Critical Infrastructure Vulnerability Intelligence

Advisories for Industrial Defenders

Compiled, structured vulnerability reports for operational technology and industrial control system security teams.

114
KEV Listed
114
Exploited
1
EPSS-Imminent
565
Total Advisories
Filter by Sector
ChemicalCommercialCommunicationsManufacturingDamsDefense IndustrialEmergency SvcsEnergyFinancial SvcsFood & AgGovernmentHealthcareInfo TechnologyNuclearTransportationWater
Filter by Status
FromToShow
UpdatedAdvisory IDTitleCVSSStatus
2026-10-06CVE-2026-94293CVE-2026-942939.8 CriticalUpdated
2026-10-04CVE-2026-86060MikroTik RouterOS's Argument Injection in a Command-Processing Component Allows Unauthenticated Attackers to Execute Arbitrary Commands on the Router; CISA's September 13th KEV Deadline Has Passed9.8 CriticalKEV
2026-10-04CVE-2026-85102Check Point Firewall Certificate Validation Bypass Across Site-to-Site and Remote Access VPN Carries a Lapsed September 25th CISA KEV Requirement for Covered Entities9.8 CriticalKEV
2026-10-04CVE-2026-82078PaperCut NG/MF's Unsafe Reflection Allows Remote Attackers to Manipulate Class Loading and Execute Arbitrary Code on the Print Management Server; CISA's September 14th KEV Deadline Has Passed9.1 CriticalKEV
2026-10-04CVE-2026-67276MikroTik RouterOS SSH Key Comparison Omits RSA Exponent, Letting an Attacker with a Known Modulus Authenticate as Another User8.1 HighEPSS-Imminent
2026-10-03CVE-2026-76504CISA's October 3rd KEV Remediation Deadline for Cisco Catalyst SD-WAN Manager URI Encoding Bypass Has Passed; Covered Entities Still Exposed Are Out of Compliance9.8 CriticalKEV
2026-10-02CVE-2026-86326Moxa MGate MB3170 Series Security Vulnerability Exploitable by Authenticated Admin Network Attackers (CVSS 8.6)8.6 HighUpdated
2026-10-02CVE-2026-86325Moxa MGate MB3170 Series Buffer Overflow Exploitable by Low-Privilege Network Attackers (CVSS 9.4)9.4 CriticalUpdated
2026-10-02CVE-2026-84411MikroTik RouterOS Remote Code Execution Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-10-02CVE-2026-75937Digi International IX Family Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 9.4)9.4 CriticalUpdated
2026-10-02CVE-2026-71452Johnson Controls EasyIO FS32 Command Injection Exploitable by Authenticated Admin Adjacent-Network Attackers (CVSS 7.2)7.2 HighUpdated
2026-10-02CVE-2026-71449Johnson Controls EasyIO FS32 Security Vulnerability Reachable Without Authentication at CVSS 9.39.3 CriticalUpdated
2026-10-02CVE-2026-64893Johnson Controls EasyIO NEO Security Vulnerability Exploitable by Low-Privilege Network (High-Complexity Exploit) Attackers (CVSS 7.3)7.3 HighUpdated
2026-10-02CVE-2026-55396Teledyne FLIR Aware2 Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 8.5)8.5 HighUpdated
2026-10-02CVE-2026-55395Teledyne FLIR Aware2 Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 9.4)9.4 CriticalUpdated
2026-10-02CVE-2026-55393Teledyne FLIR Aware2 Path Traversal Reachable Without Authentication at CVSS 10.010.0 CriticalUpdated
2026-10-02CVE-2026-34494Johnson Controls Neo Series MVP2 Unauthenticated Security Vulnerability over Network (CVSS 7.2)7.2 HighUpdated
2026-10-02CVE-2026-34493Johnson Controls EasyIO FS32 Unauthenticated Security Vulnerability over Network (CVSS 7.2)7.2 HighUpdated
2026-10-02CVE-2026-14984Teledyne FLIR Aware2 Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 9.4)9.4 CriticalUpdated
2026-10-02CVE-2026-14983Teledyne FLIR Aware2 Denial of Service Reachable by Adjacent Unauthenticated Attackers (CVSS 7.1)7.1 HighUpdated
2026-10-02CVE-2026-104286Fortinet FortiMail Unauthenticated Arbitrary File Write via Path Traversal Carries an October 4th CISA KEV Federal Remediation Requirement for Covered Entities9.8 CriticalKEV
2026-10-02CVE-2026-102490Zammad Local Privilege Escalation to Root via Improper Privilege Management Carries an October 5th CISA KEV Federal Deadline for Covered Organizations9.8 CriticalKEV
2026-10-02CVE-2026-102489Zammad Session Fixation Enabling Remote Code Execution as the Zammad User Carries an October 5th CISA KEV Federal Deadline for Covered Organizations9.8 CriticalKEV
2026-10-01CVE-2026-8037Progress LoadMaster's Command Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary OS Commands on the Load Balancer Appliance; CISA's August 10th KEV Deadline Has Passed9.6 CriticalKEV
2026-10-01CVE-2026-48710Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections6.5 MediumKEV
2026-10-01CVE-2025-41753WAGO 0751-9x01 Security Vulnerability Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-09-30CVE-2026-91191CVE-2026-911917.5 HighUpdated
2026-09-30CVE-2026-84409CVE-2026-844097.5 HighUpdated
2026-09-30CVE-2026-79625CVE-2026-796258.1 HighUpdated
2026-09-30CVE-2026-76992CVE-2026-769927.5 HighUpdated
2026-09-30CVE-2026-41940WebPros cPanel and WHM's Login Flow Authentication Bypass Gives Unauthenticated Attackers Unauthorized Access to the Control Panel; CISA's May 3rd KEV Deadline Has Passed9.8 CriticalKEV
2026-09-30CVE-2025-53844CVE-2025-538448.8 HighUpdated
2026-09-30CVE-2025-14272CVE-2025-142728.3 HighUpdated
2026-09-30CVE-2025-13036CVE-2025-130369.2 CriticalUpdated
2026-09-30CVE-2025-12659CVE-2025-126597.8 HighUpdated
2026-09-30CVE-2025-11694CVE-2025-116948.7 HighUpdated
2026-09-29CVE-2026-8066CVE-2026-80669.1 CriticalUpdated
2026-09-29CVE-2026-8065CVE-2026-80659.1 CriticalUpdated
2026-09-29CVE-2026-7395CVE-2026-73958.5 HighUpdated
2026-09-29CVE-2025-7639CVE-2025-76397.1 HighUpdated
2026-09-29CVE-2025-41770CVE-2025-417707.5 HighUpdated
2026-09-29CVE-2025-41769CVE-2025-417699.8 CriticalUpdated
2026-09-29CVE-2025-12012CVE-2025-120129.2 CriticalUpdated
2026-09-29CVE-2025-12011CVE-2025-120119.2 CriticalUpdated
2026-09-29CVE-2025-11698CVE-2025-116989.2 CriticalUpdated
2026-09-26CVE-2026-80152Lantronix SLC/EMG/SLB Web Management Services Endpoint Lets Authenticated Users Inject OS Commands as Root9.1 CriticalUpdated
2026-09-26CVE-2026-80151Lantronix SLC/EMG/SLB Web Management Services Endpoint Contains a Second Command Injection Path Allowing Root Execution by Authenticated Users9.1 CriticalUpdated
2026-09-26CVE-2026-80150Lantronix SLC8000/SLC9000/EMG/SLB882 WebSSH Listener Accepts Unauthenticated Server-Side Request Forgery Targets7.5 HighUpdated
2026-09-26CVE-2026-80149Lantronix WebSSH and WebTelnet Server-Side Request Forgery Lets Unauthenticated Attackers Redirect Device Requests to Internal Hosts8.6 HighUpdated
2026-09-26CVE-2026-80148Lantronix SLC/EMG/SLB882 WebSSH Listener Processes SSRF Probes From Unauthenticated Callers, Enabling Internal Network Mapping8.6 HighUpdated
2026-09-26CVE-2026-80146A Second Lantronix SLC/EMG/SLB Stack Buffer Overflow via Undocumented Interface Allows Authenticated Attackers to Execute Arbitrary Code9.9 CriticalUpdated
2026-09-26CVE-2026-67279MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 286.5 MediumKEV
2026-09-26CVE-2023-45796CVE-2023-457968.1 HighUpdated
2026-09-26CVE-2023-45795CVE-2023-457957.8 HighUpdated
2026-09-25CVE-2026-93616Path Traversal Across Check Point Management and Log Server Infrastructure Missed the September 25th CISA KEV Window; Covered Organizations Are Now Out of Compliance9.8 CriticalKEV
