUpdated
2026-09-24CVE-2026-41702A TOCTOU flaw in a VMware Fusion SETUID binary lets local non-admin users escalate to root7.8 HighUpdated
2026-09-24CVE-2026-4048Authenticated Command Injection in Progress LoadMaster UI Enables Remote Code Execution8.4 HighEPSS-Imminent
2026-09-24CVE-2026-40141A critical query-injection flaw in BeyondTrust Remote Support lets low-privileged users reach unauthorized resources, CVSS 9.99.9 CriticalUpdated
2026-09-24CVE-2026-40140Unauthenticated attackers can crash BeyondTrust Remote Support appliances via a network-communication flaw7.5 HighUpdated
2026-09-24CVE-2026-40139Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access9.8 CriticalUpdated
2026-09-24CVE-2026-40138BeyondTrust Privileged Remote Access Shares Pre-Authentication Bypass Flaw with Remote Support8.1 HighUpdated
2026-09-24CVE-2026-39815SQL Injection in Fortinet FortiDDoS-F 7.2 May Allow Unauthorized Data Access8.8 HighUpdated
2026-09-24CVE-2026-39304Apache ActiveMQ NIO SSL Transports Vulnerable to Denial-of-Service via Memory Exhaustion7.5 HighUpdated
2026-09-24CVE-2026-3692Low-Privilege OS Command Injection in Progress Flowmon Reporting Component8.8 HighUpdated
2026-09-24CVE-2026-35554Race Condition in Apache Kafka Producer Can Silently Deliver Messages to Wrong Topics8.7 HighUpdated
2026-09-24CVE-2026-3519Progress LoadMaster API Exposes Authenticated Command Injection for VS Administration Role8.4 HighEPSS-Imminent
2026-09-24CVE-2026-34487Apache Tomcat Cloud Clustering Component Logs Kubernetes Credentials in Plain Text7.5 HighUpdated
2026-09-24CVE-2026-34483Improper Output Encoding in Apache Tomcat JsonAccessLogValve Enables Log Injection7.5 HighUpdated
2026-09-24CVE-2026-34478Apache Log4j RFC 5424 Layout Vulnerable to Log Injection in Versions 2.21 through 2.257.5 HighUpdated
2026-09-24CVE-2026-34020Apache OpenMeetings REST Login Exposes Credentials in URL Query String7.5 HighUpdated
2026-09-24CVE-2026-33266Apache OpenMeetings Uses Default Hard-Coded Encryption Key for Remember-Me Cookies7.5 HighUpdated
2026-09-24CVE-2026-33105Critical Authorization Bypass in Microsoft Azure Kubernetes Service Allows Network Privilege Escalation10.0 CriticalUpdated
2026-09-24CVE-2026-32590Unsafe Deserialization in Red Hat Quay Resumable Upload Handling7.1 HighUpdated
2026-09-24CVE-2026-32200Use-After-Free in Microsoft PowerPoint Enables Local Code Execution7.8 HighUpdated
2026-09-24CVE-2026-32199Use-After-Free in Microsoft Office Excel Enables Local Code Execution7.8 HighUpdated
2026-09-24CVE-2026-32198Microsoft Office Excel Use-After-Free Lets Local Attacker Execute Code7.8 HighUpdated
2026-09-24CVE-2026-32197Local Code Execution via Use-After-Free in Microsoft Office Excel7.8 HighUpdated
2026-09-24CVE-2026-32190Use-After-Free in Microsoft Office Enables Local Code Execution8.4 HighUpdated
2026-09-24CVE-2026-32189Microsoft Office Excel Carries Additional Use-After-Free Code Execution Risk7.8 HighUpdated
2026-09-24CVE-2026-32188Out-of-Bounds Read in Microsoft Office Excel Discloses Information to Local Attackers7.1 HighUpdated
2026-09-24CVE-2026-32186Critical SSRF in Microsoft Bing Enables Network-Based Privilege Escalation10.0 CriticalUpdated
2026-09-24CVE-2026-32184Deserialization Flaw in Microsoft HPC Pack Allows Authorized User to Escalate Privileges7.8 HighUpdated
2026-09-24CVE-2026-32153Use-After-Free in Windows Speech Component Allows Local Privilege Escalation7.8 HighUpdated
2026-09-24CVE-2026-32091Race Condition in Microsoft Brokering File System Allows Unauthorized Privilege Escalation8.4 HighUpdated
2026-09-24CVE-2026-29145Apache Tomcat CLIENT_CERT Authentication Bypass When Soft Fail Is Disabled9.1 CriticalUpdated
2026-09-24CVE-2026-29129Apache Tomcat Fails to Preserve Configured Cipher Preference Order7.5 HighUpdated
2026-09-24CVE-2026-28814Apache JSPWiki Renders Wiki Markup Without Authentication, Exposing Sensitive Data7.5 HighUpdated
2026-09-24CVE-2026-28813JSON Hijacking in Apache JSPWiki Enables Cross-Site Request Forgery8.8 HighUpdated
2026-09-24CVE-2026-28812Apache JSPWiki UserManager Spoofing Flaw Allows Attackers to Escalate Privileges9.8 CriticalUpdated
2026-09-24CVE-2026-28811Apache JSPWiki Leaks Internal Information via Debug Messages7.5 HighUpdated
2026-09-24CVE-2026-27914Improper Access Control in Microsoft Management Console Allows Local Privilege Escalation7.8 HighUpdated
2026-09-24CVE-2026-27909Use-After-Free in Windows Search Component Allows Authorized Attacker to Escalate Privileges7.8 HighUpdated
2026-09-24CVE-2026-27314Apache Cassandra 5.0 CREATE Permission Allows Privilege Escalation in mTLS Environments8.8 HighUpdated
2026-09-24CVE-2026-26181Use-After-Free in Microsoft Brokering File System Lets Authorized User Escalate Privileges7.8 HighUpdated
2026-09-24CVE-2026-26170Input Validation Flaw in Microsoft PowerShell Allows Local Privilege Escalation7.8 HighUpdated
2026-09-24CVE-2026-26149Control Sequence Injection in Microsoft Power Apps Enables Network-Based Spoofing9.0 CriticalUpdated
2026-09-24CVE-2026-26143Improper Input Validation in Microsoft PowerShell Allows Unauthorized Security Feature Bypass7.8 HighNew
2026-09-24CVE-2026-24880Apache Tomcat Chunk Extension Parsing Allows HTTP Request Smuggling7.5 HighUpdated
2026-09-24CVE-2026-24222NVIDIA NeMoClaw Sandbox Initialization Exposes System Information to Remote Attackers8.6 HighUpdated
2026-09-24CVE-2026-24217Path Traversal in NVIDIA BioNeMo Core Allows Malicious File to Escape Sandbox8.8 HighUpdated
2026-09-24CVE-2026-24216Deserialization of Untrusted Data in NVIDIA BioNeMo Enables Code Execution7.8 HighUpdated
2026-09-24CVE-2026-24214Integer Overflow in NVIDIA Triton Inference Server DALI Backend8.0 HighUpdated
2026-09-24CVE-2026-24213Out-of-Bounds Read in NVIDIA Triton Inference Server DALI Backend8.0 HighUpdated
2026-09-24CVE-2026-24210Integer Overflow in NVIDIA Triton Inference Server Allows Code Execution or Denial of Service7.5 HighUpdated
2026-09-24CVE-2026-24209Path Traversal Vulnerability in NVIDIA Triton Inference Server7.5 HighUpdated
2026-09-24CVE-2026-24207Critical Authentication Bypass in NVIDIA Triton Inference Server9.8 CriticalUpdated
2026-09-24CVE-2026-24206NVIDIA Triton Inference Server Authentication Bypass via Alternate Path Scores 7.37.3 HighUpdated
2026-09-24CVE-2026-24188NVIDIA TensorRT Out-of-Bounds Write Scores 8.28.2 HighUpdated
2026-09-24CVE-2026-24186NVIDIA NVFlare Deserialization of Untrusted Data Scores 8.88.8 HighUpdated
2026-09-24CVE-2026-24184NVIDIA Cumulus Linux Buffer Overflow Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-24183NVIDIA Cumulus Linux Excessive-Privilege Execution Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-24178Critical NVIDIA NVFlare Authorization Bypass via User-Controlled Key Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-24175NVIDIA Triton Inference Server Uncaught Exception Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-24174NVIDIA Triton Inference Server Numeric Type Conversion Error Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-24173NVIDIA Triton Inference Server Integer Overflow Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-24163NVIDIA TensorRT-LLM Deserialization Flaw Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-24156NVIDIA Data Loading Library Deserialization Vulnerability Scores 7.37.3 HighUpdated
2026-09-24CVE-2026-24146NVIDIA Triton Inference Server Oversized Allocation Request Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-23708Fortinet FortiSOAR Authentication Flaw Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-23657Microsoft Office LTSC Use-After-Free Vulnerability Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23429Linux Kernel IOMMU SVA Use-After-Free in Unbind Path Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23428Critical Linux Kernel ksmbd Use-After-Free in Compound Request Handling Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-23427Critical Linux Kernel ksmbd Use-After-Free in Durable Handle Replay Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-23425Linux Kernel KVM arm64 ID Register Initialization Flaw Scores 8.88.8 HighUpdated
2026-09-24CVE-2026-23424Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.17.1 HighUpdated
2026-09-24CVE-2026-23422Linux Kernel dpaa2-switch Out-of-Bounds Write from Malformed Interrupt Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23415Linux Kernel Futex Use-After-Free between Key Lookup and VMA Policy Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23414Linux Kernel TLS Memory Leak in Async Decrypt Wait Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-23413Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23412Linux Kernel Netfilter BPF Use-After-Free in Hook Memory Release Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23411Linux Kernel AppArmor Race Condition Frees i_private Data Early Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23410Linux Kernel AppArmor Race on Rawdata Dereference Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23408Linux Kernel AppArmor Double Free of Namespace Name Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23407Linux Kernel AppArmor Out-of-Bounds Read in DFA Verification Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-22828Fortinet FortiManager and FortiAnalyzer Cloud Heap Overflow Scores 8.18.1 HighUpdated
2026-09-24CVE-2026-22619Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-22016Oracle Java SE JAXP Component Exposes Sensitive Information, Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-22011Oracle Applications DBA ADPatch Access Control Weakness Scores 7.67.6 HighUpdated
2026-09-24CVE-2026-22010Oracle Financial Services Infrastructure Platform Access Control Flaw Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-21997Oracle Life Sciences Empirica Signal Access Control Weakness Scores 8.58.5 HighUpdated
2026-09-24CVE-2026-21662Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-20160Critical Cisco Smart Software Manager On-Prem Resource Exposure Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-20155Cisco Evolved Programmable Network Manager Missing Authorization Scores 8.08.0 HighUpdated
2026-09-24CVE-2026-20151Cisco Smart Software Manager On-Prem Leaks Sensitive Data in Transmitted Requests7.3 HighUpdated
2026-09-24CVE-2026-20094Cisco UCS Command Injection Scores 8.88.8 HighUpdated
2026-09-24CVE-2026-18381Red Hat Cost Management Metrics Operator SSRF via Crafted Custom Resource Scores 7.67.6 HighUpdated
2026-09-24CVE-2026-18378Red Hat Cost Management Metrics Operator SSRF via Arbitrary Upload URL Scores 7.67.6 HighUpdated
2026-09-24CVE-2026-17894Google Chrome on Linux Use-After-Free in Views via Crafted HTML Scores 8.88.8 HighNew
2026-09-24CVE-2026-17877Google Chrome on Linux Chromoting Flaw Enables Local Privilege Escalation, Scores 8.48.4 HighNew
2026-09-24CVE-2026-17744Google Chrome on Linux File Input Flaw Exposes Potential Sandbox Escape, Scores 7.17.1 HighNew
2026-09-24CVE-2026-16443Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.47.4 HighUpdated
2026-09-24CVE-2026-0288Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 7.57.5 HighNew
2026-09-24CVE-2026-0273Palo Alto Networks PAN-OS OS Command Injection Scores 7.27.2 HighNew
2026-09-24CVE-2026-0272Palo Alto Networks PAN-OS Missing Authorization Scores 7.27.2 HighNew
