| 2026-10-06 | CVE-2026-94293 | CVE-2026-94293 | 9.8 Critical | Updated |
| 2026-10-04 | CVE-2026-86060 | MikroTik RouterOS's Argument Injection in a Command-Processing Component Allows Unauthenticated Attackers to Execute Arbitrary Commands on the Router; CISA's September 13th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-10-04 | CVE-2026-85102 | Check Point Firewall Certificate Validation Bypass Across Site-to-Site and Remote Access VPN Carries a Lapsed September 25th CISA KEV Requirement for Covered Entities | 9.8 Critical | KEV |
| 2026-10-04 | CVE-2026-82078 | PaperCut NG/MF's Unsafe Reflection Allows Remote Attackers to Manipulate Class Loading and Execute Arbitrary Code on the Print Management Server; CISA's September 14th KEV Deadline Has Passed | 9.1 Critical | KEV |
| 2026-10-04 | CVE-2026-67276 | MikroTik RouterOS SSH Key Comparison Omits RSA Exponent, Letting an Attacker with a Known Modulus Authenticate as Another User | 8.1 High | EPSS-Imminent |
| 2026-10-03 | CVE-2026-76504 | CISA's October 3rd KEV Remediation Deadline for Cisco Catalyst SD-WAN Manager URI Encoding Bypass Has Passed; Covered Entities Still Exposed Are Out of Compliance | 9.8 Critical | KEV |
| 2026-10-02 | CVE-2026-86326 | Moxa MGate MB3170 Series Security Vulnerability Exploitable by Authenticated Admin Network Attackers (CVSS 8.6) | 8.6 High | Updated |
| 2026-10-02 | CVE-2026-86325 | Moxa MGate MB3170 Series Buffer Overflow Exploitable by Low-Privilege Network Attackers (CVSS 9.4) | 9.4 Critical | Updated |
| 2026-10-02 | CVE-2026-84411 | MikroTik RouterOS Remote Code Execution Reachable Without Authentication at CVSS 9.8 | 9.8 Critical | Updated |
| 2026-10-02 | CVE-2026-75937 | Digi International IX Family Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 9.4) | 9.4 Critical | Updated |
| 2026-10-02 | CVE-2026-71452 | Johnson Controls EasyIO FS32 Command Injection Exploitable by Authenticated Admin Adjacent-Network Attackers (CVSS 7.2) | 7.2 High | Updated |
| 2026-10-02 | CVE-2026-71449 | Johnson Controls EasyIO FS32 Security Vulnerability Reachable Without Authentication at CVSS 9.3 | 9.3 Critical | Updated |
| 2026-10-02 | CVE-2026-64893 | Johnson Controls EasyIO NEO Security Vulnerability Exploitable by Low-Privilege Network (High-Complexity Exploit) Attackers (CVSS 7.3) | 7.3 High | Updated |
| 2026-10-02 | CVE-2026-55396 | Teledyne FLIR Aware2 Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 8.5) | 8.5 High | Updated |
| 2026-10-02 | CVE-2026-55395 | Teledyne FLIR Aware2 Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 9.4) | 9.4 Critical | Updated |
| 2026-10-02 | CVE-2026-55393 | Teledyne FLIR Aware2 Path Traversal Reachable Without Authentication at CVSS 10.0 | 10.0 Critical | Updated |
| 2026-10-02 | CVE-2026-34494 | Johnson Controls Neo Series MVP2 Unauthenticated Security Vulnerability over Network (CVSS 7.2) | 7.2 High | Updated |
| 2026-10-02 | CVE-2026-34493 | Johnson Controls EasyIO FS32 Unauthenticated Security Vulnerability over Network (CVSS 7.2) | 7.2 High | Updated |
| 2026-10-02 | CVE-2026-14984 | Teledyne FLIR Aware2 Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 9.4) | 9.4 Critical | Updated |
| 2026-10-02 | CVE-2026-14983 | Teledyne FLIR Aware2 Denial of Service Reachable by Adjacent Unauthenticated Attackers (CVSS 7.1) | 7.1 High | Updated |
| 2026-10-02 | CVE-2026-104286 | Fortinet FortiMail Unauthenticated Arbitrary File Write via Path Traversal Carries an October 4th CISA KEV Federal Remediation Requirement for Covered Entities | 9.8 Critical | KEV |
| 2026-10-02 | CVE-2026-102490 | Zammad Local Privilege Escalation to Root via Improper Privilege Management Carries an October 5th CISA KEV Federal Deadline for Covered Organizations | 9.8 Critical | KEV |
| 2026-10-02 | CVE-2026-102489 | Zammad Session Fixation Enabling Remote Code Execution as the Zammad User Carries an October 5th CISA KEV Federal Deadline for Covered Organizations | 9.8 Critical | KEV |
| 2026-10-01 | CVE-2026-8037 | Progress LoadMaster's Command Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary OS Commands on the Load Balancer Appliance; CISA's August 10th KEV Deadline Has Passed | 9.6 Critical | KEV |
| 2026-10-01 | CVE-2026-48710 | Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections | 6.5 Medium | KEV |
| 2026-10-01 | CVE-2025-41753 | WAGO 0751-9x01 Security Vulnerability Reachable Without Authentication at CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-30 | CVE-2026-91191 | CVE-2026-91191 | 7.5 High | Updated |
| 2026-09-30 | CVE-2026-84409 | CVE-2026-84409 | 7.5 High | Updated |
| 2026-09-30 | CVE-2026-79625 | CVE-2026-79625 | 8.1 High | Updated |
| 2026-09-30 | CVE-2026-76992 | CVE-2026-76992 | 7.5 High | Updated |
| 2026-09-30 | CVE-2026-41940 | WebPros cPanel and WHM's Login Flow Authentication Bypass Gives Unauthenticated Attackers Unauthorized Access to the Control Panel; CISA's May 3rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-30 | CVE-2025-53844 | CVE-2025-53844 | 8.8 High | Updated |
| 2026-09-30 | CVE-2025-14272 | CVE-2025-14272 | 8.3 High | Updated |
| 2026-09-30 | CVE-2025-13036 | CVE-2025-13036 | 9.2 Critical | Updated |
| 2026-09-30 | CVE-2025-12659 | CVE-2025-12659 | 7.8 High | Updated |
| 2026-09-30 | CVE-2025-11694 | CVE-2025-11694 | 8.7 High | Updated |
| 2026-09-29 | CVE-2026-8066 | CVE-2026-8066 | 9.1 Critical | Updated |
| 2026-09-29 | CVE-2026-8065 | CVE-2026-8065 | 9.1 Critical | Updated |
| 2026-09-29 | CVE-2026-7395 | CVE-2026-7395 | 8.5 High | Updated |
| 2026-09-29 | CVE-2025-7639 | CVE-2025-7639 | 7.1 High | Updated |
| 2026-09-29 | CVE-2025-41770 | CVE-2025-41770 | 7.5 High | Updated |
| 2026-09-29 | CVE-2025-41769 | CVE-2025-41769 | 9.8 Critical | Updated |
| 2026-09-29 | CVE-2025-12012 | CVE-2025-12012 | 9.2 Critical | Updated |