2026-09-25CVE-2026-85046Google Chromium V8's Type Confusion Allows Remote Attackers to Execute Arbitrary Code or Escape the Browser Sandbox via a Crafted Web Page8.8 HighKEV
2026-09-25CVE-2026-81578PaperCut NG/MF's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Perform Administrative Actions Without Logging In; CISA's September 14th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-25CVE-2026-76461Cisco Secure Email Gateway's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Compromise the Email Security Platform9.8 CriticalKEV
2026-09-25CVE-2026-76460Cisco Identity Services Engine's Incorrect Use of Privileged APIs Allows Unauthenticated Remote Attackers to Gain Full Administrative Control; CISA's September 19th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-25CVE-2026-75650Adobe Commerce and Magento's Template Engine Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Server-Side Code on the E-Commerce Platform10.0 CriticalKEV
2026-09-25CVE-2026-93345MikroTik RouterOS Labelled-VPN NLRI Iterator Accepts Below-Minimum Prefix Length in BGP UPDATE, Enabling On-Path Service Crash7.5 HighUpdated
2026-09-25CVE-2026-67281MikroTik RouterOS WebFig Stale Session Pointer Lets Unauthenticated Attackers Read Arbitrary Files7.5 HighUpdated
2026-09-25CVE-2026-67278MikroTik RouterOS Accepts Malformed RSA/PKCS#1 v1.5 Signatures Across TLS and SSH, and Its Trust Store Includes an e=3 Root CA, Letting a Network Attacker Forge Valid Signatures Without the Private Key9.1 CriticalUpdated
2026-09-25CVE-2026-5430WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 2710.0 CriticalKEV
2026-09-25CVE-2026-33824Microsoft Windows IKE Service Extensions' Double Free Enables Unauthenticated Remote Attackers to Execute Arbitrary Code; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-24CVE-2026-22619Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-21662Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-89028MikroTik RouterOS SMB1 Session Setup Handler Accepts Crafted uniPwdLen That Corrupts Adjacent Heap Memory7.5 HighUpdated
2026-09-24CVE-2026-89025CVE-2026-890257.5 HighUpdated
2026-09-24CVE-2026-85880Microsoft Windows' Heap-Based Buffer Overflow Allows Local Attackers to Escalate Privileges by Corrupting Heap Memory; CISA's September 22nd KEV Deadline Has Passed7.8 HighKEV
2026-09-24CVE-2026-80156Lantronix SLC8000/SLC9000/EMG Series Web Upload Path Traversal Lets Authenticated Attackers Write Arbitrary Files9.1 CriticalUpdated
2026-09-24CVE-2026-80155Lantronix SLC8000/SLC9000/EMG Series Web Upload Authentication Bypass Lets Unauthenticated Attackers Write Arbitrary Files10.0 CriticalUpdated
2026-09-24CVE-2026-80154All Lantronix SLC/EMG/SLB Firmware Versions Use Predictable Session Tokens, Letting Unauthenticated Attackers Hijack Active Sessions9.6 CriticalUpdated
2026-09-24CVE-2026-80147Lantronix SLC8000/SLC9000/EMG/SLB Stack Buffer Overflow via Undocumented Interface Allows Authenticated Attackers to Execute Arbitrary Code9.9 CriticalUpdated
2026-09-24CVE-2026-80145Lantronix SLC8000/SLC9000/EMG Series Services Permission Allows Authenticated Command Injection as Root via a Distinct Injection Path9.1 CriticalUpdated
2026-09-24CVE-2026-80144Lantronix SLC/EMG/SLB Undocumented Management Feature Lets Authenticated Attackers Execute Arbitrary Root Shell Commands9.9 CriticalUpdated
2026-09-24CVE-2026-80143A Second Undocumented Lantronix SLC/EMG/SLB Command Path Lets Authenticated Attackers Execute Arbitrary Root Shell Commands9.9 CriticalUpdated
2026-09-24CVE-2026-78312CVE-2026-783129.1 CriticalUpdated
2026-09-24CVE-2026-78311CVE-2026-783118.8 HighUpdated
2026-09-24CVE-2026-78309CVE-2026-783098.8 HighUpdated
2026-09-24CVE-2026-78308CVE-2026-783089.8 CriticalUpdated
2026-09-24CVE-2026-13249Honeywell PD45 Industrial Printer Web Management Interface Accepts Unauthenticated File Uploads That Enable Remote Code Execution9.8 CriticalUpdated
2026-09-24CVE-2026-13248Honeywell PD45 Industrial Printer Intermec Fingerprint Interface Lets Authenticated Admin Accounts Write Arbitrary Files, Enabling Remote Code Execution8.8 HighUpdated
2026-09-23CVE-2026-94127CISA's September 25th Remediation Deadline for F5 BIG-IP APM's OAuth Profile Heap Overflow Has Passed; Covered Entities Running Affected Virtual Servers Are Out of Compliance9.8 CriticalKEV
2026-09-23CVE-2026-93952Arista VeloCloud Orchestrator Input Validation Gap Lets Remote Attackers Reach Privileged APIs; CISA's September 25th KEV Deadline for Covered Entities Has Now Passed10.0 CriticalKEV
2026-09-23CVE-2026-82028absmach magistrala SQL Injection Reachable by Authenticated Remote Attackers with High Severity (CVSS 8.8)8.8 HighUpdated
2026-09-23CVE-2026-73176Advantech EKI-1242IEIMS Firmware V1.06.01 Web Management Interface Command Injection Lets Authenticated Remote Attackers Execute OS Commands8.6 HighUpdated
2026-09-23CVE-2026-73175Advantech EKI-1242EIMS OPC UA Gateway Session Pool Exhaustion Lets Adjacent Unauthenticated Attackers Cause Complete Denial of Service7.1 HighUpdated
2026-09-23CVE-2026-73174Advantech EKI-1242EIMS edgserver Management Protocol Transmits Credentials in Cleartext, Exposing Them to Network-Adjacent Observers8.7 HighUpdated
2026-09-23CVE-2026-73173Advantech EKI-1242EIMS edgserver Management Protocol Exposes Critical Device Management Functions Without Authentication8.8 HighUpdated
2026-09-23CVE-2026-73172Advantech EKI-1242EIMS edgserver Management Service Unauthenticated OS Command Injection Allows Remote Root Execution9.3 CriticalUpdated
2026-09-23CVE-2026-73171Advantech EKI-1242EIMS Backup-Restore Upload Lets Authenticated Remote Attackers Overwrite Arbitrary Device Filesystem Files8.6 HighUpdated
2026-09-23CVE-2026-73170Advantech EKI-1242EIMS Modbus CSV Import Executes Attacker-Controlled Lua Code via Crafted Upload8.6 HighUpdated
2026-09-23CVE-2026-73167Advantech EKI-1242IEIMS Web Management Interface Contains a Second OS Command Injection Path Exploitable by Authenticated Remote Attackers8.6 HighUpdated
2026-09-23CVE-2026-73166Advantech EKI-1242IEIMS Web Management Interface Code Injection Lets Authenticated Remote Attackers Execute Arbitrary OS Commands8.6 HighUpdated
2026-09-23CVE-2026-73165Advantech EKI-1242IEIMS Web Management Interface Has a Third Command Injection Path Exploitable by Authenticated Remote Attackers8.6 HighUpdated
2026-09-23CVE-2026-73164Advantech EKI-1242IEIMS Web Management Interface Contains a Fourth OS Command Injection Path Exploitable by Authenticated Remote Attackers8.6 HighUpdated
2026-09-23CVE-2026-73163Advantech EKI-1242IEIMS Web Management Interface Authenticated Command Injection Allows Remote OS Command Execution via Web Interface8.6 HighUpdated
2026-09-23CVE-2026-53985CVE-2026-539857.5 HighUpdated
2026-09-23CVE-2026-53984CVE-2026-539849.1 CriticalUpdated
2026-09-23CVE-2026-53983Ground Station Orbital-Source Configuration Path Accepts Unauthenticated Socket.IO SSRF Requests, Causing Outbound HTTP Requests to Attacker-Chosen Destinations8.6 HighUpdated