2026-09-24CVE-2026-0271Palo Alto Networks Prisma Access Agent Permission Misconfiguration Scores 7.87.8 HighNew
2026-09-24CVE-2026-0270Palo Alto Networks Cortex XSOAR Path Traversal Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-0265Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.18.1 HighUpdated
2026-09-24CVE-2026-0264Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-0263Critical Palo Alto Networks PAN-OS Out-of-Bounds Write Scores 9.89.8 CriticalNew
2026-09-24CVE-2026-0262Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE18087.5 HighUpdated
2026-09-24CVE-2026-0261Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.27.2 HighUpdated
2026-09-24CVE-2026-0259Palo Alto Networks PAN-OS External File Path Control Scores 8.88.8 HighNew
2026-09-24CVE-2026-0258Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.19.1 CriticalUpdated
2026-09-24CVE-2026-0251Palo Alto Networks GlobalProtect Untrusted Search Path Scores 7.87.8 HighNew
2026-09-24CVE-2026-0250Palo Alto Networks GlobalProtect Out-of-Bounds Write Scores 8.18.1 HighNew
2026-09-24CVE-2026-0246Palo Alto Networks Prisma Access Agent Missing Authorization Scores 7.87.8 HighNew
2026-09-24CVE-2026-0244Palo Alto Networks Prisma SD-WAN Certificate Validation Flaw Scores 8.18.1 HighUpdated
2026-09-24CVE-2026-0237Palo Alto Networks Prisma Browser Alternate Path Protection Flaw Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-0236Palo Alto Networks Prisma Browser Code Injection Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-0233Palo Alto Networks ADEM Certificate Validation Flaw Scores 8.88.8 HighUpdated
2026-09-24CVE-2025-7406Nokia MantaRay NM sudo Privilege Escalation Reaches Root, Scores 7.87.8 HighUpdated
2026-09-24CVE-2025-65114Apache Traffic Server HTTP Request Smuggling Scores 7.57.5 HighUpdated
2026-09-24CVE-2025-62188Apache DolphinScheduler Sensitive Information Exposure Scores 7.57.5 HighUpdated
2026-09-24CVE-2025-61848Fortinet FortiManager SQL Injection Scores 7.27.2 HighUpdated
2026-09-24CVE-2025-58136Apache Traffic Server Incorrect Control Flow Scores 7.57.5 HighUpdated
2026-09-24CVE-2025-53681Fortinet FortiMail SQL Injection Scores 7.27.2 HighUpdated
2026-09-24CVE-2025-33255NVIDIA TensorRT-LLM MPI Server Deserialization Flaw Scores 7.57.5 HighUpdated
2026-09-24CVE-2025-24818Nokia MantaRay NM OS Command Injection in Log Search Scores 8.08.0 HighUpdated
2026-09-24CVE-2025-24817Nokia MantaRay NM OS Command Injection in Symptom Collector Scores 8.08.0 HighUpdated
2026-09-24CVE-2025-24815Nokia MantaRay NM Unrestricted File Upload Scores 7.87.8 HighUpdated
2026-09-24CVE-2025-14774ABB T-MAC Plus Incorrect Authorization Scores 7.47.4 HighUpdated
2026-09-24CVE-2025-14773ABB T-MAC Plus Cross-Site Scripting Scores 8.08.0 HighUpdated
2026-09-24CVE-2025-14772ABB T-MAC Plus Authorization Bypass via User-Controlled Key Scores 8.88.8 HighUpdated
2026-09-24CVE-2025-14771ABB T-MAC Plus Exposes Files to External Parties, Scores 9.99.9 CriticalUpdated
2026-09-24CVE-2025-12694Forcepoint VPN Client Excessive-Privilege Execution Scores 7.87.8 HighUpdated
2026-09-24CVE-2017-20236ProSoft ICX35-HWC OS Command Injection via Web UI Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2017-20235ProSoft ICX35-HWC Authentication Bypass in Web Interface Scores 9.19.1 CriticalUpdated
2026-09-24CVE-2026-80156Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Strips Backslash Characters but Not Forward Slashes During Path Validation, Letting Authenticated Attackers Write Files to Arbitrary Filesystem Locations9.1 CriticalNew
2026-09-24CVE-2026-80155Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Requires No Authentication, Allowing Unauthenticated Attackers to Read Configuration Files and Upload to Arbitrary Filesystem Locations, Scoring CVSS 10.010.0 CriticalNew
2026-09-24CVE-2026-80154Lantronix SLC8000, SLC9000, EMG, and SLB Series Web Portal Derives Session Tokens Deterministically from Device Model and Current Second, Letting Unauthenticated Attackers Predict and Forge Valid Sessions on All Firmware Versions9.6 CriticalNew
2026-09-24CVE-2026-80147Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root9.9 CriticalNew
2026-09-24CVE-2026-80145Lantronix SLC8000/SLC9000 and EMG Series Set CIFS Password Command Passes User Input Unsanitized to system(), Enabling Authenticated Users with Services Permission to Run Commands as Root9.1 CriticalNew
2026-09-24CVE-2026-80144Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution9.9 CriticalNew
2026-09-24CVE-2026-80143Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution9.9 CriticalNew
2026-09-24CVE-2026-28324SolarWinds Observability Self-Hosted Insufficient Integrity Checks Allow Unauthenticated Remote Code Execution on Non-Default, Non-Hardened Installations9.8 CriticalNew
2026-09-24CVE-2026-13249Honeywell PD45 Industrial Printer F10.19.010040 Web Management Interface Allows Unauthenticated File Upload of Attacker-Controlled Files, Enabling Remote Code Execution Without Credentials9.8 CriticalNew
2026-09-24CVE-2008-4128Cisco IOS's Multiple Cross-Site Request Forgery Flaws Allow Remote Attackers to Execute Arbitrary Commands via Show Privilege and Alias Exec Requests; CISA's July 16th KEV Deadline Has Passed8.1 HighKEV
2026-09-23CVE-2026-3517Progress LoadMaster OS Command Injection via Geo Administration API Scores 8.48.4 HighEPSS-Imminent
2026-09-23CVE-2026-29146Apache Tomcat EncryptInterceptor Padding Oracle Scores 7.57.5 HighEPSS-Imminent
2026-09-23CVE-2026-20180Critical Cisco ISE Path Traversal Enables Remote Code Execution, Scores 9.99.9 CriticalEPSS-Imminent
2026-09-23CVE-2026-39813Fortinet FortiSandbox Path Traversal Enables Privilege Escalation, Scores 9.89.8 CriticalEPSS-Imminent
2026-09-23CVE-2026-40688Fortinet FortiWeb Out-of-Bounds Write Scores 7.27.2 HighEPSS-Imminent
2026-09-23CVE-2026-4670Critical Progress MOVEit Automation Authentication Bypass Scores 9.89.8 CriticalEPSS-Imminent
2026-09-23CVE-2026-59309Critical VMware vCenter Authentication Bypass in Directory Service Scores 9.89.8 CriticalEPSS-Imminent
2026-09-23CVE-2026-3518Progress LoadMaster OS Command Injection via Full-Permission API Scores 8.48.4 HighEPSS-Imminent
2026-09-23CVE-2026-20147Critical Cisco ISE and ISE-PIC Command Injection Scores 9.99.9 CriticalEPSS-Imminent
2026-09-23CVE-2026-94127CISA's September 25th Remediation Deadline for F5 BIG-IP APM's OAuth Profile Heap Overflow Has Passed; Covered Entities Running Affected Virtual Servers Are Out of Compliance9.8 CriticalKEV
2026-09-23CVE-2026-93952Arista VeloCloud Orchestrator Input Validation Gap Lets Remote Attackers Reach Privileged APIs; CISA's September 25th KEV Deadline for Covered Entities Has Now Passed10.0 CriticalKEV
2026-09-23CVE-2026-85102Check Point Firewall Certificate Validation Bypass Across Site-to-Site and Remote Access VPN Carries a Lapsed September 25th CISA KEV Requirement for Covered Entities9.8 CriticalKEV
2026-09-23CVE-2026-73172Advantech EKI-1242EIMS Firmware V1.06.01 edgserver Management Service Passes Unsanitized Input to the OS Shell, Enabling Unauthenticated Remote Attackers to Execute Arbitrary Commands9.3 CriticalNew
2026-09-22CVE-2026-9586Sangoma Switchvox's SQL Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Database Queries and Compromise the Telephony Platform9.8 CriticalKEV
2026-09-22CVE-2026-9198IBM Langflow's Code Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the AI Workflow Platform; CISA's August 7th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-9082Drupal Core's SQL Injection via Specially Crafted Database Abstraction API Requests Enables Privilege Escalation and Remote Code Execution; CISA's May 27th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-86218N-able N-central's Static Code Injection Flaw Allows Remote Attackers to Inject and Execute Arbitrary Code on the RMM Platform Without Prior Authentication9.8 CriticalKEV
2026-09-22CVE-2026-85706GitLab Community and Enterprise Edition's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Read Arbitrary Files on the Server and Fully Compromise the GitLab Instance10.0 CriticalKEV
2026-09-22CVE-2026-83549SonicWall SMA1000 Appliances' OS Command Injection Allows Authenticated Local Attackers to Execute Arbitrary Commands with Root Privileges; CISA's September 5th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-83548SonicWall SMA1000 Appliances' Server-Side Request Forgery Allows Unauthenticated Remote Attackers to Reach Internal Services and Compromise the Secure Mobile Access Gateway; CISA's September 5th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-82329JFrog Artifactory Carries a 9.8 Critical Improper Authentication Flaw That Lets Unauthenticated Attackers Bypass Login Controls on the Artifact Repository9.8 CriticalKEV
2026-09-22CVE-2026-8037Progress LoadMaster's Command Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary OS Commands on the Load Balancer Appliance; CISA's August 10th KEV Deadline Has Passed9.6 CriticalKEV
2026-09-22CVE-2026-73570Zimbra Collaboration Suite's OS Command Injection Allows Authenticated Attackers to Execute Arbitrary Commands on the Email Server with Elevated Privileges; CISA's August 24th KEV Deadline Has Passed8.9 HighKEV
2026-09-22CVE-2026-72898Metabase's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Achieve Full Platform Compromise; CISA's August 14th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-6973Ivanti Endpoint Manager Mobile's Improper Input Validation Allows a Remotely Authenticated Administrator to Execute Code Remotely; CISA's May 10th KEV Deadline Has Passed7.2 HighKEV
2026-09-22CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock's Use-After-Free Allows a Local Attacker to Gain Elevated Privileges via a Freed Memory Reference; CISA's August 25th KEV Deadline Has Passed7.0 HighKEV
2026-09-22CVE-2026-65400Apple macOS's Improper Authentication Flaw Allows a Network Attacker to Bypass Login Controls and Gain Unauthorized Access to the Operating System; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-64849MLflow's Server-Side Request Forgery Flaw Allows Remote Attackers to Use the ML Platform Server as a Proxy to Access Internal Services and Steal Credentials; CISA's September 2nd KEV Deadline Has Passed9.3 CriticalKEV
2026-09-22CVE-2026-63077JetBrains TeamCity's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the CI/CD Server; CISA's August 8th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-63030WordPress Core Input Interpretation Conflict Exploited in the Wild Carries a Lapsed July 24th CISA KEV Mandate for Covered Entities9.8 CriticalKEV
2026-09-22CVE-2026-60137WordPress Core SQL Injection Enabling Database Access Joins CISA's Known Exploited Vulnerabilities Catalog; Covered Entities Past the August 4th Remediation Deadline5.9 MediumKEV
2026-09-22CVE-2026-60004Gitea's Code Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Repository Platform; CISA's August 28th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-59310Broadcom VMware vCenter's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Access Files Outside the Web Root and Potentially Compromise the Virtualization Platform; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-56291Balbooa Forms Unrestricted File Upload Requiring No Authentication Has Missed CISA's July 13th KEV Remediation Deadline; Covered Entities Are Now Out of Compliance9.8 CriticalKEV