| 2026-09-29 | CVE-2025-12011 | CVE-2025-12011 | 9.2 Critical | Updated |
| 2026-09-29 | CVE-2025-11698 | CVE-2025-11698 | 9.2 Critical | Updated |
| 2026-09-26 | CVE-2026-80152 | Lantronix SLC/EMG/SLB Web Management Services Endpoint Lets Authenticated Users Inject OS Commands as Root | 9.1 Critical | Updated |
| 2026-09-26 | CVE-2026-80151 | Lantronix SLC/EMG/SLB Web Management Services Endpoint Contains a Second Command Injection Path Allowing Root Execution by Authenticated Users | 9.1 Critical | Updated |
| 2026-09-26 | CVE-2026-80150 | Lantronix SLC8000/SLC9000/EMG/SLB882 WebSSH Listener Accepts Unauthenticated Server-Side Request Forgery Targets | 7.5 High | Updated |
| 2026-09-26 | CVE-2026-80149 | Lantronix WebSSH and WebTelnet Server-Side Request Forgery Lets Unauthenticated Attackers Redirect Device Requests to Internal Hosts | 8.6 High | Updated |
| 2026-09-26 | CVE-2026-80148 | Lantronix SLC/EMG/SLB882 WebSSH Listener Processes SSRF Probes From Unauthenticated Callers, Enabling Internal Network Mapping | 8.6 High | Updated |
| 2026-09-26 | CVE-2026-80146 | A Second Lantronix SLC/EMG/SLB Stack Buffer Overflow via Undocumented Interface Allows Authenticated Attackers to Execute Arbitrary Code | 9.9 Critical | Updated |
| 2026-09-26 | CVE-2026-67279 | MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 28 | 6.5 Medium | KEV |
| 2026-09-26 | CVE-2023-45796 | CVE-2023-45796 | 8.1 High | Updated |
| 2026-09-26 | CVE-2023-45795 | CVE-2023-45795 | 7.8 High | Updated |
| 2026-09-25 | CVE-2026-93616 | Path Traversal Across Check Point Management and Log Server Infrastructure Missed the September 25th CISA KEV Window; Covered Organizations Are Now Out of Compliance | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-85046 | Google Chromium V8's Type Confusion Allows Remote Attackers to Execute Arbitrary Code or Escape the Browser Sandbox via a Crafted Web Page | 8.8 High | KEV |
| 2026-09-25 | CVE-2026-81578 | PaperCut NG/MF's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Perform Administrative Actions Without Logging In; CISA's September 14th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-76461 | Cisco Secure Email Gateway's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Compromise the Email Security Platform | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-76460 | Cisco Identity Services Engine's Incorrect Use of Privileged APIs Allows Unauthenticated Remote Attackers to Gain Full Administrative Control; CISA's September 19th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-75650 | Adobe Commerce and Magento's Template Engine Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Server-Side Code on the E-Commerce Platform | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-93345 | MikroTik RouterOS Labelled-VPN NLRI Iterator Accepts Below-Minimum Prefix Length in BGP UPDATE, Enabling On-Path Service Crash | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-67281 | MikroTik RouterOS WebFig Stale Session Pointer Lets Unauthenticated Attackers Read Arbitrary Files | 7.5 High | Updated |
| 2026-09-25 | CVE-2026-67278 | MikroTik RouterOS Accepts Malformed RSA/PKCS#1 v1.5 Signatures Across TLS and SSH, and Its Trust Store Includes an e=3 Root CA, Letting a Network Attacker Forge Valid Signatures Without the Private Key | 9.1 Critical | Updated |
| 2026-09-25 | CVE-2026-5430 | WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 27 | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-33824 | Microsoft Windows IKE Service Extensions' Double Free Enables Unauthenticated Remote Attackers to Execute Arbitrary Code; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-24 | CVE-2026-22619 | Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-21662 | Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-89028 | MikroTik RouterOS SMB1 Session Setup Handler Accepts Crafted uniPwdLen That Corrupts Adjacent Heap Memory | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-89025 | CVE-2026-89025 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-85880 | Microsoft Windows' Heap-Based Buffer Overflow Allows Local Attackers to Escalate Privileges by Corrupting Heap Memory; CISA's September 22nd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-24 | CVE-2026-80156 | Lantronix SLC8000/SLC9000/EMG Series Web Upload Path Traversal Lets Authenticated Attackers Write Arbitrary Files | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-80155 | Lantronix SLC8000/SLC9000/EMG Series Web Upload Authentication Bypass Lets Unauthenticated Attackers Write Arbitrary Files | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-80154 | All Lantronix SLC/EMG/SLB Firmware Versions Use Predictable Session Tokens, Letting Unauthenticated Attackers Hijack Active Sessions | 9.6 Critical | Updated |
| 2026-09-24 | CVE-2026-80147 | Lantronix SLC8000/SLC9000/EMG/SLB Stack Buffer Overflow via Undocumented Interface Allows Authenticated Attackers to Execute Arbitrary Code | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-80145 | Lantronix SLC8000/SLC9000/EMG Series Services Permission Allows Authenticated Command Injection as Root via a Distinct Injection Path | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-80144 | Lantronix SLC/EMG/SLB Undocumented Management Feature Lets Authenticated Attackers Execute Arbitrary Root Shell Commands | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-80143 | A Second Undocumented Lantronix SLC/EMG/SLB Command Path Lets Authenticated Attackers Execute Arbitrary Root Shell Commands | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-78312 | CVE-2026-78312 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-78311 | CVE-2026-78311 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-78309 | CVE-2026-78309 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-78308 | CVE-2026-78308 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-13249 | Honeywell PD45 Industrial Printer Web Management Interface Accepts Unauthenticated File Uploads That Enable Remote Code Execution | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-13248 | Honeywell PD45 Industrial Printer Intermec Fingerprint Interface Lets Authenticated Admin Accounts Write Arbitrary Files, Enabling Remote Code Execution | 8.8 High | Updated |