2026-09-23CVE-2026-19535Advantech EKI-1242IEIMS LuCI Administrative Interface CSRF Lets Unauthenticated Attackers Perform Unauthorized State Changes via Logged-In Users8.6 HighUpdated
2026-09-23CVE-2026-19438ABB Mint Workbench I Path Traversal Lets Unauthenticated Remote Attackers Access Sensitive Files (CVSS 7.5)7.5 HighUpdated
2026-09-22CVE-2026-9586Sangoma Switchvox's SQL Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Database Queries and Compromise the Telephony Platform9.8 CriticalKEV
2026-09-22CVE-2026-9198IBM Langflow's Code Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the AI Workflow Platform; CISA's August 7th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-9082Drupal Core's SQL Injection via Specially Crafted Database Abstraction API Requests Enables Privilege Escalation and Remote Code Execution; CISA's May 27th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-86218N-able N-central's Static Code Injection Flaw Allows Remote Attackers to Inject and Execute Arbitrary Code on the RMM Platform Without Prior Authentication9.8 CriticalKEV
2026-09-22CVE-2026-85706GitLab Community and Enterprise Edition's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Read Arbitrary Files on the Server and Fully Compromise the GitLab Instance10.0 CriticalKEV
2026-09-22CVE-2026-83549SonicWall SMA1000 Appliances' OS Command Injection Allows Authenticated Local Attackers to Execute Arbitrary Commands with Root Privileges; CISA's September 5th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-83548SonicWall SMA1000 Appliances' Server-Side Request Forgery Allows Unauthenticated Remote Attackers to Reach Internal Services and Compromise the Secure Mobile Access Gateway; CISA's September 5th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-82329JFrog Artifactory Carries a 9.8 Critical Improper Authentication Flaw That Lets Unauthenticated Attackers Bypass Login Controls on the Artifact Repository9.8 CriticalKEV
2026-09-22CVE-2026-73570Zimbra Collaboration Suite's OS Command Injection Allows Authenticated Attackers to Execute Arbitrary Commands on the Email Server with Elevated Privileges; CISA's August 24th KEV Deadline Has Passed8.9 HighKEV
2026-09-22CVE-2026-72898Metabase's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Achieve Full Platform Compromise; CISA's August 14th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-6973Ivanti Endpoint Manager Mobile's Improper Input Validation Allows a Remotely Authenticated Administrator to Execute Code Remotely; CISA's May 10th KEV Deadline Has Passed7.2 HighKEV
2026-09-22CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock's Use-After-Free Allows a Local Attacker to Gain Elevated Privileges via a Freed Memory Reference; CISA's August 25th KEV Deadline Has Passed7.0 HighKEV
2026-09-22CVE-2026-65400Apple macOS's Improper Authentication Flaw Allows a Network Attacker to Bypass Login Controls and Gain Unauthorized Access to the Operating System; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-64849MLflow's Server-Side Request Forgery Flaw Allows Remote Attackers to Use the ML Platform Server as a Proxy to Access Internal Services and Steal Credentials; CISA's September 2nd KEV Deadline Has Passed9.3 CriticalKEV
2026-09-22CVE-2026-63077JetBrains TeamCity's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the CI/CD Server; CISA's August 8th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-63030WordPress Core Input Interpretation Conflict Exploited in the Wild Carries a Lapsed July 24th CISA KEV Mandate for Covered Entities9.8 CriticalKEV
2026-09-22CVE-2026-60137WordPress Core SQL Injection Enabling Database Access Joins CISA's Known Exploited Vulnerabilities Catalog; Covered Entities Past the August 4th Remediation Deadline5.9 MediumKEV
2026-09-22CVE-2026-60004Gitea's Code Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Repository Platform; CISA's August 28th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-59310Broadcom VMware vCenter's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Access Files Outside the Web Root and Potentially Compromise the Virtualization Platform; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-56291Balbooa Forms Unrestricted File Upload Requiring No Authentication Has Missed CISA's July 13th KEV Remediation Deadline; Covered Entities Are Now Out of Compliance9.8 CriticalKEV
2026-09-22CVE-2026-56290Joomlack Page Builder Lets Unauthenticated Users Upload Arbitrary Files, Enabling Remote Code Execution; CISA's July 10th KEV Mandate Has Lapsed9.8 CriticalKEV
2026-09-22CVE-2026-55040Microsoft SharePoint's Weak Authentication Allows Attackers to Bypass Login Controls and Gain Unauthorized Access to SharePoint Sites and Data; CISA's August 21st KEV Deadline Has Passed9.1 CriticalKEV
2026-09-22CVE-2026-50751Check Point Security Gateway's IKEv1 Key Exchange Flaw Lets Unauthenticated Attackers Establish Remote Access VPN Tunnels Without a Valid Password; CISA's June 11th KEV Deadline Has Passed9.3 CriticalKEV
2026-09-22CVE-2026-48939iCagenda Joomla Event Calendar Extension Accepts Unrestricted File Uploads Without Authentication, Enabling Remote Code Execution; CISA's July 13th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-48908JoomShaper SP Page Builder Accepts Arbitrary File Uploads from Unauthenticated Users; CISA's July 10th KEV Deadline for Covered Entities Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-48907Joomla Content Editor Plugin Exposes Privileged Functions Without Proper Authorization; CISA's June 19th KEV Deadline for Covered Entities Has Lapsed9.8 CriticalKEV
2026-09-22CVE-2026-48558SimpleHelp Accepts Unverified Cryptographic Signatures, Letting Remote Attackers Bypass Authentication; CISA's July 2nd KEV Deadline for Covered Entities Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-48172Any cPanel User Can Escalate Privileges Through LiteSpeed's Plugin; CISA's May 29th KEV Remediation Requirement for Covered Entities Has Expired9.8 CriticalKEV
2026-09-22CVE-2026-46817Oracle E-Business Suite's Improper Privilege Management in Oracle Payments Allows an Unauthenticated Network Attacker to Take Over the Payments Module via HTTP; CISA's July 18th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-45498Microsoft Defender's Unspecified Vulnerability Allows for Denial of Service; CISA's June 3rd KEV Deadline Has Passed4.0 MediumKEV
2026-09-22CVE-2026-45247Mirasvit Full Page Cache Warmer's Deserialization Flaw Lets Unauthenticated Attackers Reach Remote Code Execution via a Crafted PHP Object in the CacheWarmer Cookie; CISA's June 6th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-42897Microsoft Exchange Server's Outlook Web Access Cross-Site Scripting Flaw Executes Arbitrary JavaScript When Interaction Conditions Are Met; CISA's May 29th KEV Deadline Has Passed8.1 HighKEV
2026-09-22CVE-2026-42018JFrog Artifactory's Improper Authentication Allows Network-Based Attackers to Bypass Login Controls and Gain Unauthorized Access to the Artifact Repository7.5 HighKEV