2026-09-22CVE-2026-56290Joomlack Page Builder Lets Unauthenticated Users Upload Arbitrary Files, Enabling Remote Code Execution; CISA's July 10th KEV Mandate Has Lapsed9.8 CriticalKEV
2026-09-22CVE-2026-55040Microsoft SharePoint's Weak Authentication Allows Attackers to Bypass Login Controls and Gain Unauthorized Access to SharePoint Sites and Data; CISA's August 21st KEV Deadline Has Passed9.1 CriticalKEV
2026-09-22CVE-2026-50751Check Point Security Gateway's IKEv1 Key Exchange Flaw Lets Unauthenticated Attackers Establish Remote Access VPN Tunnels Without a Valid Password; CISA's June 11th KEV Deadline Has Passed9.3 CriticalKEV
2026-09-22CVE-2026-48939iCagenda Joomla Event Calendar Extension Accepts Unrestricted File Uploads Without Authentication, Enabling Remote Code Execution; CISA's July 13th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-48908JoomShaper SP Page Builder Accepts Arbitrary File Uploads from Unauthenticated Users; CISA's July 10th KEV Deadline for Covered Entities Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-48907Joomla Content Editor Plugin Exposes Privileged Functions Without Proper Authorization; CISA's June 19th KEV Deadline for Covered Entities Has Lapsed9.8 CriticalKEV
2026-09-22CVE-2026-48710Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections6.5 MediumKEV
2026-09-22CVE-2026-48558SimpleHelp Accepts Unverified Cryptographic Signatures, Letting Remote Attackers Bypass Authentication; CISA's July 2nd KEV Deadline for Covered Entities Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-48172Any cPanel User Can Escalate Privileges Through LiteSpeed's Plugin; CISA's May 29th KEV Remediation Requirement for Covered Entities Has Expired9.8 CriticalKEV
2026-09-22CVE-2026-46817Oracle E-Business Suite's Improper Privilege Management in Oracle Payments Allows an Unauthenticated Network Attacker to Take Over the Payments Module via HTTP; CISA's July 18th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-45498Microsoft Defender's Unspecified Vulnerability Allows for Denial of Service; CISA's June 3rd KEV Deadline Has Passed4.0 MediumKEV
2026-09-22CVE-2026-45247Mirasvit Full Page Cache Warmer's Deserialization Flaw Lets Unauthenticated Attackers Reach Remote Code Execution via a Crafted PHP Object in the CacheWarmer Cookie; CISA's June 6th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-42897Microsoft Exchange Server's Outlook Web Access Cross-Site Scripting Flaw Executes Arbitrary JavaScript When Interaction Conditions Are Met; CISA's May 29th KEV Deadline Has Passed8.1 HighKEV
2026-09-22CVE-2026-42018JFrog Artifactory's Improper Authentication Allows Network-Based Attackers to Bypass Login Controls and Gain Unauthorized Access to the Artifact Repository7.5 HighKEV
2026-09-22CVE-2026-42016JFrog Artifactory's Incorrect Authorization Allows Authenticated Users to Access Artifacts and Repositories Outside Their Permitted Scope8.1 HighKEV
2026-09-22CVE-2026-41940WebPros cPanel and WHM's Login Flow Authentication Bypass Gives Unauthenticated Attackers Unauthorized Access to the Control Panel; CISA's May 3rd KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-41091Microsoft Defender's Link Following Flaw Enables an Authorized Attacker to Elevate Privileges Locally; CISA's June 3rd KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-39987Marimo's Pre-Authentication Flaw Gives Unauthenticated Attackers Shell Access and Arbitrary Command Execution; CISA's May 7th KEV Remediation Requirement for Covered Entities Has Long Lapsed9.8 CriticalKEV
2026-09-22CVE-2026-39808Fortinet FortiSandbox's OS Command Injection Gives Unauthenticated Attackers Remote Code Execution via Crafted HTTP Requests; CISA's July 19th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-35616Fortinet FortiClient EMS Access Control Bypass Entered CISA's Known Exploited Vulnerabilities Catalog with an April 9th Federal Deadline That Has Long Passed9.8 CriticalKEV
2026-09-22CVE-2026-35273Oracle PeopleSoft Enterprise PeopleTools' Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Take Over the Platform; CISA's June 15th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-34926Pre-Authenticated Local Attackers Can Use Relative Path Traversal in Trend Micro Apex One to Modify Key Configuration Data; CISA's June 4th KEV Mandate for Covered Entities Has Lapsed6.7 MediumKEV
2026-09-22CVE-2026-34910Network-Adjacent Attackers Can Inject Commands into Ubiquiti UniFi OS Through an Input Validation Flaw; CISA's June 26th KEV Remediation Window Has Closed for Covered Entities10.0 CriticalKEV
2026-09-22CVE-2026-34909Ubiquiti UniFi OS's Path Traversal Lets a Network-Adjacent Attacker Access Files on the Underlying System and Manipulate an Underlying Account; CISA's June 26th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-34908Ubiquiti UniFi OS's Improper Access Control Lets a Network-Adjacent Attacker Make Unauthorized Changes to the System; CISA's June 26th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-34486Apache Tomcat's Missing Encryption of Sensitive Session Data Exposes Credentials and Tokens to Network Interception; CISA's August 7th KEV Deadline Has Passed7.5 HighKEV
2026-09-22CVE-2026-34197Apache ActiveMQ's Improper Input Validation Enables Code Injection Affecting Both ActiveMQ and Broker Deployments; CISA's April 30th KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2026-33825Microsoft Defender's Insufficient Access Control Allows an Authorized Attacker to Escalate Privileges Locally; CISA's May 6th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-33824Microsoft Windows IKE Service Extensions' Double Free Enables Unauthenticated Remote Attackers to Execute Arbitrary Code; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-32202Microsoft Windows Shell's Protection Mechanism Failure Allows an Unauthorized Attacker to Perform Spoofing Over the Network; CISA's May 12th KEV Deadline Has Passed4.3 MediumKEV
2026-09-22CVE-2026-31431Linux Kernel Resource Mishandling That Allows Privilege Escalation Carries a Lapsed May 15th CISA KEV Mandate; Covered Entities on Unpatched Kernels Remain Out of Compliance7.8 HighKEV
2026-09-22CVE-2026-28318SolarWinds Serv-U File Transfer Server Resource Exhaustion Exploited in the Wild Carries a Lapsed June 19th CISA KEV Federal Deadline7.5 HighKEV
2026-09-22CVE-2026-25089Fortinet FortiSandbox's Unauthenticated OS Command Injection via Crafted HTTP Requests Covers Cloud and PaaS Deployments; CISA's July 19th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-21962Oracle HTTP Server and WebLogic Server Proxy Plug-in's Improper Access Control Allows Unauthenticated Network Attackers to Fully Compromise the Middleware Platform; CISA's August 27th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-21643Fortinet FortiClient EMS's SQL Injection Allows Unauthenticated Attackers to Execute Unauthorized Code via Crafted HTTP Requests; CISA's April 16th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-20316Cisco Secure Firewall Management Center Hard-Coded Password Lets Attackers Bypass Authentication; CISA's August 1st KEV Deadline for Covered Entities Has Passed5.3 MediumKEV
2026-09-22CVE-2026-20262Authenticated Path Traversal in Cisco Catalyst SD-WAN Manager Lets Remote Attackers Write Files Outside Allowed Directories; CISA's June 29th KEV Deadline Has Passed6.5 MediumKEV
2026-09-22CVE-2026-20253Splunk Enterprise's Missing Authentication on a PostgreSQL Sidecar Service Endpoint Lets Unauthenticated Users Create or Truncate Arbitrary Files; CISA's June 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-20245Cisco Catalyst SD-WAN Manager's Improper Encoding Allows an Authenticated Local Attacker to Execute Arbitrary Commands as Root via a Crafted File; CISA's June 23rd KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-20230Cisco Unified Communications Manager SSRF Flaw Routes Attacker Requests to Internal Resources; CISA's June 28th KEV Deadline for Covered Entities Has Lapsed8.6 HighKEV
2026-09-22CVE-2026-20200Cisco Unified Computing System's Argument Delimiter Injection Allows an Authenticated Attacker to Execute Arbitrary Commands on the Management Controller8.8 HighExploited
2026-09-22CVE-2026-20182Cisco Catalyst SD-WAN Controller and Manager's Authentication Bypass Gives Unauthenticated Remote Attackers Administrative Privileges; CISA's May 17th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-20133Cisco Catalyst SD-WAN Manager Leaks Sensitive Configuration Data to Unauthorized Users; CISA's April 23rd KEV Remediation Requirement Has Expired for Covered Entities6.5 MediumKEV
2026-09-22CVE-2026-20128Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed7.5 HighKEV
2026-09-22CVE-2026-20122Cisco Catalyst SD-WAN Manager Exposes Privileged API Functions to Unauthorized Callers; CISA's April 23rd KEV Remediation Deadline for Covered Entities Has Long Passed5.4 MediumKEV
2026-09-22CVE-2026-20079Cisco Firewall Management Center's Authentication Bypass via an Alternate Path Grants Unauthenticated Remote Attackers Full Administrative Control; CISA's September 12th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-19490Citrix NetScaler's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access Protected Resources Without Valid Credentials9.8 CriticalKEV
2026-09-22CVE-2026-16232Check Point SmartConsole's Improper Authentication Allows Unauthenticated Remote Attackers to Obtain a Login Token and Authenticate with Full Administrative Privileges; CISA's July 25th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-15410SonicWall SMA1000's Code Injection Allows a Remote Authenticated Administrator to Execute Arbitrary OS Commands Under Specific Conditions; CISA's July 17th KEV Deadline Has Passed7.2 HighKEV
2026-09-22CVE-2026-15409SonicWall SMA1000 Secure Access Appliances Accept Forged Server-Side Requests, Enabling Internal Network Pivoting; CISA's July 17th KEV Remediation Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-1340Ivanti Endpoint Manager Mobile's Code Injection Vulnerability Allows Attackers to Achieve Unauthenticated Remote Code Execution; CISA's April 11th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-12569PTC Windchill and FlexPLM's Improper Input Validation Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via Malicious Network Requests; CISA's June 28th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-10520Ivanti Sentry's OS Command Injection Gives Remote Unauthenticated Attackers Root-Level Remote Code Execution; CISA's June 14th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-0300PAN-OS Out-of-Bounds Write Enabling Code Execution Affects Both Palo Alto Networks Firewalls and Siemens RUGGEDCOM APE1808 Industrial Appliances; CISA's May 9th KEV Window Has Closed9.8 CriticalKEV
2026-09-22CVE-2026-0257PAN-OS Authentication Bypass Enabling Unauthorized VPN Tunnels Affects Palo Alto Networks Prisma Access and Siemens RUGGEDCOM APE1808; Now Listed in CISA's Known Exploited Vulnerabilities Catalog9.1 CriticalKEV