| 2026-09-23 | CVE-2026-94127 | CISA's September 25th Remediation Deadline for F5 BIG-IP APM's OAuth Profile Heap Overflow Has Passed; Covered Entities Running Affected Virtual Servers Are Out of Compliance | 9.8 Critical | KEV |
| 2026-09-23 | CVE-2026-93952 | Arista VeloCloud Orchestrator Input Validation Gap Lets Remote Attackers Reach Privileged APIs; CISA's September 25th KEV Deadline for Covered Entities Has Now Passed | 10.0 Critical | KEV |
| 2026-09-23 | CVE-2026-82028 | absmach magistrala SQL Injection Reachable by Authenticated Remote Attackers with High Severity (CVSS 8.8) | 8.8 High | Updated |
| 2026-09-23 | CVE-2026-73176 | Advantech EKI-1242IEIMS Firmware V1.06.01 Web Management Interface Command Injection Lets Authenticated Remote Attackers Execute OS Commands | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73175 | Advantech EKI-1242EIMS OPC UA Gateway Session Pool Exhaustion Lets Adjacent Unauthenticated Attackers Cause Complete Denial of Service | 7.1 High | Updated |
| 2026-09-23 | CVE-2026-73174 | Advantech EKI-1242EIMS edgserver Management Protocol Transmits Credentials in Cleartext, Exposing Them to Network-Adjacent Observers | 8.7 High | Updated |
| 2026-09-23 | CVE-2026-73173 | Advantech EKI-1242EIMS edgserver Management Protocol Exposes Critical Device Management Functions Without Authentication | 8.8 High | Updated |
| 2026-09-23 | CVE-2026-73172 | Advantech EKI-1242EIMS edgserver Management Service Unauthenticated OS Command Injection Allows Remote Root Execution | 9.3 Critical | Updated |
| 2026-09-23 | CVE-2026-73171 | Advantech EKI-1242EIMS Backup-Restore Upload Lets Authenticated Remote Attackers Overwrite Arbitrary Device Filesystem Files | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73170 | Advantech EKI-1242EIMS Modbus CSV Import Executes Attacker-Controlled Lua Code via Crafted Upload | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73167 | Advantech EKI-1242IEIMS Web Management Interface Contains a Second OS Command Injection Path Exploitable by Authenticated Remote Attackers | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73166 | Advantech EKI-1242IEIMS Web Management Interface Code Injection Lets Authenticated Remote Attackers Execute Arbitrary OS Commands | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73165 | Advantech EKI-1242IEIMS Web Management Interface Has a Third Command Injection Path Exploitable by Authenticated Remote Attackers | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73164 | Advantech EKI-1242IEIMS Web Management Interface Contains a Fourth OS Command Injection Path Exploitable by Authenticated Remote Attackers | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-73163 | Advantech EKI-1242IEIMS Web Management Interface Authenticated Command Injection Allows Remote OS Command Execution via Web Interface | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-53985 | CVE-2026-53985 | 7.5 High | Updated |
| 2026-09-23 | CVE-2026-53984 | CVE-2026-53984 | 9.1 Critical | Updated |
| 2026-09-23 | CVE-2026-53983 | Ground Station Orbital-Source Configuration Path Accepts Unauthenticated Socket.IO SSRF Requests, Causing Outbound HTTP Requests to Attacker-Chosen Destinations | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-19535 | Advantech EKI-1242IEIMS LuCI Administrative Interface CSRF Lets Unauthenticated Attackers Perform Unauthorized State Changes via Logged-In Users | 8.6 High | Updated |
| 2026-09-23 | CVE-2026-19438 | ABB Mint Workbench I Path Traversal Lets Unauthenticated Remote Attackers Access Sensitive Files (CVSS 7.5) | 7.5 High | Updated |
| 2026-09-22 | CVE-2026-9586 | Sangoma Switchvox's SQL Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Database Queries and Compromise the Telephony Platform | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9198 | IBM Langflow's Code Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the AI Workflow Platform; CISA's August 7th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9082 | Drupal Core's SQL Injection via Specially Crafted Database Abstraction API Requests Enables Privilege Escalation and Remote Code Execution; CISA's May 27th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-86218 | N-able N-central's Static Code Injection Flaw Allows Remote Attackers to Inject and Execute Arbitrary Code on the RMM Platform Without Prior Authentication | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-85706 | GitLab Community and Enterprise Edition's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Read Arbitrary Files on the Server and Fully Compromise the GitLab Instance | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-83549 | SonicWall SMA1000 Appliances' OS Command Injection Allows Authenticated Local Attackers to Execute Arbitrary Commands with Root Privileges; CISA's September 5th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-83548 | SonicWall SMA1000 Appliances' Server-Side Request Forgery Allows Unauthenticated Remote Attackers to Reach Internal Services and Compromise the Secure Mobile Access Gateway; CISA's September 5th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-82329 | JFrog Artifactory Carries a 9.8 Critical Improper Authentication Flaw That Lets Unauthenticated Attackers Bypass Login Controls on the Artifact Repository | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-73570 | Zimbra Collaboration Suite's OS Command Injection Allows Authenticated Attackers to Execute Arbitrary Commands on the Email Server with Elevated Privileges; CISA's August 24th KEV Deadline Has Passed | 8.9 High | KEV |