2026-09-22CVE-2026-42016JFrog Artifactory's Incorrect Authorization Allows Authenticated Users to Access Artifacts and Repositories Outside Their Permitted Scope8.1 HighKEV
2026-09-22CVE-2026-41091Microsoft Defender's Link Following Flaw Enables an Authorized Attacker to Elevate Privileges Locally; CISA's June 3rd KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-39987Marimo's Pre-Authentication Flaw Gives Unauthenticated Attackers Shell Access and Arbitrary Command Execution; CISA's May 7th KEV Remediation Requirement for Covered Entities Has Long Lapsed9.8 CriticalKEV
2026-09-22CVE-2026-39808Fortinet FortiSandbox's OS Command Injection Gives Unauthenticated Attackers Remote Code Execution via Crafted HTTP Requests; CISA's July 19th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-35616Fortinet FortiClient EMS Access Control Bypass Entered CISA's Known Exploited Vulnerabilities Catalog with an April 9th Federal Deadline That Has Long Passed9.8 CriticalKEV
2026-09-22CVE-2026-35273Oracle PeopleSoft Enterprise PeopleTools' Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Take Over the Platform; CISA's June 15th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-34926Pre-Authenticated Local Attackers Can Use Relative Path Traversal in Trend Micro Apex One to Modify Key Configuration Data; CISA's June 4th KEV Mandate for Covered Entities Has Lapsed6.7 MediumKEV
2026-09-22CVE-2026-34910Network-Adjacent Attackers Can Inject Commands into Ubiquiti UniFi OS Through an Input Validation Flaw; CISA's June 26th KEV Remediation Window Has Closed for Covered Entities10.0 CriticalKEV
2026-09-22CVE-2026-34909Ubiquiti UniFi OS's Path Traversal Lets a Network-Adjacent Attacker Access Files on the Underlying System and Manipulate an Underlying Account; CISA's June 26th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-34908Ubiquiti UniFi OS's Improper Access Control Lets a Network-Adjacent Attacker Make Unauthorized Changes to the System; CISA's June 26th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-34486Apache Tomcat's Missing Encryption of Sensitive Session Data Exposes Credentials and Tokens to Network Interception; CISA's August 7th KEV Deadline Has Passed7.5 HighKEV
2026-09-22CVE-2026-34197Apache ActiveMQ's Improper Input Validation Enables Code Injection Affecting Both ActiveMQ and Broker Deployments; CISA's April 30th KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2026-33825Microsoft Defender's Insufficient Access Control Allows an Authorized Attacker to Escalate Privileges Locally; CISA's May 6th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-32202Microsoft Windows Shell's Protection Mechanism Failure Allows an Unauthorized Attacker to Perform Spoofing Over the Network; CISA's May 12th KEV Deadline Has Passed4.3 MediumKEV
2026-09-22CVE-2026-31431Linux Kernel Resource Mishandling That Allows Privilege Escalation Carries a Lapsed May 15th CISA KEV Mandate; Covered Entities on Unpatched Kernels Remain Out of Compliance7.8 HighKEV
2026-09-22CVE-2026-28318SolarWinds Serv-U File Transfer Server Resource Exhaustion Exploited in the Wild Carries a Lapsed June 19th CISA KEV Federal Deadline7.5 HighKEV
2026-09-22CVE-2026-25089Fortinet FortiSandbox's Unauthenticated OS Command Injection via Crafted HTTP Requests Covers Cloud and PaaS Deployments; CISA's July 19th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-21962Oracle HTTP Server and WebLogic Server Proxy Plug-in's Improper Access Control Allows Unauthenticated Network Attackers to Fully Compromise the Middleware Platform; CISA's August 27th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-21643Fortinet FortiClient EMS's SQL Injection Allows Unauthenticated Attackers to Execute Unauthorized Code via Crafted HTTP Requests; CISA's April 16th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-20316Cisco Secure Firewall Management Center Hard-Coded Password Lets Attackers Bypass Authentication; CISA's August 1st KEV Deadline for Covered Entities Has Passed5.3 MediumKEV
2026-09-22CVE-2026-20262Authenticated Path Traversal in Cisco Catalyst SD-WAN Manager Lets Remote Attackers Write Files Outside Allowed Directories; CISA's June 29th KEV Deadline Has Passed6.5 MediumKEV
2026-09-22CVE-2026-20253Splunk Enterprise's Missing Authentication on a PostgreSQL Sidecar Service Endpoint Lets Unauthenticated Users Create or Truncate Arbitrary Files; CISA's June 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-20245Cisco Catalyst SD-WAN Manager's Improper Encoding Allows an Authenticated Local Attacker to Execute Arbitrary Commands as Root via a Crafted File; CISA's June 23rd KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-20230Cisco Unified Communications Manager SSRF Flaw Routes Attacker Requests to Internal Resources; CISA's June 28th KEV Deadline for Covered Entities Has Lapsed8.6 HighKEV
2026-09-22CVE-2026-20182Cisco Catalyst SD-WAN Controller and Manager's Authentication Bypass Gives Unauthenticated Remote Attackers Administrative Privileges; CISA's May 17th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-20133Cisco Catalyst SD-WAN Manager Leaks Sensitive Configuration Data to Unauthorized Users; CISA's April 23rd KEV Remediation Requirement Has Expired for Covered Entities6.5 MediumKEV
2026-09-22CVE-2026-20128Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed7.5 HighKEV
2026-09-22CVE-2026-20122Cisco Catalyst SD-WAN Manager Exposes Privileged API Functions to Unauthorized Callers; CISA's April 23rd KEV Remediation Deadline for Covered Entities Has Long Passed5.4 MediumKEV
2026-09-22CVE-2026-20079Cisco Firewall Management Center's Authentication Bypass via an Alternate Path Grants Unauthenticated Remote Attackers Full Administrative Control; CISA's September 12th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-19490Citrix NetScaler's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access Protected Resources Without Valid Credentials9.8 CriticalKEV
2026-09-22CVE-2026-16232Check Point SmartConsole's Improper Authentication Allows Unauthenticated Remote Attackers to Obtain a Login Token and Authenticate with Full Administrative Privileges; CISA's July 25th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-15410SonicWall SMA1000's Code Injection Allows a Remote Authenticated Administrator to Execute Arbitrary OS Commands Under Specific Conditions; CISA's July 17th KEV Deadline Has Passed7.2 HighKEV
2026-09-22CVE-2026-15409SonicWall SMA1000 Secure Access Appliances Accept Forged Server-Side Requests, Enabling Internal Network Pivoting; CISA's July 17th KEV Remediation Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-1340Ivanti Endpoint Manager Mobile's Code Injection Vulnerability Allows Attackers to Achieve Unauthenticated Remote Code Execution; CISA's April 11th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-12569PTC Windchill and FlexPLM's Improper Input Validation Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via Malicious Network Requests; CISA's June 28th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-10520Ivanti Sentry's OS Command Injection Gives Remote Unauthenticated Attackers Root-Level Remote Code Execution; CISA's June 14th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-0300PAN-OS Out-of-Bounds Write Enabling Code Execution Affects Both Palo Alto Networks Firewalls and Siemens RUGGEDCOM APE1808 Industrial Appliances; CISA's May 9th KEV Window Has Closed9.8 CriticalKEV