2026-09-22CVE-2025-68686Fortinet FortiOS's Information Exposure Flaw Allows a Remote Unauthenticated Attacker to Bypass the Previously Issued Patch for Symbolic Link Persistency; CISA's August 10th KEV Deadline Has Passed5.9 MediumKEV
2026-09-22CVE-2025-67038Lantronix EDS5000's Code Injection via the Username Parameter Executes Injected OS Commands with Root Privileges; CISA's June 26th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2025-62593Ray-Project Ray's Code Injection Flaw Allows Remote Attackers to Execute Arbitrary Code on the Distributed ML Framework's Cluster Nodes; CISA's August 20th KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2025-60710Microsoft Windows Link Following Flaw Enables Privilege Escalation; CISA's April 27th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2025-29635D-Link DIR-823X's set_prohibiting POST Endpoint Accepts Injected Commands and Executes Them on Remote Devices; CISA's May 8th KEV Deadline Has Passed for This Potentially End-of-Life Router7.2 HighKEV
2026-09-22CVE-2025-2749Kentico Xperience's Path Traversal in the Staging Sync Server Allows Authenticated Users to Upload Arbitrary Data Outside Expected Directories; CISA's May 4th KEV Deadline Has Passed7.2 HighKEV
2026-09-22CVE-2024-7399Samsung MagicINFO 9 Path Traversal Enabling Arbitrary File Writes as System Authority Has Missed CISA's May 8th KEV Deadline; Covered Entities Remain Out of Compliance8.8 HighKEV
2026-09-22CVE-2024-57728SimpleHelp's Zip Slip Path Traversal Lets Admin Users Write Arbitrary Files to Any Location on the Server and Execute Code as the Service Account; CISA's May 8th KEV Deadline Has Passed7.2 HighKEV
2026-09-22CVE-2024-57726SimpleHelp Lets Low-Privilege Technicians Mint Overpowered API Keys Through a Missing Authorization Check; CISA's May 8th KEV Deadline for Covered Entities Has Lapsed9.9 CriticalKEV
2026-09-22CVE-2024-21182Unauthenticated T3 and IIOP Network Access to Oracle WebLogic Enables System Compromise; CISA's June 4th KEV Mandate for Covered Entities Has Been Lapsed for Months7.5 HighKEV
2026-09-22CVE-2024-1708ConnectWise ScreenConnect's Path Traversal Enables Remote Code Execution or Direct Access to Confidential Data and Critical Systems; CISA's May 12th KEV Deadline Has Passed8.4 HighKEV
2026-09-22CVE-2023-49105ownCloud's Improper Authentication Allows Unauthenticated Remote Attackers to Gain Access to Protected Files Without Valid Credentials; CISA's August 30th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2023-36424Microsoft Windows Common Log File System Driver's Out-of-Bounds Read Enables Privilege Escalation; CISA's April 27th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2023-21529Microsoft Exchange Server's Deserialization of Untrusted Data Enables Authenticated Attackers to Achieve Remote Code Execution; CISA's April 27th KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2022-0995Linux Kernel's Out-of-Bounds Write Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 9th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2022-0492Linux Kernel's cgroup v1 release_agent Feature Enables Privilege Escalation; CISA's June 5th KEV Deadline for Covered Entities Has Lapsed7.8 HighKEV
2026-09-22CVE-2021-27137Unauthenticated Attackers Can Overflow DD-WRT's UPnP Stack Buffer; CISA's July 24th KEV Mandate for Covered Entities Has Lapsed8.1 HighKEV
2026-09-22CVE-2021-23758Ajax.NET Professional's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via a Crafted Serialized Object; CISA's September 9th KEV Deadline Has Passed8.1 HighKEV
2026-09-22CVE-2019-1068Microsoft SQL Server's Unspecified Flaw Allows Authenticated Attackers to Execute Arbitrary Code on the Database Server; CISA's August 29th KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2015-5287Red Hat Automatic Bug Reporting Tool's Privilege Escalation Flaw Allows Local Attackers to Gain Root Access on Affected Enterprise Linux Systems; CISA's September 9th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2015-3246Red Hat Enterprise Linux's Libuser Race Condition in Password File Writes Allows Local Attackers to Corrupt System Files; CISA's September 9th KEV Deadline Has Passed5.1 MediumKEV
2026-09-22CVE-2012-1854Microsoft Visual Basic for Applications Loads Libraries Insecurely, Enabling Remote Code Execution; CISA's April 27th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2010-0806Microsoft Internet Explorer's Use-After-Free Enables Remote Code Execution via Invalid Pointer Access After Object Deletion; CISA's June 3rd KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2010-0249Microsoft Internet Explorer's Use-After-Free Gives Remote Attackers Code Execution via a Pointer to a Deleted Object; CISA's June 3rd KEV Deadline Has Passed for This End-of-Life Browser8.8 HighKEV
2026-09-22CVE-2009-1537Microsoft DirectX's QuickTime Movie Parser Filter Lets Remote Attackers Execute Arbitrary Code via a Crafted Media File; CISA's June 3rd KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2009-0238Microsoft Office Code Injection From 2009 Added to CISA's Known Exploited Vulnerabilities Catalog with an April 28th Federal Deadline That Has Since Passed8.8 HighKEV
2026-09-22CVE-2008-4250Microsoft Windows Server Service's Path Canonicalization Buffer Overflow Enables Remote Code Execution via Crafted RPC Requests; CISA's June 3rd KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-7273Zyxel GS1900 Series Switches' CGI Program Stack-Based Buffer Overflow Allows a LAN-Side Unauthenticated Attacker to Execute OS Commands via Crafted HTTP Requests; CISA's September 24th KEV Deadline Has Passed8.8 HighKEV
2026-09-20CVE-2026-87886Acronis Backup's Incorrect Default Permissions Allow a Local Attacker to Access Backup Files and Configurations Not Intended for Their Account; CISA's September 19th KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-86060MikroTik RouterOS's Argument Injection in a Command-Processing Component Allows Unauthenticated Attackers to Execute Arbitrary Commands on the Router; CISA's September 13th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-20CVE-2026-85880Microsoft Windows' Heap-Based Buffer Overflow Allows Local Attackers to Escalate Privileges by Corrupting Heap Memory; CISA's September 22nd KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-84869ConnectWise ScreenConnect's Improper Privilege Management and Missing Authorization Allow Unauthenticated Attackers to Gain Administrative Control of the Remote Support Platform; CISA's September 14th KEV Deadline Has Passed9.9 CriticalKEV
2026-09-20CVE-2026-81963Microsoft Windows' Improper Link Resolution Before File Access Allows a Local Attacker to Follow Symbolic Links to Privileged Files and Gain Elevated Access; CISA's September 22nd KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-70468Fortinet FortiManager's Authentication Bypass via an Alternate Path Grants Unauthenticated Attackers Access to Management Functions8.1 HighUpdated
2026-09-20CVE-2026-70465Fortinet FortiClient's Classic Buffer Overflow Allows an Attacker to Corrupt Memory and Potentially Execute Arbitrary Code8.1 HighUpdated
2026-09-20CVE-2026-67277MikroTik RouterOS's Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Access and Modify Router Configuration; CISA's September 13th KEV Deadline Has Passed8.2 HighKEV
2026-09-20CVE-2026-53362Linux Kernel's Unspecified Flaw Allows Local Attackers to Gain Elevated Privileges on Affected Systems; CISA's August 30th KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-53266Linux Kernel's Out-of-Bounds Write Vulnerability Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 21st KEV Deadline Has Passed8.8 HighKEV
2026-09-20CVE-2026-50516Microsoft Azure Kubernetes Service's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Interact with Privileged Cluster Management Endpoints9.4 CriticalUpdated
2026-09-20CVE-2026-26035Fortinet FortiWeb's Improper Authentication Allows Unauthenticated Attackers to Bypass Login Controls and Access the Web Application Firewall Management Interface9.8 CriticalUpdated
2026-09-20CVE-2026-20349Cisco Secure Firewall ASA and FTD's Heap Inspection Vulnerability Allows Remote Attackers to Extract Sensitive Memory Contents from the Firewall Device; CISA's August 14th KEV Deadline Has Passed8.6 HighKEV
2026-09-20CVE-2026-20301Cisco IOS XE's Unchecked Loop Condition Input Allows Network-Accessible Devices to Be Crashed via a Specially Crafted Packet8.6 HighExploited
2026-09-20CVE-2026-20273Cisco IOS XE's Improper Input Validation Allows a Remote Attacker to Trigger a Device Crash or Disruption via a Specially Crafted Input8.6 HighUpdated
2026-09-20CVE-2026-20272Cisco IOS XE's Injection Flaw Allows Remote Attackers to Execute Arbitrary Commands via a Specially Crafted Input Reaching a Downstream Component9.8 CriticalUpdated
2026-09-20CVE-2026-20271Cisco IOS XE's Insufficient Control Flow Management Allows a Remote Attacker to Disrupt Device Operation via a Crafted Packet8.6 HighUpdated
2026-09-20CVE-2026-20270Cisco IOS XE's Incorrect Calculation Vulnerability Allows a Remote Attacker to Cause an Unrecoverable Device Condition via a Specially Crafted Input8.6 HighUpdated
2026-09-20CVE-2026-20269Cisco IOS XE's Improper Resource Lifetime Management Allows Remote Attackers to Exhaust Device Resources and Cause a Denial of Service8.6 HighUpdated
2026-09-20CVE-2026-20268Cisco IOS XE's Improper Restriction of Memory Buffer Operations Allows Remote Attackers to Potentially Execute Code or Crash the Device via a Malformed Packet8.6 HighUpdated
2026-09-20CVE-2026-20267Cisco IOS XE's Improper Access Control Allows Network-Based Attackers to Access Protected Functions or Data Without Proper Authorization9.0 CriticalUpdated
2026-09-20CVE-2026-20124Cisco IOS XE's Memory Resource Leak Allows Remote Attackers to Exhaust Device Memory and Cause a Denial of Service via Repeated Packet Transmission7.7 HighExploited
2026-09-20CVE-2026-0301Palo Alto Networks Cloud NGFW and Prisma Access Use of Uninitialized Resource Allows a Network-Based Attacker to Access Sensitive Information7.5 HighExploited
2026-09-20CVE-2026-0299Palo Alto Networks GlobalProtect's Untrusted Search Path Allows a Local Attacker to Load a Malicious Library and Execute Code in the Application's Context7.8 HighExploited
2026-09-20CVE-2026-0298Palo Alto Networks GlobalProtect's Code Injection Vulnerability Allows an Authenticated Remote Attacker to Execute Arbitrary Code in the Context of the VPN Client8.1 HighExploited
2026-09-20CVE-2026-0297Palo Alto Networks GlobalProtect's Out-of-Bounds Write Allows a Remote Attacker to Corrupt Memory and Execute Code or Crash the Application8.1 HighExploited
2026-09-20CVE-2026-0296Palo Alto Networks GlobalProtect's Improper Certificate Validation Allows a Network Adversary to Present a Forged Certificate and Intercept the VPN Connection7.4 HighExploited
2026-09-20CVE-2026-0295Palo Alto Networks GlobalProtect's Race Condition Allows a Local Attacker to Exploit a Timing Window and Gain Elevated Privileges7.0 HighExploited
2026-09-20CVE-2026-0294Palo Alto Networks Prisma Access Agent's Uncontrolled Search Path Allows a Local Attacker to Place a Malicious Library Where the Agent Will Load It7.8 HighExploited