| 2026-09-22 | CVE-2026-72898 | Metabase's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Achieve Full Platform Compromise; CISA's August 14th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-6973 | Ivanti Endpoint Manager Mobile's Improper Input Validation Allows a Remotely Authenticated Administrator to Execute Code Remotely; CISA's May 10th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock's Use-After-Free Allows a Local Attacker to Gain Elevated Privileges via a Freed Memory Reference; CISA's August 25th KEV Deadline Has Passed | 7.0 High | KEV |
| 2026-09-22 | CVE-2026-65400 | Apple macOS's Improper Authentication Flaw Allows a Network Attacker to Bypass Login Controls and Gain Unauthorized Access to the Operating System; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-64849 | MLflow's Server-Side Request Forgery Flaw Allows Remote Attackers to Use the ML Platform Server as a Proxy to Access Internal Services and Steal Credentials; CISA's September 2nd KEV Deadline Has Passed | 9.3 Critical | KEV |
| 2026-09-22 | CVE-2026-63077 | JetBrains TeamCity's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the CI/CD Server; CISA's August 8th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-63030 | WordPress Core Input Interpretation Conflict Exploited in the Wild Carries a Lapsed July 24th CISA KEV Mandate for Covered Entities | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-60137 | WordPress Core SQL Injection Enabling Database Access Joins CISA's Known Exploited Vulnerabilities Catalog; Covered Entities Past the August 4th Remediation Deadline | 5.9 Medium | KEV |
| 2026-09-22 | CVE-2026-60004 | Gitea's Code Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Repository Platform; CISA's August 28th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-59310 | Broadcom VMware vCenter's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Access Files Outside the Web Root and Potentially Compromise the Virtualization Platform; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-56291 | Balbooa Forms Unrestricted File Upload Requiring No Authentication Has Missed CISA's July 13th KEV Remediation Deadline; Covered Entities Are Now Out of Compliance | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-56290 | Joomlack Page Builder Lets Unauthenticated Users Upload Arbitrary Files, Enabling Remote Code Execution; CISA's July 10th KEV Mandate Has Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-55040 | Microsoft SharePoint's Weak Authentication Allows Attackers to Bypass Login Controls and Gain Unauthorized Access to SharePoint Sites and Data; CISA's August 21st KEV Deadline Has Passed | 9.1 Critical | KEV |
| 2026-09-22 | CVE-2026-50751 | Check Point Security Gateway's IKEv1 Key Exchange Flaw Lets Unauthenticated Attackers Establish Remote Access VPN Tunnels Without a Valid Password; CISA's June 11th KEV Deadline Has Passed | 9.3 Critical | KEV |
| 2026-09-22 | CVE-2026-48939 | iCagenda Joomla Event Calendar Extension Accepts Unrestricted File Uploads Without Authentication, Enabling Remote Code Execution; CISA's July 13th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48908 | JoomShaper SP Page Builder Accepts Arbitrary File Uploads from Unauthenticated Users; CISA's July 10th KEV Deadline for Covered Entities Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48907 | Joomla Content Editor Plugin Exposes Privileged Functions Without Proper Authorization; CISA's June 19th KEV Deadline for Covered Entities Has Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48558 | SimpleHelp Accepts Unverified Cryptographic Signatures, Letting Remote Attackers Bypass Authentication; CISA's July 2nd KEV Deadline for Covered Entities Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-48172 | Any cPanel User Can Escalate Privileges Through LiteSpeed's Plugin; CISA's May 29th KEV Remediation Requirement for Covered Entities Has Expired | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-46817 | Oracle E-Business Suite's Improper Privilege Management in Oracle Payments Allows an Unauthenticated Network Attacker to Take Over the Payments Module via HTTP; CISA's July 18th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-45498 | Microsoft Defender's Unspecified Vulnerability Allows for Denial of Service; CISA's June 3rd KEV Deadline Has Passed | 4.0 Medium | KEV |
| 2026-09-22 | CVE-2026-45247 | Mirasvit Full Page Cache Warmer's Deserialization Flaw Lets Unauthenticated Attackers Reach Remote Code Execution via a Crafted PHP Object in the CacheWarmer Cookie; CISA's June 6th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-42897 | Microsoft Exchange Server's Outlook Web Access Cross-Site Scripting Flaw Executes Arbitrary JavaScript When Interaction Conditions Are Met; CISA's May 29th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-22 | CVE-2026-42018 | JFrog Artifactory's Improper Authentication Allows Network-Based Attackers to Bypass Login Controls and Gain Unauthorized Access to the Artifact Repository | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-42016 | JFrog Artifactory's Incorrect Authorization Allows Authenticated Users to Access Artifacts and Repositories Outside Their Permitted Scope | 8.1 High | KEV |