2026-09-22CVE-2026-0257PAN-OS Authentication Bypass Enabling Unauthorized VPN Tunnels Affects Palo Alto Networks Prisma Access and Siemens RUGGEDCOM APE1808; Now Listed in CISA's Known Exploited Vulnerabilities Catalog9.1 CriticalKEV
2026-09-22CVE-2026-7273Zyxel GS1900 Series Switches' CGI Program Stack-Based Buffer Overflow Allows a LAN-Side Unauthenticated Attacker to Execute OS Commands via Crafted HTTP Requests; CISA's September 24th KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2026-31278Suprema BioStar 2 Active Directory Settings Endpoint Exposes Service Account Credentials in Cleartext to Crafted GET Requests7.7 HighUpdated
2026-09-20CVE-2026-87886Acronis Backup's Incorrect Default Permissions Allow a Local Attacker to Access Backup Files and Configurations Not Intended for Their Account; CISA's September 19th KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-84869ConnectWise ScreenConnect's Improper Privilege Management and Missing Authorization Allow Unauthenticated Attackers to Gain Administrative Control of the Remote Support Platform; CISA's September 14th KEV Deadline Has Passed9.9 CriticalKEV
2026-09-20CVE-2026-81963Windows Update Stack Symbolic Link Following Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighKEV
2026-09-20CVE-2026-67277MikroTik RouterOS's Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Access and Modify Router Configuration; CISA's September 13th KEV Deadline Has Passed8.2 HighKEV
2026-09-20CVE-2026-53362Linux Kernel's Unspecified Flaw Allows Local Attackers to Gain Elevated Privileges on Affected Systems; CISA's August 30th KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-53266Linux Kernel's Out-of-Bounds Write Vulnerability Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 21st KEV Deadline Has Passed8.8 HighKEV
2026-09-20CVE-2026-20349Cisco Secure Firewall ASA and FTD's Heap Inspection Vulnerability Allows Remote Attackers to Extract Sensitive Memory Contents from the Firewall Device; CISA's August 14th KEV Deadline Has Passed8.6 HighKEV
2026-09-20CVE-2026-72530TrueConf Server's Code Injection Vulnerability Allows Remote Attackers to Execute Arbitrary Code on the Video Conferencing Platform; CISA's September 3rd KEV Deadline Has Passed9.0 CriticalKEV
2026-09-20CVE-2026-72529TrueConf Server's Missing Authentication on a Critical Function Allows Unauthenticated Remote Attackers to Access Administrative Capabilities; CISA's August 23rd KEV Deadline Has Passed9.8 CriticalKEV
2026-09-18CVE-2026-87491Google Chromium V8's Out-of-Bounds Write Allows Remote Attackers to Corrupt the JavaScript Engine's Heap and Execute Arbitrary Code via a Crafted Web Page8.8 HighKEV
2026-09-18CVE-2026-59822BerriAI LiteLLM's Improper Authentication Allows Unauthenticated Attackers to Access the AI Model Gateway and Interact with Configured LLM Endpoints Without Credentials8.2 HighKEV
2026-09-18CVE-2026-58704Google Pixel's Improper Authorization Flaw Allows an Attacker with Physical or Local Access to Bypass Permission Controls and Access Protected Device Functions8.8 HighKEV
2026-09-18CVE-2026-49869Kestra OSS's OS Command Injection Flaw Lets Unauthenticated Remote Attackers Execute Arbitrary Commands on the Workflow Orchestration Server with Full System Privileges10.0 CriticalKEV
2026-09-18CVE-2026-80469CVE-2026-804698.3 HighUpdated
2026-09-18CVE-2026-3869CVE-2026-38699.2 CriticalUpdated
2026-09-18CVE-2026-27563Crafted GET Request to the Datastorage API Lets Admin Credentials Trigger Root Command Execution on Pepperl+Fuchs ICE-Series IO-Link Masters7.2 HighUpdated
2026-09-18CVE-2026-27558Operator Access to the IODD File Removal Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Allows Root Command Injection8.8 HighUpdated
2026-09-18CVE-2026-27548Command Injection in the IODD Port Info Endpoint Grants Root Access on Pepperl+Fuchs ICE-Series IO-Link Masters to Any User or Operator Account8.8 HighUpdated
2026-09-18CVE-2026-15579CVE-2026-155798.8 HighUpdated
2026-09-18CVE-2023-5778CVE-2023-57787.5 HighUpdated
2026-09-16CVE-2026-53006CVE-2026-530069.8 CriticalUpdated
2026-09-16CVE-2026-27565Unauthenticated IODD File Upload on Pepperl+Fuchs ICE-Series IO-Link Masters Executes a Root Shell Script That Persists Across Reboots9.8 CriticalUpdated
2026-09-16CVE-2026-27564Pepperl+Fuchs ICE-Series IO-Link Masters Run Injected Root Commands When Admin Credentials Submit a Crafted PUT Request to the Datastorage API7.2 HighUpdated
2026-09-16CVE-2026-27562Admin-Level PUT Requests to the IODD Configuration API Execute Injected Commands as Root on Pepperl+Fuchs ICE-Series IO-Link Masters7.2 HighUpdated
2026-09-16CVE-2026-27561Admin Credentials Enable Root Command Injection via the IODD Config GET API on Pepperl+Fuchs ICE-Series IO-Link Masters7.2 HighUpdated
2026-09-16CVE-2026-27560Admin-Credentialed DELETE Requests to Pepperl+Fuchs ICE-Series IO-Link Masters' Status API Carry Injected Commands Executed at Root7.2 HighUpdated
2026-09-16CVE-2026-27559User Credentials Are Enough to Inject Root-Level Commands via the Status Data API on Pepperl+Fuchs ICE-Series IO-Link Masters8.8 HighUpdated
2026-09-16CVE-2026-27557Unauthenticated Path Traversal in Pepperl+Fuchs ICE-Series IO-Link Masters Exposes the Device's SSH Server Private Keys7.5 HighUpdated
2026-09-16CVE-2026-27556Operator Cookie Enables Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Parameter Save Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27555A Valid User Cookie Triggers Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Port Info Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27554IODD Parameter Save Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Accepts Injected Commands from Operator-Level Accounts, Yielding Root Access8.8 HighUpdated
2026-09-16CVE-2026-27552Pepperl+Fuchs ICE-Series IO-Link Masters Allow Low-Privileged Users to Upload Arbitrary IODD Files via a Missing Authorization Check, Enabling Device Manipulation or Crashes8.1 HighUpdated
2026-09-16CVE-2026-27551User-Level Credentials Give Root Shell on Pepperl+Fuchs ICE-Series IO-Link Masters via the Parameter Management Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27550Operator Credentials Can Inject Root-Level OS Commands via the Field_Shadow_Password Handler on Pepperl+Fuchs ICE-Series IO-Link Masters8.8 HighUpdated
2026-09-16CVE-2026-27549Operator-Level Credentials Suffice to Run Root Commands on Pepperl+Fuchs ICE-Series IO-Link Masters via the IODD Upload Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27547IODD Menu Info Request on Pepperl+Fuchs ICE-Series IO-Link Masters Passes Unvalidated Parameters to Root-Level Commands, Reachable with User-Level Credentials8.8 HighUpdated