2026-09-20CVE-2025-39964Linux Kernel's Race Condition Allows a Local Attacker to Exploit a Timing Window and Gain Elevated Privileges on the System; CISA's September 21st KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2025-39682Linux Kernel's Improper Check for Exceptional Conditions Allows Remote Attackers to Execute Arbitrary Code or Crash Affected Systems; CISA's September 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-20CVE-2025-25249Fortinet Multiple Products' Heap-Based Buffer Overflow Allows Remote Attackers to Potentially Execute Arbitrary Code or Crash Affected Devices; CISA's September 12th KEV Deadline Has Passed8.1 HighKEV
2026-09-20CVE-2026-82078PaperCut NG/MF's Unsafe Reflection Allows Remote Attackers to Manipulate Class Loading and Execute Arbitrary Code on the Print Management Server; CISA's September 14th KEV Deadline Has Passed9.1 CriticalKEV
2026-09-20CVE-2026-72530TrueConf Server's Code Injection Vulnerability Allows Remote Attackers to Execute Arbitrary Code on the Video Conferencing Platform; CISA's September 3rd KEV Deadline Has Passed9.0 CriticalKEV
2026-09-20CVE-2026-72529TrueConf Server's Missing Authentication on a Critical Function Allows Unauthenticated Remote Attackers to Access Administrative Capabilities; CISA's August 23rd KEV Deadline Has Passed9.8 CriticalKEV
2026-09-20CVE-2026-70332Microsoft SharePoint Online's Cross-Site Scripting Flaw Lets Attackers Execute Arbitrary JavaScript in the Victim's Browser Session9.6 CriticalUpdated
2026-09-20CVE-2026-66322Microsoft Edge's Origin Validation Error Allows a Cross-Origin Attacker to Bypass Boundary Enforcement and Access Content from a Different Origin7.1 HighUpdated
2026-09-20CVE-2026-66321Microsoft Edge's Type Confusion in the Browser Engine Allows a Remote Attacker to Execute Arbitrary Code via a Crafted Web Page7.4 HighUpdated
2026-09-20CVE-2026-66318Microsoft Edge's Origin Validation Error Exposes Protected Resources to Cross-Origin Content Access by a Network Attacker8.1 HighUpdated
2026-09-20CVE-2026-66315Microsoft Edge's Use After Free Vulnerability Lets a Remote Attacker Corrupt the Browser Heap and Potentially Execute Code via a Crafted Web Page7.5 HighUpdated
2026-09-20CVE-2026-66310Microsoft Edge's Externally Controlled File Path Allows a Crafted Web Page to Reference Arbitrary Files on the Local System7.7 HighUpdated
2026-09-20CVE-2026-65802Microsoft Edge's External Control of a File Path Flaw Allows Attackers to Read or Write Files Outside the Intended Browsing Sandbox via a Crafted Page7.4 HighUpdated
2026-09-20CVE-2026-65668Microsoft Purview eDiscovery's Improper Access Control Allows Authenticated Attackers to Access Data Outside Their Authorized Scope8.8 HighUpdated
2026-09-20CVE-2026-65667Microsoft Teams Carries a Critical 10.0 CVSS Score for a Missing Authorization Flaw That Lets Authenticated Users Access Privileged Functions10.0 CriticalUpdated
2026-09-20CVE-2026-63508Microsoft Planetary Computer's Missing Authentication on a Critical Endpoint Allows Unauthenticated Attackers to Access and Execute Privileged Functions10.0 CriticalUpdated
2026-09-20CVE-2026-62918Microsoft Teams' Improper Cryptographic Signature Verification Allows Attackers to Submit Forged Messages That the Application Accepts as Authentic7.5 HighUpdated
2026-09-20CVE-2026-62896Microsoft Teams' Improper Authentication Allows Unauthenticated Remote Attackers to Access the Platform Without Valid Credentials9.6 CriticalUpdated
2026-09-20CVE-2026-62873Microsoft Windows Admin Center's Improper Cryptographic Signature Verification Enables Unauthenticated Attackers to Forge Signed Requests and Gain Unauthorized Access9.8 CriticalUpdated
2026-09-20CVE-2026-62870Microsoft Excel's Use After Free Vulnerability Lets Remote Attackers Execute Arbitrary Code via a Specially Crafted Workbook8.8 HighUpdated
2026-09-20CVE-2026-59115Microsoft Entra Provisioning Service's Path Traversal Flaw Allows Attackers to Navigate Outside the Intended Directory and Access Provisioned Tenant Data9.9 CriticalUpdated
2026-09-20CVE-2026-58612Microsoft PowerShell's High-Severity Flaw Allows a Network-Based Attacker to Gain Unauthorized Access on Affected Installations7.4 HighUpdated
2026-09-20CVE-2026-57105Microsoft SharePoint Server's Unspecified Flaw Allows an Authenticated Attacker to Gain Unauthorized Access to Server Resources8.0 HighUpdated
2026-09-20CVE-2025-40582Siemens SCALANCE LPE9403's Configuration Parameter Handling Flaw Lets Non-Privileged Local Attackers Execute Commands as Root When SINEMA Remote Connect Edge Client Is Installed7.8 HighUpdated
2026-09-20CVE-2025-40581Siemens SCALANCE LPE9403's Authentication Bypass Allows Non-Privileged Local Attackers to Bypass Authentication Controls on Affected Versions7.1 HighUpdated
2026-09-20CVE-2025-40574Siemens SCALANCE LPE9403's Incorrect Permissions on Critical Resources Expose the Backup Manager Service to Non-Privileged Local Attackers7.8 HighUpdated
2026-09-18CVE-2026-87491Google Chromium V8's Out-of-Bounds Write Allows Remote Attackers to Corrupt the JavaScript Engine's Heap and Execute Arbitrary Code via a Crafted Web Page8.8 HighKEV
2026-09-18CVE-2026-59822BerriAI LiteLLM's Improper Authentication Allows Unauthenticated Attackers to Access the AI Model Gateway and Interact with Configured LLM Endpoints Without Credentials8.2 HighKEV
2026-09-18CVE-2026-58704Google Pixel's Improper Authorization Flaw Allows an Attacker with Physical or Local Access to Bypass Permission Controls and Access Protected Device Functions8.8 HighKEV
2026-09-18CVE-2026-49869Kestra OSS's OS Command Injection Flaw Lets Unauthenticated Remote Attackers Execute Arbitrary Commands on the Workflow Orchestration Server with Full System Privileges10.0 CriticalKEV
2026-09-18CVE-2026-15688Mitsubishi Electric GX Works3 and Motion Control Setting Authentication Algorithm Allows a Local Attacker to Successfully Authenticate with an Invalid Block Password by Modifying the Executable Module in Memory9.2 CriticalNew
2026-09-18CVE-2026-12745Ivanti Neurons for ITSM Before 2026.2 Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Server9.8 CriticalUpdated
2026-09-18CVE-2026-12744Ivanti Neurons for ITSM Before 2026.2 Deserialization of Untrusted Data Allows a Second Unauthenticated Remote Code Execution Path on the Server9.8 CriticalUpdated
2026-09-18CVE-2026-12650Ivanti Neurons for ITSM Before 2026.2 Deserialization of Untrusted Data Allows Authenticated Remote Attackers to Execute Arbitrary Code on the Server, Scoring CVSS 9.99.9 CriticalUpdated
2026-09-18CVE-2026-12647Ivanti Neurons for ITSM Before 2026.2 Missing Authorization Lets Authenticated Remote Attackers Execute Arbitrary Code on the Server, Scoring CVSS 9.99.9 CriticalUpdated
2026-09-18CVE-2026-12646Ivanti Neurons for ITSM Before 2026.2 Missing Authorization Lets Authenticated Remote Attackers Execute Arbitrary Code on the Server via a Second Unprotected Path9.9 CriticalUpdated
2026-09-18CVE-2026-12645Ivanti Neurons for ITSM Before 2026.2 Missing Authorization Lets Authenticated Remote Attackers Execute Arbitrary Code on the Server via a Third Unprotected Path9.9 CriticalUpdated
2026-09-17CVE-2026-93188Linux Kernel HID Roccat Driver Uses an 8-bit Device-Supplied Profile Value as an Array Index Without Bounds Checking, Enabling an Out-of-Bounds Memory Access via a Crafted USB Device—New
2026-09-17CVE-2026-90099Linux Kernel TC Classifier Filter Allocations in the change() Path Use Plain GFP Flags Without Accounting to memcg, Allowing Container Workloads to Exhaust Host Memory Without Being Charged—New
2026-09-17CVE-2026-90058Linux Kernel qdisc_calculate_pkt_len Amplifies User-Supplied Size Table Values Without Bounds Checking, Allowing a Crafted Size Table to Cause a Soft Lockup in the Packet Scheduler—New
2026-09-17CVE-2026-73453Arista EOS P4Runtime Client Interface Allows Unauthenticated Arbitrary Code Execution Under Certain Conditions on Platforms Running EOS with P4Runtime Configured, Scoring CVSS 10.010.0 CriticalNew
2026-09-17CVE-2026-73447Arista EOS gRPC Network Security Interface Certz Service Lets a Privileged Authenticated User Execute Arbitrary Commands with Root Privileges, Leading to Full Device Compromise9.1 CriticalNew
2026-09-17CVE-2026-73437Arista EOS DHCP Relay Forwards Crafted Reply Packets From Non-Helper-Address Sources to Clients Without Validation, Letting Unauthenticated Network Attackers Inject Arbitrary DHCP Responses to Hosts9.6 CriticalNew
2026-09-14CVE-2026-89478Linux Kernel SCTP Authenticated ASCONF DEL-IP Removes a Transport While a Backlogged Chunk Still Holds a Pointer to It, Enabling Use-After-Free on the Next SACK9.8 CriticalNew
2026-09-11CVE-2026-84390Fortinet FortiMonitorOnSight 7.2.0 Through 7.2.7 Embeds Sensitive Information in Source Code, Potentially Allowing Attackers to Gain Unauthorized Access via Exposed Credentials9.8 CriticalNew
2026-09-11CVE-2026-79698Advantech WISE-6610 Series Management Interface Fails to Neutralize Special Elements in a Command Argument, Allowing Unauthenticated Remote Attackers to Inject Arbitrary Application Commands9.9 CriticalNew
2026-09-11CVE-2026-63298LXD NVIDIA Instance Configuration Handler Accepts Newline Characters in nvidia.driver.capabilities and nvidia.require.* Values, Letting Authenticated Attackers Inject Arbitrary Directives into the GPU Configuration9.9 CriticalUpdated
2026-09-10CVE-2026-69240Sequelize Before 6.37.4 Fails to Escape Quotes in the Oracle Dialect When a String Value Starts with TO_TIMESTAMP or TO_DATE, Enabling SQL Injection Against Oracle Databases9.8 CriticalNew
2026-09-08CVE-2026-81939SonicWall Network Security Manager On-Prem File Upload Extracts Archive Entries Without Validating Path Components, Enabling Zip Slip File Placement Outside the Intended Destination Directory9.1 CriticalNew
2026-09-08CVE-2026-79697Advantech WISE-6610 Series Management Interface Exposes a Second Special-Element Injection Path, Allowing Unauthenticated Remote Attackers to Manipulate Application Command Execution9.9 CriticalNew
2026-09-08CVE-2026-78328SonicWall Network Security Manager On-Prem Lets a Lower-Privileged Admin Escalate to SuperAdmin Due to a Missing Authorization Check9.1 CriticalNew
2026-09-08CVE-2026-78327SonicWall Network Security Manager On-Prem Management Interface Passes Authenticated User Input to the OS Shell, Enabling Arbitrary Command Execution9.1 CriticalNew
2026-09-08CVE-2026-75925IXON VPN Client Before 1.4.7 Writes Local Service Configuration Values to a File Without Stripping Line-Ending Sequences, Letting an Attacker Inject Commands That Execute as Root or SYSTEM via a Privileged Subprocess9.6 CriticalNew
2026-09-08CVE-2026-45538OpenSIPS 4.0.0 and Prior Stack Buffer Overflow in sip_to_json When a SIP Header Name Exceeds 255 Bytes, Enabling Remote Code Execution via Crafted SIP Messages9.8 CriticalNew
2026-09-08CVE-2026-26084Fortinet FortiSandbox 4.4.x and 5.0.x Improper Access Control Lets Attackers Access Sensitive Information via Crafted HTTP Requests9.9 CriticalNew
2026-09-08CVE-2026-10090Red Hat Advanced Cluster Management Application Subscription Controller Lets a User with Namespace-Scoped Edit Privileges Create a Channel Pointing to an Attacker-Controlled Helm Repository, Enabling Privilege Escalation9.0 CriticalNew
2026-09-04CVE-2026-85224D-Link DNS-320 ShareCenter 2.06B01 File Sharing CGI Passes the fileurl Parameter Unsanitized to the Shell, Enabling Remote Code Execution by Authenticated Admin Users9.1 CriticalNew