| 2026-09-22 | CVE-2026-41091 | Microsoft Defender's Link Following Flaw Enables an Authorized Attacker to Elevate Privileges Locally; CISA's June 3rd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-39987 | Marimo's Pre-Authentication Flaw Gives Unauthenticated Attackers Shell Access and Arbitrary Command Execution; CISA's May 7th KEV Remediation Requirement for Covered Entities Has Long Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-39808 | Fortinet FortiSandbox's OS Command Injection Gives Unauthenticated Attackers Remote Code Execution via Crafted HTTP Requests; CISA's July 19th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-35616 | Fortinet FortiClient EMS Access Control Bypass Entered CISA's Known Exploited Vulnerabilities Catalog with an April 9th Federal Deadline That Has Long Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools' Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Take Over the Platform; CISA's June 15th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-34926 | Pre-Authenticated Local Attackers Can Use Relative Path Traversal in Trend Micro Apex One to Modify Key Configuration Data; CISA's June 4th KEV Mandate for Covered Entities Has Lapsed | 6.7 Medium | KEV |
| 2026-09-22 | CVE-2026-34910 | Network-Adjacent Attackers Can Inject Commands into Ubiquiti UniFi OS Through an Input Validation Flaw; CISA's June 26th KEV Remediation Window Has Closed for Covered Entities | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34909 | Ubiquiti UniFi OS's Path Traversal Lets a Network-Adjacent Attacker Access Files on the Underlying System and Manipulate an Underlying Account; CISA's June 26th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34908 | Ubiquiti UniFi OS's Improper Access Control Lets a Network-Adjacent Attacker Make Unauthorized Changes to the System; CISA's June 26th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34486 | Apache Tomcat's Missing Encryption of Sensitive Session Data Exposes Credentials and Tokens to Network Interception; CISA's August 7th KEV Deadline Has Passed | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-34197 | Apache ActiveMQ's Improper Input Validation Enables Code Injection Affecting Both ActiveMQ and Broker Deployments; CISA's April 30th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2026-33825 | Microsoft Defender's Insufficient Access Control Allows an Authorized Attacker to Escalate Privileges Locally; CISA's May 6th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-32202 | Microsoft Windows Shell's Protection Mechanism Failure Allows an Unauthorized Attacker to Perform Spoofing Over the Network; CISA's May 12th KEV Deadline Has Passed | 4.3 Medium | KEV |
| 2026-09-22 | CVE-2026-31431 | Linux Kernel Resource Mishandling That Allows Privilege Escalation Carries a Lapsed May 15th CISA KEV Mandate; Covered Entities on Unpatched Kernels Remain Out of Compliance | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-28318 | SolarWinds Serv-U File Transfer Server Resource Exhaustion Exploited in the Wild Carries a Lapsed June 19th CISA KEV Federal Deadline | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-25089 | Fortinet FortiSandbox's Unauthenticated OS Command Injection via Crafted HTTP Requests Covers Cloud and PaaS Deployments; CISA's July 19th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-21962 | Oracle HTTP Server and WebLogic Server Proxy Plug-in's Improper Access Control Allows Unauthenticated Network Attackers to Fully Compromise the Middleware Platform; CISA's August 27th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-21643 | Fortinet FortiClient EMS's SQL Injection Allows Unauthenticated Attackers to Execute Unauthorized Code via Crafted HTTP Requests; CISA's April 16th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-20316 | Cisco Secure Firewall Management Center Hard-Coded Password Lets Attackers Bypass Authentication; CISA's August 1st KEV Deadline for Covered Entities Has Passed | 5.3 Medium | KEV |
| 2026-09-22 | CVE-2026-20262 | Authenticated Path Traversal in Cisco Catalyst SD-WAN Manager Lets Remote Attackers Write Files Outside Allowed Directories; CISA's June 29th KEV Deadline Has Passed | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-20253 | Splunk Enterprise's Missing Authentication on a PostgreSQL Sidecar Service Endpoint Lets Unauthenticated Users Create or Truncate Arbitrary Files; CISA's June 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-20245 | Cisco Catalyst SD-WAN Manager's Improper Encoding Allows an Authenticated Local Attacker to Execute Arbitrary Commands as Root via a Crafted File; CISA's June 23rd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-20230 | Cisco Unified Communications Manager SSRF Flaw Routes Attacker Requests to Internal Resources; CISA's June 28th KEV Deadline for Covered Entities Has Lapsed | 8.6 High | KEV |
| 2026-09-22 | CVE-2026-20182 | Cisco Catalyst SD-WAN Controller and Manager's Authentication Bypass Gives Unauthenticated Remote Attackers Administrative Privileges; CISA's May 17th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Leaks Sensitive Configuration Data to Unauthorized Users; CISA's April 23rd KEV Remediation Requirement Has Expired for Covered Entities | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-20122 | Cisco Catalyst SD-WAN Manager Exposes Privileged API Functions to Unauthorized Callers; CISA's April 23rd KEV Remediation Deadline for Covered Entities Has Long Passed | 5.4 Medium | KEV |