2026-09-16CVE-2026-27546The _account_log Function in Pepperl+Fuchs ICE-Series IO-Link Masters Lets Unauthenticated Attackers Log In as Admin Regardless of Account Configuration9.8 CriticalUpdated
2026-09-15CVE-2026-46116CVE-2026-461167.8 HighUpdated
2026-09-14CVE-2026-62647CVE-2026-626477.4 HighUpdated
2026-09-14CVE-2026-34223CVE-2026-342238.2 HighUpdated
2026-09-11CVE-2026-81822CVE-2026-818228.4 HighUpdated
2026-09-11CVE-2026-81821CVE-2026-818218.4 HighUpdated
2026-09-10CVE-2026-62646CVE-2026-626467.4 HighUpdated
2026-09-10CVE-2026-53002CVE-2026-530029.8 CriticalUpdated
2026-09-10CVE-2026-50064CVE-2026-500647.8 HighUpdated
2026-09-10CVE-2026-50063CVE-2026-500637.8 HighUpdated
2026-09-10CVE-2026-50062CVE-2026-500627.8 HighUpdated
2026-09-10CVE-2026-50061CVE-2026-500617.8 HighUpdated
2026-09-10CVE-2026-50060CVE-2026-500607.8 HighUpdated
2026-09-10CVE-2026-50059CVE-2026-500597.8 HighUpdated
2026-09-10CVE-2026-50058CVE-2026-500587.8 HighUpdated
2026-09-09CVE-2026-9854CVE-2026-98547.8 HighUpdated
2026-09-09CVE-2026-9853CVE-2026-98537.8 HighUpdated
2026-09-09CVE-2026-9852CVE-2026-98527.8 HighUpdated
2026-09-09CVE-2026-8044CVE-2026-80448.6 HighUpdated
2026-09-09CVE-2026-77120CVE-2026-771208.7 HighUpdated
2026-09-09CVE-2026-67367CVE-2026-673678.6 HighUpdated
2026-09-09CVE-2026-62649CVE-2026-626497.5 HighUpdated
2026-09-09CVE-2026-19233CVE-2026-192338.6 HighUpdated
2026-09-09CVE-2026-11841CVE-2026-118419.4 CriticalUpdated
2026-09-08CVE-2026-80465CVE-2026-804658.7 HighUpdated
2026-09-08CVE-2026-77393CVE-2026-773938.8 HighUpdated
2026-09-08CVE-2026-64560CVE-2026-645607.8 HighUpdated
2026-09-08CVE-2026-64552CVE-2026-645528.4 HighUpdated
2026-09-08CVE-2026-64545CVE-2026-645457.5 HighUpdated
2026-09-08CVE-2026-64423CVE-2026-644237.8 HighUpdated
2026-09-08CVE-2026-64422CVE-2026-644227.1 HighUpdated
2026-09-08CVE-2026-64413CVE-2026-644137.0 HighUpdated
2026-09-08CVE-2026-64412CVE-2026-644127.1 HighUpdated
2026-09-08CVE-2026-64411CVE-2026-644117.1 HighUpdated
2026-09-08CVE-2026-64375CVE-2026-643757.8 HighUpdated
2026-09-08CVE-2026-64317CVE-2026-643177.1 HighUpdated
2026-09-08CVE-2026-64279CVE-2026-642797.8 HighUpdated
2026-09-08CVE-2026-62650CVE-2026-626508.8 HighUpdated
2026-09-08CVE-2026-62648CVE-2026-626487.5 HighUpdated
2026-09-08CVE-2026-62645CVE-2026-626459.8 CriticalUpdated
2026-09-08CVE-2026-53400CVE-2026-534007.8 HighUpdated
2026-09-08CVE-2026-53275CVE-2026-532758.8 HighUpdated
2026-09-08CVE-2026-53268CVE-2026-532688.2 HighUpdated
2026-09-08CVE-2026-53239CVE-2026-532397.8 HighUpdated
2026-09-08CVE-2026-53223CVE-2026-532237.1 HighUpdated
2026-09-08CVE-2026-53050CVE-2026-530507.8 HighUpdated
2026-09-08CVE-2026-52999CVE-2026-529999.1 CriticalUpdated
2026-09-08CVE-2026-52998CVE-2026-529987.5 HighUpdated
2026-09-08CVE-2026-52986CVE-2026-529869.8 CriticalUpdated
2026-09-08CVE-2026-52946CVE-2026-529467.5 HighUpdated
2026-09-08CVE-2026-52943CVE-2026-529437.8 HighUpdated
2026-09-08CVE-2026-52942CVE-2026-529427.1 HighUpdated
2026-09-08CVE-2026-52933CVE-2026-529337.8 HighUpdated
2026-09-08CVE-2026-52912CVE-2026-529127.8 HighUpdated
2026-09-08CVE-2026-52910CVE-2026-529107.8 HighUpdated
2026-09-08CVE-2026-50093CVE-2026-500939.0 CriticalUpdated
2026-09-08CVE-2026-46323CVE-2026-463237.8 HighUpdated
2026-09-08CVE-2026-46306CVE-2026-463067.5 HighUpdated
2026-09-08CVE-2026-46303CVE-2026-463038.2 HighUpdated
2026-09-08CVE-2026-46300CVE-2026-463007.8 HighUpdated
2026-09-08CVE-2026-46173CVE-2026-461737.8 HighUpdated
2026-09-08CVE-2026-46037CVE-2026-460378.2 HighUpdated
2026-09-08CVE-2026-46033CVE-2026-460337.1 HighUpdated
2026-09-08CVE-2026-46015CVE-2026-460157.8 HighUpdated
2026-09-08CVE-2026-43501CVE-2026-435019.8 CriticalUpdated
2026-09-08CVE-2026-43499CVE-2026-434997.8 HighUpdated
2026-09-08CVE-2026-43303CVE-2026-433037.8 HighUpdated
2026-09-08CVE-2026-43284CVE-2026-432848.8 HighUpdated
2026-09-08CVE-2026-43116CVE-2026-431167.8 HighUpdated
2026-09-08CVE-2026-43071CVE-2026-430719.1 CriticalUpdated
2026-09-08CVE-2026-31700CVE-2026-317007.8 HighUpdated
2026-09-08CVE-2026-31449CVE-2026-314497.8 HighUpdated
2026-09-08CVE-2026-18963CVE-2026-189639.1 CriticalUpdated
2026-09-08CVE-2025-46418CVE-2025-464187.6 HighUpdated
2026-09-03CVE-2026-78319CVE-2026-783199.3 CriticalUpdated
2026-09-03CVE-2026-65423CVE-2026-654238.8 HighUpdated
2026-09-03CVE-2026-63559CVE-2026-635597.5 HighUpdated
2026-09-03CVE-2026-63035CVE-2026-630358.1 HighUpdated
2026-09-03CVE-2026-6071CVE-2026-60717.5 HighUpdated
2026-09-03CVE-2024-7956CVE-2024-79567.6 HighUpdated
2026-09-01CVE-2026-9637CVE-2026-96378.7 HighUpdated
2026-09-01CVE-2026-9634CVE-2026-96347.0 HighUpdated
2026-09-01CVE-2026-9633CVE-2026-96337.0 HighUpdated
2026-09-01CVE-2026-9625CVE-2026-96258.7 HighUpdated
2026-09-01CVE-2026-9624CVE-2026-96248.7 HighUpdated
2026-09-01CVE-2026-9622CVE-2026-96228.7 HighUpdated
2026-09-01CVE-2026-9621CVE-2026-96219.2 CriticalUpdated
2026-09-01CVE-2026-84235CVE-2026-842358.7 HighUpdated
2026-09-01CVE-2026-78317CVE-2026-783178.8 HighUpdated
2026-09-01CVE-2026-78316CVE-2026-783168.8 HighUpdated
2026-09-01CVE-2026-78315CVE-2026-783158.8 HighUpdated
2026-09-01CVE-2026-78314CVE-2026-783148.8 HighUpdated
2026-09-01CVE-2026-35535CVE-2026-355357.4 HighUpdated
2026-09-01CVE-2026-19472CVE-2026-194728.7 HighUpdated
2026-09-01CVE-2026-16675CVE-2026-166758.5 HighUpdated
2026-09-01CVE-2026-13336CVE-2026-133367.3 HighUpdated
2026-09-01CVE-2026-12663CVE-2026-126637.0 HighUpdated
2026-09-01CVE-2025-12768CVE-2025-127688.6 HighUpdated
2026-09-01CVE-2024-7953CVE-2024-79538.7 HighUpdated
2026-09-01CVE-2024-7952CVE-2024-79528.7 HighUpdated
2026-09-01CVE-2024-10085CVE-2024-100858.2 HighUpdated
2026-08-28CVE-2026-66155CVE-2026-661557.6 HighUpdated
2026-08-28CVE-2026-64629CVE-2026-646297.8 HighUpdated
2026-08-28CVE-2026-59701CVE-2026-597017.8 HighUpdated
2026-08-28CVE-2026-59700CVE-2026-597007.8 HighUpdated
2026-08-28CVE-2026-59086CVE-2026-590867.8 HighUpdated
2026-08-28CVE-2026-58115CVE-2026-5811510.0 CriticalUpdated
2026-08-26CVE-2026-71276CVE-2026-712767.1 HighUpdated
2026-08-26CVE-2026-71235CVE-2026-712358.8 HighUpdated
2026-08-25CVE-2026-9128CVE-2026-91287.5 HighUpdated
2026-08-25CVE-2026-9127CVE-2026-91277.5 HighUpdated
2026-08-25CVE-2026-9108CVE-2026-91087.5 HighUpdated
2026-08-24CVE-2026-46333CVE-2026-463337.1 HighUpdated
2026-08-24CVE-2026-21661CVE-2026-216618.4 HighUpdated
2026-08-20CVE-2026-43038CVE-2026-430389.8 CriticalUpdated
2026-08-17CVE-2026-25193CVE-2026-251938.1 HighUpdated
2026-08-11CVE-2026-33390CVE-2026-333908.1 HighUpdated
2026-08-11CVE-2026-31984CVE-2026-319847.5 HighUpdated
2026-08-11CVE-2026-31982CVE-2026-319827.1 HighUpdated
2026-08-11CVE-2026-3014CVE-2026-30149.1 CriticalUpdated
2026-08-11CVE-2026-0287CVE-2026-02877.5 HighUpdated
2026-08-11CVE-2026-0286CVE-2026-02867.2 HighUpdated
2026-08-11CVE-2026-0284CVE-2026-02849.9 CriticalUpdated
2026-08-11CVE-2026-0283CVE-2026-02837.2 HighUpdated
2026-08-11CVE-2026-0281CVE-2026-02817.1 HighUpdated
2026-08-11CVE-2026-0280CVE-2026-02807.2 HighUpdated
2026-08-11CVE-2025-40833CVE-2025-408337.5 HighUpdated