2026-09-04CVE-2026-85223D-Link DNS-340L 1.01B04 Dropbox CGI Injects the callback_url and sync_interval Fields Directly into the Shell, Allowing Low-Privileged Authenticated Attackers to Execute Remote Commands9.9 CriticalNew
2026-09-04CVE-2026-85222D-Link DNS-340L 1.01B04 Add-On Center CGI Passes f_name, f_url, and f_flag Unsanitized to the Shell, Enabling Authenticated Admin Remote Code Execution9.1 CriticalNew
2026-09-02CVE-2026-82691D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 USB Device Handler Passes Unsanitized Input to the Shell, Enabling Authenticated Admin Remote Code Execution9.1 CriticalNew
2026-09-01CVE-2026-82688D-Link DNS-340L and DNS-345 Virtual Volume CGI Injects Input Arguments Unsanitized into the Shell, Enabling Authenticated Admin Remote Code Execution9.1 CriticalNew
2026-09-01CVE-2026-82593D-Link DIR-825M 1.1.8 LTE Fibocom Firmware Upgrade Handler Copies Unbounded User Input into a Fixed Stack Buffer, Enabling Unauthenticated Remote Code Execution9.9 CriticalNew
2026-08-31CVE-2026-82692D-Link DNS-340L and DNS-345 iSCSI Manager CGI Passes alias, username, and password Arguments Directly to the Shell, Allowing Low-Privileged Attackers to Execute Remote Code9.9 CriticalNew
2026-08-31CVE-2026-82690D-Link DNS-327L and DNS-340L Virtual Environment Manager CGI Injects Unsanitized User Arguments into the Shell, Enabling Authenticated Admin Remote Code Execution9.1 CriticalNew
2026-08-31CVE-2026-82689D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 ISO Image Mount Handler Passes Mount Arguments Unsanitized to the Shell, Allowing Low-Privileged Attackers to Execute Remote Commands9.9 CriticalNew
2026-08-31CVE-2026-82592D-Link DIR-825M 1.1.8 Disk Format Handler Overflows a Stack Buffer When the manipulation Parameter Exceeds Its Declared Bounds, Enabling Unauthenticated Remote Code Execution9.9 CriticalNew
2026-08-31CVE-2026-71957D-Link DWR-M961 C1 app.cgi Overflows a Stack Buffer on a Long netAcc.addlist[].name Value, Enabling Unauthenticated Remote Code Execution9.8 CriticalNew
2026-08-31CVE-2026-71956D-Link DWR-M961 C1 app.cgi Injects the netDig.ping.dst Field Unsanitized into the Shell, Enabling Unauthenticated Remote Code Execution with Root Privileges9.8 CriticalNew
2026-08-31CVE-2026-71952D-Link DWR-M961 C1 PIN Management Setup Handler Injects the oldPIn Field Into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution9.8 CriticalNew
2026-08-31CVE-2026-71951D-Link DWR-M961 C1 IMEI Setup Handler Passes the IMEI_value Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution9.8 CriticalNew
2026-08-31CVE-2026-71950D-Link DWR-M961 C1 SMS Management Handler Injects the action_value Field Directly into the Shell, Enabling Unauthenticated Remote Root Code Execution9.8 CriticalNew
2026-08-31CVE-2026-71947D-Link DWR-M961 C1 Traceroute Diagnostic Handler Injects the host and ipVer Fields into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution9.8 CriticalNew
2026-08-31CVE-2026-71946D-Link DWR-M961 C1 Ping Diagnostic Run Handler Passes the host Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution9.8 CriticalNew
2026-08-28CVE-2026-80660Linux Kernel OCC hwmon Driver Unregisters sysfs Devices While Holding the OCC Lock, Causing a Deadlock When hwmon_device_unregister Tries to Flush sysfs Work Items—New
2026-08-28CVE-2026-80659Linux Kernel MMC vub300 Driver Issues a Reset While Holding cmd_mutex, Blocking the Command Thread That Must Complete Before the Reset Can Proceed—New
2026-08-28CVE-2026-71958D-Link DWR-M961 C1 quicksetup.cgi Overflows a Stack Buffer on Long test4, ssid2, or username Values, Enabling Unauthenticated Remote Code Execution9.8 CriticalNew
2026-08-28CVE-2026-71955D-Link DWR-M961 C1 formWsc Handler Injects localPin, targetAPSsid, peerPin, and peerRptPin Fields into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution9.8 CriticalNew
2026-08-28CVE-2026-71954D-Link DWR-M961 C1 L2TPv3 Configuration Handler Injects tunnelid and sessionid Fields Directly into the Shell, Enabling Unauthenticated Remote Root Code Execution9.8 CriticalNew
2026-08-28CVE-2026-71953D-Link DWR-M961 C1 NTP Setup Handler Passes the ntpServerIp1 Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution9.8 CriticalNew
2026-08-28CVE-2026-71949D-Link DWR-M961 C1 USSD Setup Handler Injects ussdValue and selectMenuValue into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution9.8 CriticalNew
2026-08-28CVE-2026-71948D-Link DWR-M961 C1 Debug Diagnostic Run Handler Passes the host Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution9.8 CriticalNew
2026-08-28CVE-2026-71945D-Link DWR-M961 C1 LTE Fibocom Firmware Upgrade Handler Injects the fota_url Field into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution9.8 CriticalNew
2026-08-28CVE-2026-71944D-Link DWR-M961 C1 LTE Quectel Firmware Upgrade Handler Passes the fota_url Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution9.8 CriticalNew
2026-08-27CVE-2026-76312Splunk Enterprise Below 10.4.1 Exposes Session Material in the HTML Source of Pages Embedding Reports, Letting Unauthenticated Users Who Can Read That Source Access All Report Data and Affect System Integrity9.4 CriticalUpdated
2026-08-27CVE-2026-76311Splunk Enterprise Below 10.4.2 Lets an Unauthenticated User with an Embedded Report Token Download the Search Job Dispatch Archive and Recover Session Material for Full Report Data Access9.4 CriticalUpdated
2026-08-27CVE-2026-76310Splunk Enterprise Below 10.4.2 Lets an Unauthenticated User with an Embedded Report Token Download the Dispatch Archive and Recover Session Tokens That Grant Access to All Data Available to the Report Owner9.4 CriticalUpdated
2026-08-27CVE-2026-72508Red Hat Advanced Cluster Management Multicloud Subscription Component Lets a Namespace-Admin Tenant Abuse a Privileged ServiceAccount via Subscription CRs, Enabling a Confused-Deputy Attack Against Other Cluster Namespaces9.9 CriticalNew
2026-08-27CVE-2026-70398Red Hat Advanced Cluster Management GitOpsCluster Controller Lets an Authenticated Tenant Redirect Spoke Cluster Bearer Tokens to an Attacker-Controlled Endpoint, Enabling a Confused-Deputy Attack9.6 CriticalNew
2026-08-27CVE-2026-61272Oracle JD Edwards EnterpriseOne Tools Web Runtime SEC Component Allows Unauthenticated HTTP Attackers to Compromise the Application, Enabling Full Takeover of the EnterpriseOne Tools Instance9.8 CriticalUpdated
2026-08-26CVE-2026-13206Zyxel WAH7601 Through July 2026 Firmware OS Command Injection Allows Attackers to Execute Arbitrary OS Commands on Affected Devices9.8 CriticalNew
2026-08-25CVE-2026-74688Linux Kernel SCTP Heartbeat ACK Chunk Caches a Transport Without Taking a Reference, Enabling Use-After-Free When That Transport Is Concurrently Removed9.8 CriticalNew
2026-08-25CVE-2026-74588Linux Kernel SCTP Retransmit Path Moves a Gap-Acked Chunk to a New Transport Without Updating the Chunk's Cached Transport Pointer, Enabling Use-After-Free9.8 CriticalNew
2026-08-25CVE-2026-74587Linux Kernel SCTP Teardown Path Frees the Cached Outbound ASCONF Chunk Without Clearing the Cache Pointer, Exposing a Use-After-Free9.8 CriticalNew
2026-08-25CVE-2026-74586Linux Kernel SCTP Fails to Clear new_transport After DEL-IP Peer Removal, Leaving a Dangling Pointer That Subsequent ASCONF Processing Reads9.8 CriticalNew
2026-08-23CVE-2026-68136Linux Kernel GRO Path Performs Double Aggregation of flush-Marked Skbs Because skb_gro_receive_list Lacks the Flush Check Added to skb_gro_receive9.8 CriticalNew
2026-08-22CVE-2026-74677Linux Kernel ipheth USB Ethernet Driver Re-Arms carrier_work on Any Non-Zero URB Status After Disconnect Begins, Causing a Use-After-Free When the Work Item Runs After the Device Structure Is Freed—New
2026-08-20CVE-2026-47865VMware Avi Load Balancer 31.x Through 31.2.2 and 30.x Through 30.2.6 Authentication Bypass Lets Network-Accessible Attackers Reach the Avi Control Plane Without Valid Credentials9.8 CriticalUpdated
2026-08-20CVE-2026-20231Cisco Secure Workload Improper Neutralization of Special Elements Vulnerabilities Allow Authenticated Attackers to Inject Directives into Application Commands, Scoring CVSS 9.99.9 CriticalNew
2026-08-20CVE-2026-20030Cisco Crosswork Multiple Internally Discovered SQL Injection Vulnerabilities Allow Authenticated Attackers to Execute Arbitrary SQL Against the Underlying Database, Scoring CVSS 10.010.0 CriticalNew
2026-08-19CVE-2026-74468Linux Kernel PCH GPIO Driver Acquires a Regular Spinlock in irq_set_type Which Can Be Called From a Non-IRQ Context, Leading to a Deadlock When Interrupts Are Disabled—New
2026-08-19CVE-2026-72392Linux Kernel IPv6 FIB6 Walk Reuses a Stale Position Index Across Hash Chain Batches During a Multi-Batch Netlink Dump, Triggering a NULL Dereference in fib6_walk_continue—New
2026-08-19CVE-2026-68369Linux Kernel USB Gadget Printer Driver printer_read Uses the Same Variable for Requested Copy Size and Bytes Copied, Looping Indefinitely When copy_to_user Fails to Copy Anything—New
2026-08-19CVE-2026-68160Linux Kernel Ceph Cap Handler Reads snap_trace_len from the Wire and Uses It Without Bounds Checking, Enabling a Network-Controlled Out-of-Bounds Read Before Authentication9.8 CriticalNew
2026-08-19CVE-2026-68137Linux Kernel X.25 Drops the x25_list_lock Before Calling sock_hold During Neighbour Teardown, Allowing a Concurrent Free to Race and Produce a Use-After-Free9.8 CriticalNew
2026-08-19CVE-2026-68127Linux Kernel ILA Caches the IPv6 Header Pointer Before pskb_may_pull, Which Can Reallocate the Header on a Non-Linear skb, Producing a Stale Pointer in Checksum Adjust9.8 CriticalNew
2026-08-19CVE-2026-68117Linux Kernel TIPC Socket Creation Error Path Frees the sk While Leaving sock->sk Pointing at the Freed Object, Enabling a Use-After-Free on Subsequent Socket Operations9.8 CriticalNew
2026-08-19CVE-2026-64565Linux Kernel Input ims-pcu Driver ims_pcu_process_data Processes Incoming URB Data Without Checking Whether read_pos Exceeds IMS_PCU_BUF_SIZE, Enabling Heap Buffer Overflow via a Crafted USB Device—New
2026-08-19CVE-2026-64564Linux Kernel SCTP DEL-IP Processing Frees the Transport Cached on the ASCONF Chunk Itself, Triggering Use-After-Free on the Chunk's Own Transport Pointer9.8 CriticalNew
2026-08-18CVE-2026-72585CVE-2026-72585 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review—New
2026-08-17CVE-2026-74287Linux Kernel SCTP ASCONF Chunk Processing Skips Length Validation of Embedded Address Parameters, Allowing Network-Controlled Data to Trigger Out-of-Bounds Reads9.1 CriticalNew
2026-08-17CVE-2026-72568CVE-2026-72568 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review—New
2026-08-17CVE-2026-72540CVE-2026-72540 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review—New
2026-08-17CVE-2026-72293Linux Kernel KVM s390 VSIE Shadow Fault Handler Missing radix_tree_preload Call Can Block Forward Progress Under Memory Pressure During Fault Handling—New
2026-08-17CVE-2026-72265Linux Kernel nvidiafb Driver nvidiafb_probe Error Path Leaks the modelist Memory Allocated by nvidia_set_fbinfo When Subsequent Initialization Steps Fail—New
2026-08-17CVE-2026-71245CVE-2026-71245 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review—New