| 2026-09-22 | CVE-2026-20079 | Cisco Firewall Management Center's Authentication Bypass via an Alternate Path Grants Unauthenticated Remote Attackers Full Administrative Control; CISA's September 12th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-19490 | Citrix NetScaler's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access Protected Resources Without Valid Credentials | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-16232 | Check Point SmartConsole's Improper Authentication Allows Unauthenticated Remote Attackers to Obtain a Login Token and Authenticate with Full Administrative Privileges; CISA's July 25th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-15410 | SonicWall SMA1000's Code Injection Allows a Remote Authenticated Administrator to Execute Arbitrary OS Commands Under Specific Conditions; CISA's July 17th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2026-15409 | SonicWall SMA1000 Secure Access Appliances Accept Forged Server-Side Requests, Enabling Internal Network Pivoting; CISA's July 17th KEV Remediation Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-1340 | Ivanti Endpoint Manager Mobile's Code Injection Vulnerability Allows Attackers to Achieve Unauthenticated Remote Code Execution; CISA's April 11th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-12569 | PTC Windchill and FlexPLM's Improper Input Validation Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via Malicious Network Requests; CISA's June 28th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-10520 | Ivanti Sentry's OS Command Injection Gives Remote Unauthenticated Attackers Root-Level Remote Code Execution; CISA's June 14th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-0300 | PAN-OS Out-of-Bounds Write Enabling Code Execution Affects Both Palo Alto Networks Firewalls and Siemens RUGGEDCOM APE1808 Industrial Appliances; CISA's May 9th KEV Window Has Closed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-0257 | PAN-OS Authentication Bypass Enabling Unauthorized VPN Tunnels Affects Palo Alto Networks Prisma Access and Siemens RUGGEDCOM APE1808; Now Listed in CISA's Known Exploited Vulnerabilities Catalog | 9.1 Critical | KEV |
| 2026-09-22 | CVE-2026-7273 | Zyxel GS1900 Series Switches' CGI Program Stack-Based Buffer Overflow Allows a LAN-Side Unauthenticated Attacker to Execute OS Commands via Crafted HTTP Requests; CISA's September 24th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2026-31278 | Suprema BioStar 2 Active Directory Settings Endpoint Exposes Service Account Credentials in Cleartext to Crafted GET Requests | 7.7 High | Updated |
| 2026-09-20 | CVE-2026-87886 | Acronis Backup's Incorrect Default Permissions Allow a Local Attacker to Access Backup Files and Configurations Not Intended for Their Account; CISA's September 19th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-84869 | ConnectWise ScreenConnect's Improper Privilege Management and Missing Authorization Allow Unauthenticated Attackers to Gain Administrative Control of the Remote Support Platform; CISA's September 14th KEV Deadline Has Passed | 9.9 Critical | KEV |
| 2026-09-20 | CVE-2026-81963 | Windows Update Stack Symbolic Link Following Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8) | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-67277 | MikroTik RouterOS's Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Access and Modify Router Configuration; CISA's September 13th KEV Deadline Has Passed | 8.2 High | KEV |
| 2026-09-20 | CVE-2026-53362 | Linux Kernel's Unspecified Flaw Allows Local Attackers to Gain Elevated Privileges on Affected Systems; CISA's August 30th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-53266 | Linux Kernel's Out-of-Bounds Write Vulnerability Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 21st KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-20 | CVE-2026-20349 | Cisco Secure Firewall ASA and FTD's Heap Inspection Vulnerability Allows Remote Attackers to Extract Sensitive Memory Contents from the Firewall Device; CISA's August 14th KEV Deadline Has Passed | 8.6 High | KEV |
| 2026-09-20 | CVE-2026-72530 | TrueConf Server's Code Injection Vulnerability Allows Remote Attackers to Execute Arbitrary Code on the Video Conferencing Platform; CISA's September 3rd KEV Deadline Has Passed | 9.0 Critical | KEV |
| 2026-09-20 | CVE-2026-72529 | TrueConf Server's Missing Authentication on a Critical Function Allows Unauthenticated Remote Attackers to Access Administrative Capabilities; CISA's August 23rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-18 | CVE-2026-87491 | Google Chromium V8's Out-of-Bounds Write Allows Remote Attackers to Corrupt the JavaScript Engine's Heap and Execute Arbitrary Code via a Crafted Web Page | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-59822 | BerriAI LiteLLM's Improper Authentication Allows Unauthenticated Attackers to Access the AI Model Gateway and Interact with Configured LLM Endpoints Without Credentials | 8.2 High | KEV |
| 2026-09-18 | CVE-2026-58704 | Google Pixel's Improper Authorization Flaw Allows an Attacker with Physical or Local Access to Bypass Permission Controls and Access Protected Device Functions | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-49869 | Kestra OSS's OS Command Injection Flaw Lets Unauthenticated Remote Attackers Execute Arbitrary Commands on the Workflow Orchestration Server with Full System Privileges | 10.0 Critical | KEV |
| 2026-09-18 | CVE-2026-80469 | CVE-2026-80469 | 8.3 High | Updated |
| 2026-09-18 | CVE-2026-3869 | CVE-2026-3869 | 9.2 Critical | Updated |
| 2026-09-18 | CVE-2026-27563 | Crafted GET Request to the Datastorage API Lets Admin Credentials Trigger Root Command Execution on Pepperl+Fuchs ICE-Series IO-Link Masters | 7.2 High | Updated |
| 2026-09-18 | CVE-2026-27558 | Operator Access to the IODD File Removal Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Allows Root Command Injection | 8.8 High | Updated |
| 2026-09-18 | CVE-2026-27548 | Command Injection in the IODD Port Info Endpoint Grants Root Access on Pepperl+Fuchs ICE-Series IO-Link Masters to Any User or Operator Account | 8.8 High | Updated |
| 2026-09-18 | CVE-2026-15579 | CVE-2026-15579 | 8.8 High | Updated |
| 2026-09-18 | CVE-2023-5778 | CVE-2023-5778 | 7.5 High | Updated |