2026-07-31CVE-2026-44106CVE-2026-441067.8 HighUpdated
2026-07-31CVE-2026-44101CVE-2026-441019.8 CriticalUpdated
2026-07-31CVE-2026-44096CVE-2026-440967.8 HighUpdated
2026-07-31CVE-2026-44091CVE-2026-440919.1 CriticalUpdated
2026-07-31CVE-2026-22620CVE-2026-226208.6 HighUpdated
2026-07-30CVE-2026-7849CVE-2026-78499.8 CriticalUpdated
2026-07-30CVE-2026-44108CVE-2026-441089.8 CriticalUpdated
2026-07-30CVE-2026-44107CVE-2026-441077.5 HighUpdated
2026-07-30CVE-2026-44104CVE-2026-441049.8 CriticalUpdated
2026-07-30CVE-2026-44100CVE-2026-441009.4 CriticalUpdated
2026-07-30CVE-2026-44099CVE-2026-440997.8 HighUpdated
2026-07-30CVE-2026-44098CVE-2026-440988.6 HighUpdated
2026-07-30CVE-2026-44097CVE-2026-440977.1 HighUpdated
2026-07-30CVE-2026-44095CVE-2026-440957.8 HighUpdated
2026-07-30CVE-2026-44094CVE-2026-440948.6 HighUpdated
2026-07-30CVE-2026-44093CVE-2026-440937.8 HighUpdated
2026-07-30CVE-2026-44092CVE-2026-440929.1 CriticalUpdated
2026-07-30CVE-2026-44090CVE-2026-440909.8 CriticalUpdated
2026-07-30CVE-2026-14837CVE-2026-148377.8 HighUpdated
2026-07-30CVE-2026-14354CVE-2026-143548.7 HighUpdated
2026-07-30CVE-2026-14169CVE-2026-141698.1 HighUpdated
2026-07-30CVE-2026-14168CVE-2026-141688.8 HighUpdated
2026-07-30CVE-2026-14167CVE-2026-141678.8 HighUpdated
2026-07-30CVE-2026-12927CVE-2026-129278.4 HighUpdated
2026-07-30CVE-2026-0667CVE-2026-06679.3 CriticalUpdated
2026-07-28CVE-2026-16812Arista VeloCloud Orchestrator On-Prem Management Plane Executes Injected OS Commands; CISA's July 30th KEV Deadline Has Passed for Covered Entities10.0 CriticalKEV
2026-07-24CVE-2026-5726CVE-2026-57267.8 HighUpdated
2026-07-24CVE-2026-44469CVE-2026-444697.8 HighUpdated
2026-07-24CVE-2026-44468CVE-2026-444687.8 HighUpdated
2026-07-24CVE-2026-31790CVE-2026-317907.5 HighUpdated
2026-07-24CVE-2026-31789CVE-2026-317899.8 CriticalUpdated
2026-07-24CVE-2026-31403CVE-2026-314037.8 HighUpdated
2026-07-24CVE-2026-31402CVE-2026-314029.8 CriticalUpdated
2026-07-24CVE-2026-31389CVE-2026-313897.8 HighUpdated
2026-07-24CVE-2026-28387CVE-2026-283878.1 HighUpdated
2026-07-24CVE-2026-23457CVE-2026-234578.6 HighUpdated
2026-07-24CVE-2026-23456CVE-2026-234568.2 HighUpdated
2026-07-24CVE-2026-23455CVE-2026-234559.1 CriticalUpdated
2026-07-24CVE-2026-23454CVE-2026-234547.0 HighUpdated
2026-07-24CVE-2026-23434CVE-2026-234347.1 HighUpdated
2026-07-24CVE-2025-15620CVE-2025-156208.6 HighUpdated
2026-07-24CVE-2025-14859CVE-2025-148597.0 HighUpdated
2026-07-24CVE-2024-14034CVE-2024-140349.8 CriticalUpdated
2026-07-24CVE-2024-14033CVE-2024-140337.5 HighUpdated
2026-07-24CVE-2023-7343CVE-2023-73437.8 HighUpdated
2026-07-24CVE-2023-7342CVE-2023-73428.8 HighUpdated
2026-07-24CVE-2022-4987CVE-2022-49877.3 HighUpdated
2026-07-24CVE-2022-4986CVE-2022-49867.5 HighUpdated
2026-07-24CVE-2021-4477CVE-2021-44779.1 CriticalUpdated
2026-07-24CVE-2020-37216CVE-2020-372167.5 HighUpdated
2026-07-23CVE-2026-8047CVE-2026-80477.5 HighUpdated
2026-07-23CVE-2026-8046CVE-2026-80468.1 HighUpdated
2026-07-23CVE-2026-54420LiteSpeed's cPanel Plugin Follows Symlinks Across Security Boundaries to Escalate Privileges; CISA's June 18th KEV Remediation Window Has Closed for Covered Entities8.5 HighKEV
2026-07-23CVE-2026-46749CVE-2026-467497.5 HighUpdated
2026-07-23CVE-2026-46748CVE-2026-467488.8 HighUpdated
2026-07-23CVE-2026-46746CVE-2026-467468.8 HighUpdated
2026-07-23CVE-2026-42542TDengine taosd Integer Underflow in RPC Handler Lets Unauthenticated Attackers Crash the Server With One Packet7.5 HighUpdated
2026-07-23CVE-2026-24349CVE-2026-243497.1 HighUpdated
2026-07-22CVE-2026-41032CVE-2026-410327.5 HighUpdated
2026-07-22CVE-2026-35085CVE-2026-350858.8 HighUpdated
2026-07-22CVE-2026-35084CVE-2026-350848.8 HighUpdated
2026-07-22CVE-2026-35083CVE-2026-350838.8 HighUpdated
2026-07-22CVE-2026-35082CVE-2026-350828.8 HighUpdated
2026-07-22CVE-2026-35081CVE-2026-350818.1 HighUpdated
2026-07-22CVE-2026-35080CVE-2026-350808.1 HighUpdated
2026-07-22CVE-2026-35079CVE-2026-350798.1 HighUpdated
2026-07-22CVE-2026-35078CVE-2026-350788.1 HighUpdated
2026-07-22CVE-2026-35077CVE-2026-350778.1 HighUpdated
2026-07-22CVE-2026-35076CVE-2026-350768.1 HighUpdated
2026-07-22CVE-2026-35075CVE-2026-350759.8 CriticalUpdated
2026-07-22CVE-2026-14448CVE-2026-144487.2 HighUpdated
2026-07-22CVE-2025-14774CVE-2025-147747.4 HighUpdated
2026-07-22CVE-2025-14773CVE-2025-147738.0 HighUpdated
2026-07-22CVE-2025-14772CVE-2025-147728.8 HighUpdated
2026-07-22CVE-2025-14771CVE-2025-147719.9 CriticalUpdated
2026-07-22CVE-2024-14036CVE-2024-140367.5 HighUpdated
2026-07-22CVE-2022-4992CVE-2022-49928.6 HighUpdated
2026-07-22CVE-2021-4481CVE-2021-44818.2 HighUpdated
2026-07-22CVE-2021-4480CVE-2021-44808.2 HighUpdated
2026-07-22CVE-2021-4478CVE-2021-44788.2 HighUpdated
2026-07-22CVE-2019-25722CVE-2019-257227.6 HighUpdated
2026-07-22CVE-2019-25719CVE-2019-257198.6 HighUpdated
2026-07-22CVE-2019-25718CVE-2019-257188.4 HighUpdated
2026-07-21CVE-2018-25237CVE-2018-252379.8 CriticalUpdated
2026-07-21CVE-2018-25236CVE-2018-252369.8 CriticalUpdated
2026-07-21CVE-2017-20238CVE-2017-202387.1 HighUpdated
2026-07-21CVE-2017-20237CVE-2017-202379.8 CriticalUpdated
2026-07-21CVE-2017-20236CVE-2017-202369.8 CriticalUpdated
2026-07-21CVE-2017-20235CVE-2017-202359.1 CriticalUpdated
2026-07-21CVE-2017-20234CVE-2017-202349.8 CriticalUpdated
2026-07-21CVE-2016-15058CVE-2016-150588.1 HighUpdated
2026-07-21CVE-2015-10148CVE-2015-101488.2 HighUpdated
2026-07-15CVE-2026-8314CVE-2026-83147.3 HighUpdated
2026-07-15CVE-2026-8313CVE-2026-83137.3 HighUpdated
2026-07-15CVE-2026-8312CVE-2026-83127.3 HighUpdated
2026-07-15CVE-2026-8085CVE-2026-80857.3 HighUpdated
2026-07-15CVE-2026-56451CVE-2026-5645110.0 CriticalUpdated
2026-07-15CVE-2026-56155Microsoft Active Directory Federation Services Insufficient Access Control Allows an Authorized Attacker to Elevate Privileges Locally; CISA's July 28th KEV Deadline Has Passed7.8 HighKEV
2026-07-15CVE-2026-54429CVE-2026-544297.4 HighUpdated
2026-07-14CVE-2026-9653CVE-2026-96538.7 HighUpdated
2026-07-14CVE-2026-9650CVE-2026-96507.5 HighUpdated
2026-07-14CVE-2026-9636CVE-2026-96368.2 HighUpdated
2026-07-14CVE-2026-9292CVE-2026-92928.4 HighUpdated
2026-07-14CVE-2026-9140CVE-2026-91408.7 HighUpdated
2026-07-14CVE-2026-5928CVE-2026-59287.5 HighUpdated
2026-07-14CVE-2026-5450CVE-2026-54509.8 CriticalUpdated
2026-07-14CVE-2026-5435CVE-2026-54357.3 HighUpdated
2026-07-14CVE-2026-46174CVE-2026-461748.8 HighUpdated
2026-07-14CVE-2026-43057CVE-2026-430577.5 HighUpdated
2026-07-14CVE-2026-43040CVE-2026-430407.1 HighUpdated
2026-07-14CVE-2026-43033CVE-2026-430337.8 HighUpdated
2026-07-14CVE-2026-43030CVE-2026-430307.8 HighUpdated
2026-07-14CVE-2026-43028CVE-2026-430287.1 HighUpdated
2026-07-14CVE-2026-43027CVE-2026-430277.8 HighUpdated
2026-07-14CVE-2026-43025CVE-2026-430257.3 HighUpdated
2026-07-14CVE-2026-43011CVE-2026-430119.8 CriticalUpdated
2026-07-14CVE-2026-31768CVE-2026-317687.8 HighUpdated
2026-07-14CVE-2026-31761CVE-2026-317617.8 HighUpdated
2026-07-14CVE-2026-31682CVE-2026-316829.1 CriticalUpdated