2026-08-17CVE-2026-68170Linux Kernel MPTCP Cleans Up Subflow backlog References Outside the Lock That Guards the Backlog List, Leaving a Stale skb->sk Pointer After Subflow Close9.8 CriticalNew
2026-08-17CVE-2026-68122Linux Kernel OpenVPN Driver Peer Reference Count Leaks in the TCP Error Path When defer_del_work Is Already Pending, Preventing Timely Peer Cleanup—New
2026-08-17CVE-2026-68092Linux Kernel Uses the jiffies Clocksource Before It Is Registered With the Clocksource Framework, Causing XEN HVM Guests to Experience Long Boot Delays Due to Negative Motion Reporting—New
2026-08-17CVE-2026-68090Linux Kernel debugobjects OOM Disable Path Races Against a Concurrent hrtimer_fixup_assert_init Call, Producing a Spurious stub_timer Callback Warning—New
2026-08-17CVE-2026-64603Linux Kernel Intel HID ACPI Notify Handler Can Run Concurrently on Multiple CPU Cores Since commit e2ffcda16290, Causing Race Conditions in the Hot-Plug Notification Handler—New
2026-08-17CVE-2026-64593Linux Kernel btrfs Trim Path Calls blkdev_issue_discard on a Device Marked Read-Only During Degraded Mount, Dereferencing a NULL Device Pointer and Panicking—New
2026-08-17CVE-2026-28323SolarWinds Web Help Desk SAML 2.0 Authentication Bypass Lets Attackers Authenticate Without Valid Credentials When SAML Is Enabled9.8 CriticalUpdated
2026-08-14CVE-2026-20310Cisco Catalyst SD-WAN Addresses Multiple Internally Discovered Improper Link Resolution Vulnerabilities That Could Allow Local Privilege Escalation via Symlink Following9.1 CriticalNew
2026-08-14CVE-2026-20304Cisco Catalyst SD-WAN Improper Access Control Vulnerabilities Allow Attackers to Perform Unauthorized Actions on Affected Systems, Scoring CVSS 9.99.9 CriticalNew
2026-08-14CVE-2026-20303Cisco Catalyst SD-WAN Improper Input Validation Vulnerabilities Enable Attackers to Cause Unintended System Behavior on Affected Deployments, Scoring CVSS 9.99.9 CriticalNew
2026-08-13CVE-2026-64125Linux Kernel bcmgenet Driver Enabling RBUF EEE and PM Bits Stops RX Traffic When MAC EEE Activates, Causing a Denial-of-Service Condition on Broadcom GENET Hardware9.8 CriticalUpdated
2026-08-12CVE-2026-3141FormGent WordPress Plugin Through 1.9.2 Missing Capability Check on the formgent/responses/attachments REST Endpoint Lets Any Authenticated User Delete Arbitrary Attachments9.1 CriticalNew
2026-08-07CVE-2026-67261Dell Virtual Storage Integrator for VMware vSphere Client IAPI Component Accepts Unauthenticated Remote Input and Passes It to the OS Shell, Enabling Arbitrary Command Execution on the Application Host9.8 CriticalUpdated
2026-08-07CVE-2026-56160Azure Red Hat OpenShift Improper Authorization Lets an Authorized Attacker Escalate Privileges Over the Network9.1 CriticalUpdated
2026-08-07CVE-2026-54489Dell Virtual Storage Integrator for VMware vSphere Client Exposes Sensitive Information to Unauthenticated Remote Attackers, Enabling Information Disclosure and Session Hijacking9.1 CriticalUpdated
2026-08-07CVE-2026-47623NVIDIA Dynamo's Deserialization of Untrusted Data Allows Remote Attackers to Execute Arbitrary Code via a Crafted Serialized Object8.2 HighUpdated
2026-08-07CVE-2026-47618NVIDIA Dynamo's Server-Side Request Forgery Flaw Lets Attackers Use the Inference Server as an HTTP Proxy to Reach Internal Services7.5 HighUpdated
2026-08-07CVE-2026-47617NVIDIA Dynamo Server-Side Request Forgery Flaw Allows Attackers to Make the Service Issue Requests to Arbitrary Hosts, Including Internal Resources7.5 HighUpdated
2026-08-07CVE-2026-47616NVIDIA Dynamo's SSRF Vulnerability Exposes Internal Network Infrastructure to Attackers Who Can Redirect the Server's Outbound HTTP Connections7.5 HighUpdated
2026-08-07CVE-2026-47615NVIDIA Dynamo's Unvalidated URL Handling Lets Attackers Steer the Inference Server's HTTP Requests Toward Internal Hosts and Retrieve Their Responses7.5 HighUpdated
2026-08-07CVE-2026-47614NVIDIA Dynamo Carries an SSRF Flaw That Enables Attackers to Probe Internal Services via the Dynamo Server's Request Mechanism7.5 HighUpdated
2026-08-07CVE-2026-47613NVIDIA Dynamo's Server-Side Request Forgery Vulnerability Allows Attackers to Redirect the AI Inference Server's HTTP Requests Toward Internal or External Targets7.5 HighUpdated
2026-08-07CVE-2026-47612NVIDIA Dynamo's Path Traversal Flaw Allows Attackers to Navigate Outside the Intended Directory and Read or Write Files in Restricted Locations7.5 HighUpdated
2026-08-07CVE-2026-24255NVIDIA Dynamo's Incomplete Input Comparison Allows Attackers to Bypass a Security Check by Supplying Input the Comparison Logic Fails to Fully Evaluate7.5 HighUpdated
2026-08-07CVE-2026-24254NVIDIA Dynamo's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access the AI Inference Platform Without Valid Credentials9.8 CriticalUpdated
2026-08-07CVE-2026-24253NVIDIA Dynamo's Out-of-Bounds Write Allows Remote Attackers to Corrupt Memory and Potentially Execute Arbitrary Code via a Crafted Request8.2 HighUpdated
2026-08-05CVE-2026-18574Check Point Security Management Server and Multi-Domain Management Server Authentication Bypass Lets Unauthenticated Remote Attackers Execute Arbitrary Commands via Management Service Network Access9.3 CriticalNew
2026-08-05CVE-2026-17566pgAdmin 4 Import/Export Data Tool Builds a psql \copy Command by Interpolating User-Supplied SQL into a Jinja Template Without Sufficient Escaping, Enabling Authenticated Attackers to Execute Arbitrary OS Commands9.9 CriticalUpdated
2026-08-04CVE-2026-13325CVE-2026-13325 Rejected by Red Hat Product Security After Concluding the CVE Record Is Not Needed—New
2026-07-30CVE-2026-5433Honeywell Control Network Module Web Interface Allows Command Delimiter Injection, Potentially Enabling Remote Code Execution via the Web Management Interface9.1 CriticalNew
2026-07-30CVE-2026-47876VMware ESX VMXNET3 Virtual Network Adapter Contains an Out-of-Bounds Write Reachable by a Local VM Admin, Potentially Enabling Code Execution on the Underlying Host9.3 CriticalNew
2026-07-30CVE-2026-17191Arista EOS Orchestrator API Component Fails to Validate Input Before Building Backend Queries, Letting Authenticated Users Access Unauthorized Data and Trigger Unintended Outbound Network Connections9.1 CriticalNew
2026-07-30CVE-2022-4994Linux Kernel KVM x86 Fast IN Path Calls emulator_pio_in When __emulator_pio_in Could Be Used Directly, Causing Unnecessary Indirection in the PIO Emulation Path—New
2026-07-28CVE-2026-16812Arista VeloCloud Orchestrator On-Prem Management Plane Executes Injected OS Commands; CISA's July 30th KEV Deadline Has Passed for Covered Entities10.0 CriticalKEV
2026-07-27CVE-2026-63880Linux Kernel amdgpu GEM Op IOCTL Leaks a drm_exec Lock Held at the Time of a kvcalloc Failure in AMDGPU_GEM_OP_GET_MAPPING_INFO, Causing a Lock Imbalance—New
2026-07-27CVE-2026-10517CVE-2026-10517 Retracted by Red Hat Product Security and Upstream Clair/Claircore Maintainer After Confirming the Described PSK Authentication Behavior Is Intentional and Implemented in a Separate Package—New
2026-07-24CVE-2026-31405Linux Kernel DVB-net ULE Extension Handler Uses a Network-Controlled Index into a 255-Entry Table Without Bounds Checking, Enabling Out-of-Bounds Reads and Writes9.8 CriticalUpdated
2026-07-24CVE-2026-28321SolarWinds Serv-U Broken Access Control Allows a Domain Administrator to Read and Write Arbitrary Files, Then Escalate Privileges and Execute Code as Root9.1 CriticalUpdated
2026-07-24CVE-2026-28317SolarWinds Serv-U IDOR Vulnerability Lets a Domain Administrator Reference Objects Outside Their Authorized Scope to Escalate Privileges9.1 CriticalUpdated
2026-07-24CVE-2026-28316SolarWinds Serv-U IDOR Vulnerability Lets a Domain Account With Administrator Access Escalate to System Administrator and Execute Commands as Root9.1 CriticalUpdated
2026-07-24CVE-2026-28314SolarWinds Serv-U IDOR Vulnerability Allows Authenticated Users to Reference Objects Outside Their Authorized Scope, Leading to Account Takeover9.1 CriticalUpdated
2026-07-24CVE-2026-28313SolarWinds Serv-U IDOR Vulnerability Enables SMTP Configuration Hijacking, Allowing an Authenticated User to Take Over Arbitrary Accounts9.1 CriticalUpdated
2026-07-24CVE-2026-28312SolarWinds Serv-U Privilege Escalation Lets a Group's Access Be Elevated to System Administrator, Enabling Code Execution as Root9.1 CriticalUpdated
2026-07-24CVE-2026-28310SolarWinds Serv-U Privilege Escalation Allows a Domain Administrator to Elevate Their User Type to System Administrator9.1 CriticalUpdated
2026-07-24CVE-2026-28309SolarWinds Serv-U Broken Access Control Lets a Domain Administrator Create System Administrator Accounts Without Proper Authorization9.1 CriticalUpdated
2026-07-24CVE-2026-28308SolarWinds Serv-U IDOR Vulnerability Allows a Domain Administrator to Reference Objects Outside Authorized Scope, Leading to Remote Code Execution9.1 CriticalUpdated
2026-07-24CVE-2026-28307SolarWinds Serv-U Privilege Escalation Allows a Domain User Group to Be Elevated to Administrator Access Without Authorization9.1 CriticalUpdated
2026-07-24CVE-2026-28306SolarWinds Serv-U Privilege Escalation Allows a Domain Administrator to Elevate Their Privileges to System Administrator Level9.1 CriticalUpdated
2026-07-24CVE-2026-28305SolarWinds Serv-U IDOR Vulnerability Allows a Domain Administrator with Home Directory Access to Reference Out-of-Scope Objects, Enabling Remote Code Execution as Root9.1 CriticalUpdated
2026-07-24CVE-2026-28304SolarWinds Serv-U Remote Code Execution Vulnerability Allows Arbitrary Code to Run as Root on Affected Linux Installations9.1 CriticalUpdated
2026-07-24CVE-2026-28302SolarWinds Serv-U IDOR Vulnerability Lets Group Administrators Reference Out-of-Scope Objects to Escalate Privileges and Execute Code as Root9.1 CriticalUpdated
2026-07-24CVE-2026-23450Linux Kernel SMC-over-TCP SYN Receive Path Calls sock_hold Then Schedules a tcp_close Work Item Without Synchronizing Against Concurrent Stack Cleanup, Enabling Use-After-Free and Null Dereference9.8 CriticalUpdated
2026-07-24CVE-2025-58349Samsung Exynos L2 Layer Incorrect Handling of LTE MAC Packets Containing Many MAC Control Elements Leads to Uncontrolled Resource Consumption, Affecting Processors from Exynos 980 Through W10009.1 CriticalUpdated
2026-07-24CVE-2025-54328Samsung Exynos Modem SMS Processing Stack-Based Buffer Overflow, Scoring CVSS 10.0 and Affecting Processors from Exynos 980 Through Exynos 2500 and Multiple Modem Generations10.0 CriticalUpdated
2026-07-24CVE-2025-14816Mitsubishi Electric GENESIS64 and ICONICS Suite 10.97.3 and Prior Store Sensitive Information in Cleartext in the GUI, Potentially Allowing Local Attackers to Recover Credentials From Screen Captures or Memory9.3 CriticalNew
2026-07-24CVE-2025-14815Mitsubishi Electric GENESIS64 and ICONICS Suite 10.97.3 and Prior Store Sensitive Information in Cleartext in Persistent Storage, Potentially Allowing Local Attackers to Recover Credentials From Disk9.3 CriticalNew
2026-07-23CVE-2026-54420LiteSpeed's cPanel Plugin Follows Symlinks Across Security Boundaries to Escalate Privileges; CISA's June 18th KEV Remediation Window Has Closed for Covered Entities8.5 HighKEV
2026-07-23CVE-2026-39834SSH Channel Write Path Overflows a Size Counter on Payloads Larger Than 4GB, Causing the Write Loop to Spin Indefinitely Sending Empty Packets Without Making Progress9.1 CriticalUpdated