| 2026-09-16 | CVE-2026-53006 | CVE-2026-53006 | 9.8 Critical | Updated |
| 2026-09-16 | CVE-2026-27565 | Unauthenticated IODD File Upload on Pepperl+Fuchs ICE-Series IO-Link Masters Executes a Root Shell Script That Persists Across Reboots | 9.8 Critical | Updated |
| 2026-09-16 | CVE-2026-27564 | Pepperl+Fuchs ICE-Series IO-Link Masters Run Injected Root Commands When Admin Credentials Submit a Crafted PUT Request to the Datastorage API | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27562 | Admin-Level PUT Requests to the IODD Configuration API Execute Injected Commands as Root on Pepperl+Fuchs ICE-Series IO-Link Masters | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27561 | Admin Credentials Enable Root Command Injection via the IODD Config GET API on Pepperl+Fuchs ICE-Series IO-Link Masters | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27560 | Admin-Credentialed DELETE Requests to Pepperl+Fuchs ICE-Series IO-Link Masters' Status API Carry Injected Commands Executed at Root | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27559 | User Credentials Are Enough to Inject Root-Level Commands via the Status Data API on Pepperl+Fuchs ICE-Series IO-Link Masters | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27557 | Unauthenticated Path Traversal in Pepperl+Fuchs ICE-Series IO-Link Masters Exposes the Device's SSH Server Private Keys | 7.5 High | Updated |
| 2026-09-16 | CVE-2026-27556 | Operator Cookie Enables Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Parameter Save Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27555 | A Valid User Cookie Triggers Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Port Info Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27554 | IODD Parameter Save Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Accepts Injected Commands from Operator-Level Accounts, Yielding Root Access | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27552 | Pepperl+Fuchs ICE-Series IO-Link Masters Allow Low-Privileged Users to Upload Arbitrary IODD Files via a Missing Authorization Check, Enabling Device Manipulation or Crashes | 8.1 High | Updated |
| 2026-09-16 | CVE-2026-27551 | User-Level Credentials Give Root Shell on Pepperl+Fuchs ICE-Series IO-Link Masters via the Parameter Management Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27550 | Operator Credentials Can Inject Root-Level OS Commands via the Field_Shadow_Password Handler on Pepperl+Fuchs ICE-Series IO-Link Masters | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27549 | Operator-Level Credentials Suffice to Run Root Commands on Pepperl+Fuchs ICE-Series IO-Link Masters via the IODD Upload Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27547 | IODD Menu Info Request on Pepperl+Fuchs ICE-Series IO-Link Masters Passes Unvalidated Parameters to Root-Level Commands, Reachable with User-Level Credentials | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27546 | The _account_log Function in Pepperl+Fuchs ICE-Series IO-Link Masters Lets Unauthenticated Attackers Log In as Admin Regardless of Account Configuration | 9.8 Critical | Updated |
| 2026-09-15 | CVE-2026-46116 | CVE-2026-46116 | 7.8 High | Updated |
| 2026-09-14 | CVE-2026-62647 | CVE-2026-62647 | 7.4 High | Updated |
| 2026-09-14 | CVE-2026-34223 | CVE-2026-34223 | 8.2 High | Updated |
| 2026-09-11 | CVE-2026-81822 | CVE-2026-81822 | 8.4 High | Updated |
| 2026-09-11 | CVE-2026-81821 | CVE-2026-81821 | 8.4 High | Updated |
| 2026-09-10 | CVE-2026-62646 | CVE-2026-62646 | 7.4 High | Updated |
| 2026-09-10 | CVE-2026-53002 | CVE-2026-53002 | 9.8 Critical | Updated |
| 2026-09-10 | CVE-2026-50064 | CVE-2026-50064 | 7.8 High | Updated |
| 2026-09-10 | CVE-2026-50063 | CVE-2026-50063 | 7.8 High | Updated |
| 2026-09-10 | CVE-2026-50062 | CVE-2026-50062 | 7.8 High | Updated |
| 2026-09-10 | CVE-2026-50061 | CVE-2026-50061 | 7.8 High | Updated |
| 2026-09-10 | CVE-2026-50060 | CVE-2026-50060 | 7.8 High | Updated |
| 2026-09-10 | CVE-2026-50059 | CVE-2026-50059 | 7.8 High | Updated |
| 2026-09-10 | CVE-2026-50058 | CVE-2026-50058 | 7.8 High | Updated |
| 2026-09-09 | CVE-2026-9854 | CVE-2026-9854 | 7.8 High | Updated |
| 2026-09-09 | CVE-2026-9853 | CVE-2026-9853 | 7.8 High | Updated |
| 2026-09-09 | CVE-2026-9852 | CVE-2026-9852 | 7.8 High | Updated |
| 2026-09-09 | CVE-2026-8044 | CVE-2026-8044 | 8.6 High | Updated |
| 2026-09-09 | CVE-2026-77120 | CVE-2026-77120 | 8.7 High | Updated |
| 2026-09-09 | CVE-2026-67367 | CVE-2026-67367 | 8.6 High | Updated |
| 2026-09-09 | CVE-2026-62649 | CVE-2026-62649 | 7.5 High | Updated |
| 2026-09-09 | CVE-2026-19233 | CVE-2026-19233 | 8.6 High | Updated |
| 2026-09-09 | CVE-2026-11841 | CVE-2026-11841 | 9.4 Critical | Updated |
| 2026-09-08 | CVE-2026-80465 | CVE-2026-80465 | 8.7 High | Updated |
| 2026-09-08 | CVE-2026-77393 | CVE-2026-77393 | 8.8 High | Updated |
| 2026-09-08 | CVE-2026-64560 | CVE-2026-64560 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-64552 | CVE-2026-64552 | 8.4 High | Updated |
| 2026-09-08 | CVE-2026-64545 | CVE-2026-64545 | 7.5 High | Updated |
| 2026-09-08 | CVE-2026-64423 | CVE-2026-64423 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-64422 | CVE-2026-64422 | 7.1 High | Updated |
| 2026-09-08 | CVE-2026-64413 | CVE-2026-64413 | 7.0 High | Updated |
| 2026-09-08 | CVE-2026-64412 | CVE-2026-64412 | 7.1 High | Updated |
| 2026-09-08 | CVE-2026-64411 | CVE-2026-64411 | 7.1 High | Updated |
| 2026-09-08 | CVE-2026-64375 | CVE-2026-64375 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-64317 | CVE-2026-64317 | 7.1 High | Updated |
| 2026-09-08 | CVE-2026-64279 | CVE-2026-64279 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-62650 | CVE-2026-62650 | 8.8 High | Updated |
| 2026-09-08 | CVE-2026-62648 | CVE-2026-62648 | 7.5 High | Updated |