2026-07-14CVE-2026-31680CVE-2026-316807.8 HighUpdated
2026-07-14CVE-2026-31674CVE-2026-316747.1 HighUpdated
2026-07-14CVE-2026-31669CVE-2026-316699.8 CriticalUpdated
2026-07-14CVE-2026-31665CVE-2026-316657.8 HighUpdated
2026-07-14CVE-2026-31649CVE-2026-316499.8 CriticalUpdated
2026-07-14CVE-2026-31563CVE-2026-315637.5 HighUpdated
2026-07-14CVE-2026-31533CVE-2026-315339.8 CriticalUpdated
2026-07-14CVE-2026-31508CVE-2026-315087.8 HighUpdated
2026-07-14CVE-2026-31507CVE-2026-315077.8 HighUpdated
2026-07-14CVE-2026-31504CVE-2026-315047.8 HighUpdated
2026-07-14CVE-2026-31494CVE-2026-314947.8 HighUpdated
2026-07-14CVE-2026-31485CVE-2026-314857.8 HighUpdated
2026-07-14CVE-2026-31469CVE-2026-314697.8 HighUpdated
2026-07-14CVE-2026-31452CVE-2026-314527.8 HighUpdated
2026-07-14CVE-2026-31450CVE-2026-314508.8 HighUpdated
2026-07-14CVE-2026-31448CVE-2026-314489.4 CriticalUpdated
2026-07-14CVE-2026-31447CVE-2026-314477.8 HighUpdated
2026-07-14CVE-2026-31417CVE-2026-314177.5 HighUpdated
2026-07-14CVE-2026-31414CVE-2026-314149.8 CriticalUpdated
2026-07-14CVE-2026-31396CVE-2026-313967.8 HighUpdated
2026-07-14CVE-2026-25789CVE-2026-257897.1 HighUpdated
2026-07-14CVE-2026-25787CVE-2026-257879.1 CriticalUpdated
2026-07-14CVE-2026-25786CVE-2026-257869.1 CriticalUpdated
2026-07-14CVE-2026-23449CVE-2026-234497.8 HighUpdated
2026-07-14CVE-2026-12659CVE-2026-126598.7 HighUpdated
2026-07-14CVE-2026-10714CVE-2026-107148.8 HighUpdated
2026-07-14CVE-2026-0265Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.18.1 HighUpdated
2026-07-14CVE-2026-0264Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.89.8 CriticalUpdated
2026-07-14CVE-2026-0262Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE18087.5 HighUpdated
2026-07-14CVE-2026-0261Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.27.2 HighUpdated
2026-07-14CVE-2026-0258Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.19.1 CriticalUpdated
2026-07-09CVE-2026-54801CVE-2026-548017.2 HighUpdated
2026-07-01CVE-2026-9717CVE-2026-97177.2 HighUpdated
2026-07-01CVE-2026-9716CVE-2026-97167.5 HighUpdated
2026-07-01CVE-2026-14193CVE-2026-141937.5 HighUpdated
2026-07-01CVE-2026-12579CVE-2026-125797.4 HighUpdated
2026-07-01CVE-2026-12577CVE-2026-125778.7 HighUpdated
2026-07-01CVE-2026-12576CVE-2026-125767.5 HighUpdated
2026-07-01CVE-2026-12575CVE-2026-125757.5 HighUpdated
2026-06-30CVE-2026-12578CVE-2026-125788.4 HighUpdated
2026-06-30CVE-2026-10763CVE-2026-107637.0 HighUpdated
2026-06-29CVE-2026-44411CVE-2026-444117.8 HighUpdated
2026-06-29CVE-2026-22925CVE-2026-229257.5 HighUpdated
2026-06-29CVE-2026-22924CVE-2026-229249.1 CriticalUpdated
2026-06-29CVE-2025-40949CVE-2025-409499.1 CriticalUpdated
2026-06-29CVE-2025-40947CVE-2025-409477.5 HighUpdated
2026-06-27CVE-2024-54013CVE-2024-540138.8 HighUpdated
2026-06-24CVE-2026-6866CVE-2026-68667.5 HighUpdated
2026-06-23CVE-2026-10521CVE-2026-105217.2 HighUpdated
2026-06-22CVE-2026-8024CVE-2026-80249.8 CriticalUpdated
2026-06-17CVE-2026-8398Daemon Tools Lite Contains Embedded Malicious Code; CISA Added It to KEV with a May 30th Deadline That Has Since Passed for Covered Entities9.8 CriticalKEV
2026-06-17CVE-2026-7473Arista Extensible Operating System Validation Bypass Added to CISA's Known Exploited Vulnerabilities List; Federal Remediation Window for Covered Entities Closed June 23rd5.8 MediumKEV
2026-06-17CVE-2026-6888CVE-2026-68887.2 HighUpdated
2026-06-17CVE-2026-6865CVE-2026-68657.1 HighUpdated
2026-06-17CVE-2026-6332CVE-2026-63327.5 HighUpdated
2026-06-17CVE-2026-5416CVE-2026-54168.8 HighUpdated
2026-06-17CVE-2026-5387CVE-2026-53879.3 CriticalUpdated
2026-06-17CVE-2026-4827CVE-2026-48278.7 HighUpdated
2026-06-17CVE-2026-48027Nx Console Developer Tooling Published Packages Contain Embedded Malicious Code; CISA's June 10th KEV Mandate for Covered Entities Has Passed9.8 CriticalKEV
2026-06-17CVE-2026-45321TanStack JavaScript Library Suite Added to CISA's Known Exploited Vulnerabilities Catalog; Federal Remediation Deadline for Covered Entities Was June 10th9.6 CriticalKEV
2026-06-17CVE-2026-44412CVE-2026-444127.8 HighUpdated
2026-06-17CVE-2026-41551CVE-2026-415519.1 CriticalUpdated
2026-06-17CVE-2026-40852CVE-2026-408527.2 HighUpdated
2026-06-17CVE-2026-40851CVE-2026-408518.4 HighUpdated
2026-06-17CVE-2026-40850CVE-2026-408507.5 HighUpdated
2026-06-17CVE-2026-40836CVE-2026-408367.1 HighUpdated
2026-06-17CVE-2026-40834CVE-2026-408347.1 HighUpdated
2026-06-17CVE-2026-40833CVE-2026-408337.1 HighUpdated
2026-06-17CVE-2026-40819CVE-2026-408197.5 HighUpdated
2026-06-17CVE-2026-40818CVE-2026-408187.5 HighUpdated
2026-06-17CVE-2026-40817CVE-2026-408177.5 HighUpdated
2026-06-17CVE-2026-40816CVE-2026-408167.5 HighUpdated
2026-06-17CVE-2026-40815CVE-2026-408157.5 HighUpdated
2026-06-17CVE-2026-40814CVE-2026-408147.5 HighUpdated
2026-06-17CVE-2026-40813CVE-2026-408137.5 HighUpdated
2026-06-17CVE-2026-40812CVE-2026-408127.5 HighUpdated
2026-06-17CVE-2026-40811CVE-2026-408117.5 HighUpdated
2026-06-17CVE-2026-40810CVE-2026-408107.5 HighUpdated
2026-06-17CVE-2026-33893CVE-2026-338937.5 HighUpdated
2026-06-17CVE-2026-33892CVE-2026-338927.1 HighUpdated
2026-06-17CVE-2026-33862CVE-2026-338627.3 HighUpdated
2026-06-17CVE-2026-33616CVE-2026-336167.5 HighUpdated
2026-06-17CVE-2026-33615CVE-2026-336159.1 CriticalUpdated
2026-06-17CVE-2026-33614CVE-2026-336147.5 HighUpdated
2026-06-17CVE-2026-33613CVE-2026-336137.2 HighUpdated
2026-06-17CVE-2026-3323CVE-2026-33237.5 HighUpdated
2026-06-17CVE-2026-27668CVE-2026-276688.8 HighUpdated
2026-06-17CVE-2026-27662CVE-2026-276627.7 HighUpdated
2026-06-17CVE-2026-25654CVE-2026-256548.8 HighUpdated
2026-06-17CVE-2026-24032CVE-2026-240327.3 HighUpdated
2026-06-17CVE-2026-1952Delta Electronics AS320T Denial of Service via Undocumented Subfunction Call, Exploitable Remotely Without Authentication9.8 CriticalUpdated
2026-06-17CVE-2026-1951Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing Directory Name Length Check, Enabling Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-06-17CVE-2026-1950Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing File Name Length Check, Enabling Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-06-17CVE-2026-1949Delta Electronics AS320T GET/PUT Request Handler Incorrectly Calculates Stack Buffer Size, Enabling Unauthenticated Remote Code Execution via the Web Service9.8 CriticalUpdated
2026-06-17CVE-2026-11317CVE-2026-113178.7 HighUpdated
2026-06-17CVE-2026-10829CVE-2026-108298.6 HighUpdated
2026-06-17CVE-2026-10825CVE-2026-108257.1 HighUpdated
2026-06-17CVE-2026-0647CVE-2026-06478.8 HighUpdated
2026-06-17CVE-2026-0646CVE-2026-06468.7 HighUpdated
2026-06-17CVE-2025-41670CVE-2025-416707.8 HighUpdated
2026-06-17CVE-2025-41669CVE-2025-416698.8 HighUpdated
2026-06-17CVE-2025-40946CVE-2025-409468.3 HighUpdated
2026-06-17CVE-2025-40899CVE-2025-408998.9 HighUpdated
2026-06-17CVE-2025-40897CVE-2025-408978.1 HighUpdated
2026-06-17CVE-2024-43384CVE-2024-433848.0 HighUpdated
2026-06-17CVE-2024-1490CVE-2024-14907.2 HighUpdated
2026-06-17CVE-2023-3634CVE-2023-36348.8 HighUpdated

No advisories match this filter.