2026-07-23CVE-2026-10523Ivanti Sentry Before R10.5.2 / R10.6.2 / R10.7.1 Authentication Bypass Lets Unauthenticated Remote Attackers Create Arbitrary Administrative Accounts and Obtain Full Administrative Access9.9 CriticalUpdated
2026-07-23CVE-2025-71211Trend Micro Apex One Management Console Path Traversal in a Second Executable Allows Remote Attackers to Upload Malicious Code and Execute Commands on Affected Installations9.8 CriticalUpdated
2026-07-23CVE-2025-71210Trend Micro Apex One Management Console Path Traversal Allows Remote Attackers to Upload Malicious Code and Execute Commands on Affected Installations9.8 CriticalUpdated
2026-07-22CVE-2025-48595Android Framework's Integer Overflow Enables Code Execution and Local Privilege Escalation; CISA's June 5th KEV Deadline Has Passed8.4 HighKEV
2026-07-22CVE-2024-27892Arista EOS with OpenConfig Configured Fails to Reject Certain gNMI Set Requests That Should Not Execute, Potentially Allowing Unauthorized Configuration Changes on Affected Switches9.6 CriticalNew
2026-07-22CVE-2024-27890Arista EOS with OpenConfig Configured Fails to Reject a Second Class of gNMI Set Requests That Should Not Execute, Potentially Allowing Unauthorized Configuration Changes on Affected Switches9.6 CriticalNew
2026-07-21CVE-2026-9508Suprema BioStar 2 Exposes Backup ZIP Files Without Authentication When Administrator Places the Backup Path Inside the NGINX Webroot, Allowing Database Download and Server Impersonation10.0 CriticalNew
2026-07-16CVE-2023-4346KNX Protocol Connection Authorization Option 1's Overly Restrictive Lockout Mechanism Lets Attackers Purge Devices and Lock Out Authorized Users with a BCU Key; CISA's July 29th KEV Deadline Has Passed7.5 HighKEV
2026-07-15CVE-2026-56155Microsoft Active Directory Federation Services Insufficient Access Control Allows an Authorized Attacker to Elevate Privileges Locally; CISA's July 28th KEV Deadline Has Passed7.8 HighKEV
2026-07-13CVE-2026-4769WAGO System I/O Field Series Activates an Undocumented Diagnostic Interface Without Authentication During Early Boot, Granting Unauthenticated Network Access for a Brief Window at Each Power Cycle9.8 CriticalNew
2026-07-07CVE-2026-0234Cortex XSOAR and XSIAM Microsoft Teams Integration Fails to Verify Cryptographic Signatures, Letting Unauthenticated Users Access and Modify Protected Resources9.1 CriticalUpdated
2026-07-03CVE-2026-50238CVE-2026-50238 Rejected by Red Hat Product Security as Not Required; Underlying Issue Reclassified as a Regular Bug to Be Fixed Through Standard Bug-Fixing Process—New
2026-07-02CVE-2026-53225Linux Kernel SCTP ASCONF Lookup Reads Past the Validated Header Boundary, Exposing Uninitialized Memory to Downstream Address Parameter Processing9.1 CriticalUpdated
2026-06-30CVE-2026-14162Advantech Hospital Queuing Management System Exposes API Documentation to Unauthenticated Remote Attackers via a Specific URL, Facilitating Unauthorized Access to Internal API Details9.8 CriticalNew
2026-06-30CVE-2026-12819Delta Electronics DVP12SE PLC Modbus TCP Service Runs Without Authentication or Access Control, Granting Unauthenticated Network Access to Security-Sensitive PLC Functions9.3 CriticalNew
2026-06-30CVE-2026-12818Delta Electronics DVP12SE PLC Modbus TCP Service Has No Resource Allocation Limits, Making the PLC Susceptible to Denial-of-Service via Request Flooding9.3 CriticalNew
2026-06-26CVE-2026-46893Oracle JD Edwards EnterpriseOne General Ledger E1 Foundation Component Allows Low-Privileged SMB Attackers to Compromise the Application, With Attacks Potentially Spreading to Additional Oracle Products9.9 CriticalUpdated
2026-06-26CVE-2026-46892Oracle JD Edwards EnterpriseOne Human Resources Management Component Allows Unauthenticated HTTP Attackers to Read and Modify Data, Affecting Confidentiality and Integrity9.1 CriticalUpdated
2026-06-22CVE-2026-45177Idira Secrets Manager SaaS Edge Before 1.8 Improper Access Control in Internal Authentication Components Lets Unauthenticated Remote Attackers Access Protected Resources Under Specific Conditions9.1 CriticalUpdated
2026-06-22CVE-2026-39962MISP Before 2.5.36 ApacheAuthenticate Module Passes Unsanitized Username Values Into an LDAP Query, Enabling LDAP Injection by Unauthenticated Users When ApacheAuthenticate Is Enabled9.6 CriticalUpdated
2026-06-22CVE-2026-20266Splunk AI Toolkit Below 5.7.4 Constructs OS Command Strings from Dynamic btool Configuration Parameters Without Sanitization, Letting Admin-Role Users Execute Arbitrary OS Commands on the Host9.1 CriticalUpdated
2026-06-18CVE-2026-46913Oracle JD Edwards EnterpriseOne Tools Installation Security Component Allows Unauthenticated Local Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products9.3 CriticalUpdated
2026-06-18CVE-2026-46911Oracle JD Edwards EnterpriseOne Project Costing Job Costing Component Allows Low-Privileged JDENET Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products9.6 CriticalUpdated
2026-06-18CVE-2026-46909Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated HTTP Attackers Full Takeover of the EnterpriseOne Tools Instance, Scoring CVSS 9.89.8 CriticalUpdated
2026-06-18CVE-2026-46908Oracle JD Edwards EnterpriseOne Accounts Payable Component Allows Low-Privileged HTTP Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products9.9 CriticalUpdated
2026-06-18CVE-2026-46907Oracle JD Edwards EnterpriseOne Order Promising Integration Component Allows Low-Privileged HTTP Attackers to Compromise the Application, With Attacks Potentially Spreading to Additional Oracle Products9.9 CriticalUpdated
2026-06-18CVE-2026-46906Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Low-Privileged HTTP Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products9.6 CriticalUpdated
2026-06-18CVE-2026-46905Oracle JD Edwards EnterpriseOne Tools Web Runtime Security Component Allows Unauthenticated HTTP Attackers Full Takeover of the EnterpriseOne Tools Instance, Scoring CVSS 9.89.8 CriticalUpdated
2026-06-18CVE-2026-46904Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the EnterpriseOne Tools Instance, Scoring CVSS 9.89.8 CriticalUpdated
2026-06-18CVE-2026-46883Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance in Versions 9.2.0.0 Through 9.2.26.2, One of Six Related CVEs9.8 CriticalUpdated
2026-06-18CVE-2026-46882Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance in Versions 9.2.0.0 Through 9.2.26.2, One of Six Related CVEs9.8 CriticalUpdated
2026-06-18CVE-2026-46881Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Third in a Set of Six JDENET-Reachable Takeover Vulnerabilities9.8 CriticalUpdated
2026-06-18CVE-2026-46880Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Fourth in a Set of Six JDENET-Reachable Takeover Vulnerabilities9.8 CriticalUpdated
2026-06-18CVE-2026-46879Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Fifth in a Set of Six JDENET-Reachable Takeover Vulnerabilities9.8 CriticalUpdated
2026-06-18CVE-2026-46878Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Sixth in a Set of Six JDENET-Reachable Takeover Vulnerabilities9.8 CriticalUpdated
2026-06-17CVE-2026-8398Daemon Tools Lite Contains Embedded Malicious Code; CISA Added It to KEV with a May 30th Deadline That Has Since Passed for Covered Entities9.8 CriticalKEV
2026-06-17CVE-2026-8043Ivanti Xtraction Before 2026.2 Lets Authenticated Remote Attackers Supply Arbitrary File Paths to Read Sensitive Files or Write HTML Files into a Web-Accessible Directory9.6 CriticalUpdated
2026-06-17CVE-2026-7473Arista Extensible Operating System Validation Bypass Added to CISA's Known Exploited Vulnerabilities List; Federal Remediation Window for Covered Entities Closed June 23rd5.8 MediumKEV
2026-06-17CVE-2026-48027Nx Console Developer Tooling Published Packages Contain Embedded Malicious Code; CISA's June 10th KEV Mandate for Covered Entities Has Passed9.8 CriticalKEV
2026-06-17CVE-2026-46912Oracle JD Edwards EnterpriseOne Tools Web Runtime Security Component Allows Unauthenticated HTTP Attackers to Compromise the Application, With High Impact on Confidentiality, Integrity, and Availability9.3 CriticalUpdated
2026-06-17CVE-2026-46910Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated HTTP Attackers to Read and Write Data in a Way That Affects Confidentiality and Integrity9.1 CriticalUpdated
2026-06-17CVE-2026-45321TanStack JavaScript Library Suite Added to CISA's Known Exploited Vulnerabilities Catalog; Federal Remediation Deadline for Covered Entities Was June 10th9.6 CriticalKEV
2026-06-17CVE-2026-41512ai-scanner 1.0.0 Through 1.4.0 Remote Code Execution via JavaScript Injection in BrowserAutomation PlaywrightService, Reachable Without Authentication9.9 CriticalUpdated
2026-06-17CVE-2026-35573ChurchCRM Before 6.5.3 Backup Restore Functionality Allows Authenticated Administrators to Upload Files to Arbitrary Paths via Path Traversal, Enabling Remote Code Execution9.1 CriticalUpdated
2026-06-17CVE-2026-20794Intel Data Center Graphics Driver for VMware ESXi Before 2.0.2 Ring 1 Device Driver Buffer Overflow Allows a Privileged System Software Adversary to Escalate Privileges and Execute Code Locally9.3 CriticalNew
2026-06-17CVE-2026-20184Cisco Webex SSO Integration with Control Hub Performed Improper Certificate Validation, Allowing Unauthenticated Attackers to Impersonate Any User Within the Service Prior to Patching9.8 CriticalNew
2026-06-17CVE-2026-20093Cisco Integrated Management Controller Change Password Handler Incorrectly Processes Password Change Requests, Letting Unauthenticated Remote Attackers Bypass Authentication and Gain Admin Access9.8 CriticalNew
2026-06-17CVE-2026-1952Delta Electronics AS320T Denial of Service via Undocumented Subfunction Call, Exploitable Remotely Without Authentication9.8 CriticalUpdated
2026-06-17CVE-2026-1951Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing Directory Name Length Check, Enabling Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-06-17CVE-2026-1950Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing File Name Length Check, Enabling Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-06-17CVE-2026-1949Delta Electronics AS320T GET/PUT Request Handler Incorrectly Calculates Stack Buffer Size, Enabling Unauthenticated Remote Code Execution via the Web Service9.8 CriticalUpdated
2026-06-17CVE-2025-62818Samsung Exynos Modem SMS Processing Out-of-Bounds Write Due to TP-UDHI Header Mismatch, Affecting Processors from Exynos 980 Through Exynos 2500 and Multiple Modem Generations9.8 CriticalUpdated
2026-06-17CVE-2025-52909Samsung Exynos Wi-Fi Driver NL80211 Vendor Command Handler Overflows a Buffer via a Crafted Packet, Affecting Exynos 980 Through W1000 Mobile and Wearable Processors9.8 CriticalUpdated
2026-06-17CVE-2025-52908Samsung Exynos Wi-Fi Driver NL80211 Vendor Command Handler Contains a Second Buffer Overflow Path via a Crafted Packet, Affecting Exynos 980 Through W1000 Mobile and Wearable Processors9.8 CriticalUpdated
2026-06-17CVE-2025-32975Quest KACE Systems Management Appliance's Improper Authentication Allows Attackers to Impersonate Legitimate Users Without Valid Credentials; CISA's May 4th KEV Deadline Has Passed10.0 CriticalKEV

No advisories match this filter.