| 2026-09-08 | CVE-2026-62645 | CVE-2026-62645 | 9.8 Critical | Updated |
| 2026-09-08 | CVE-2026-53400 | CVE-2026-53400 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-53275 | CVE-2026-53275 | 8.8 High | Updated |
| 2026-09-08 | CVE-2026-53268 | CVE-2026-53268 | 8.2 High | Updated |
| 2026-09-08 | CVE-2026-53239 | CVE-2026-53239 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-53223 | CVE-2026-53223 | 7.1 High | Updated |
| 2026-09-08 | CVE-2026-53050 | CVE-2026-53050 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-52999 | CVE-2026-52999 | 9.1 Critical | Updated |
| 2026-09-08 | CVE-2026-52998 | CVE-2026-52998 | 7.5 High | Updated |
| 2026-09-08 | CVE-2026-52986 | CVE-2026-52986 | 9.8 Critical | Updated |
| 2026-09-08 | CVE-2026-52946 | CVE-2026-52946 | 7.5 High | Updated |
| 2026-09-08 | CVE-2026-52943 | CVE-2026-52943 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-52942 | CVE-2026-52942 | 7.1 High | Updated |
| 2026-09-08 | CVE-2026-52933 | CVE-2026-52933 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-52912 | CVE-2026-52912 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-52910 | CVE-2026-52910 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-50093 | CVE-2026-50093 | 9.0 Critical | Updated |
| 2026-09-08 | CVE-2026-46323 | CVE-2026-46323 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-46306 | CVE-2026-46306 | 7.5 High | Updated |
| 2026-09-08 | CVE-2026-46303 | CVE-2026-46303 | 8.2 High | Updated |
| 2026-09-08 | CVE-2026-46300 | CVE-2026-46300 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-46173 | CVE-2026-46173 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-46037 | CVE-2026-46037 | 8.2 High | Updated |
| 2026-09-08 | CVE-2026-46033 | CVE-2026-46033 | 7.1 High | Updated |
| 2026-09-08 | CVE-2026-46015 | CVE-2026-46015 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-43501 | CVE-2026-43501 | 9.8 Critical | Updated |
| 2026-09-08 | CVE-2026-43499 | CVE-2026-43499 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-43303 | CVE-2026-43303 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-43284 | CVE-2026-43284 | 8.8 High | Updated |
| 2026-09-08 | CVE-2026-43116 | CVE-2026-43116 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-43071 | CVE-2026-43071 | 9.1 Critical | Updated |
| 2026-09-08 | CVE-2026-31700 | CVE-2026-31700 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-31449 | CVE-2026-31449 | 7.8 High | Updated |
| 2026-09-08 | CVE-2026-18963 | CVE-2026-18963 | 9.1 Critical | Updated |
| 2026-09-08 | CVE-2025-46418 | CVE-2025-46418 | 7.6 High | Updated |
| 2026-09-03 | CVE-2026-78319 | CVE-2026-78319 | 9.3 Critical | Updated |
| 2026-09-03 | CVE-2026-65423 | CVE-2026-65423 | 8.8 High | Updated |
| 2026-09-03 | CVE-2026-63559 | CVE-2026-63559 | 7.5 High | Updated |
| 2026-09-03 | CVE-2026-63035 | CVE-2026-63035 | 8.1 High | Updated |
| 2026-09-03 | CVE-2026-6071 | CVE-2026-6071 | 7.5 High | Updated |
| 2026-09-03 | CVE-2024-7956 | CVE-2024-7956 | 7.6 High | Updated |
| 2026-09-01 | CVE-2026-9637 | CVE-2026-9637 | 8.7 High | Updated |
| 2026-09-01 | CVE-2026-9634 | CVE-2026-9634 | 7.0 High | Updated |
| 2026-09-01 | CVE-2026-9633 | CVE-2026-9633 | 7.0 High | Updated |
| 2026-09-01 | CVE-2026-9625 | CVE-2026-9625 | 8.7 High | Updated |
| 2026-09-01 | CVE-2026-9624 | CVE-2026-9624 | 8.7 High | Updated |
| 2026-09-01 | CVE-2026-9622 | CVE-2026-9622 | 8.7 High | Updated |
| 2026-09-01 | CVE-2026-9621 | CVE-2026-9621 | 9.2 Critical | Updated |
| 2026-09-01 | CVE-2026-84235 | CVE-2026-84235 | 8.7 High | Updated |
| 2026-09-01 | CVE-2026-78317 | CVE-2026-78317 | 8.8 High | Updated |
| 2026-09-01 | CVE-2026-78316 | CVE-2026-78316 | 8.8 High | Updated |
| 2026-09-01 | CVE-2026-78315 | CVE-2026-78315 | 8.8 High | Updated |
| 2026-09-01 | CVE-2026-78314 | CVE-2026-78314 | 8.8 High | Updated |
| 2026-09-01 | CVE-2026-35535 | CVE-2026-35535 | 7.4 High | Updated |
| 2026-09-01 | CVE-2026-19472 | CVE-2026-19472 | 8.7 High | Updated |
| 2026-09-01 | CVE-2026-16675 | CVE-2026-16675 | 8.5 High | Updated |
| 2026-09-01 | CVE-2026-13336 | CVE-2026-13336 | 7.3 High | Updated |
| 2026-09-01 | CVE-2026-12663 | CVE-2026-12663 | 7.0 High | Updated |
| 2026-09-01 | CVE-2025-12768 | CVE-2025-12768 | 8.6 High | Updated |
| 2026-09-01 | CVE-2024-7953 | CVE-2024-7953 | 8.7 High | Updated |
| 2026-09-01 | CVE-2024-7952 | CVE-2024-7952 | 8.7 High | Updated |
| 2026-09-01 | CVE-2024-10085 | CVE-2024-10085 | 8.2 High | Updated |
| 2026-08-28 | CVE-2026-66155 | CVE-2026-66155 | 7.6 High | Updated |
| 2026-08-28 | CVE-2026-64629 | CVE-2026-64629 | 7.8 High | Updated |
| 2026-08-28 | CVE-2026-59701 | CVE-2026-59701 | 7.8 High | Updated |
| 2026-08-28 | CVE-2026-59700 | CVE-2026-59700 | 7.8 High | Updated |
| 2026-08-28 | CVE-2026-59086 | CVE-2026-59086 | 7.8 High | Updated |
| 2026-08-28 | CVE-2026-58115 | CVE-2026-58115 | 10.0 Critical | Updated |
| 2026-08-26 | CVE-2026-71276 | CVE-2026-71276 | 7.1 High | Updated |
| 2026-08-26 | CVE-2026-71235 | CVE-2026-71235 | 8.8 High | Updated |
| 2026-08-25 | CVE-2026-9128 | CVE-2026-9128 | 7.5 High | Updated |
| 2026-08-25 | CVE-2026-9127 | CVE-2026-9127 | 7.5 High | Updated |
| 2026-08-25 | CVE-2026-9108 | CVE-2026-9108 | 7.5 High | Updated |
| 2026-08-24 | CVE-2026-46333 | CVE-2026-46333 | 7.1 High | Updated |
| 2026-08-24 | CVE-2026-21661 | CVE-2026-21661 | 8.4 High | Updated |
| 2026-08-20 | CVE-2026-43038 | CVE-2026-43038 | 9.8 Critical | Updated |
| 2026-08-17 | CVE-2026-25193 | CVE-2026-25193 | 8.1 High | Updated |
| 2026-08-11 | CVE-2026-33390 | CVE-2026-33390 | 8.1 High | Updated |
| 2026-08-11 | CVE-2026-31984 | CVE-2026-31984 | 7.5 High | Updated |
| 2026-08-11 | CVE-2026-31982 | CVE-2026-31982 | 7.1 High | Updated |
| 2026-08-11 | CVE-2026-3014 | CVE-2026-3014 | 9.1 Critical | Updated |
| 2026-08-11 | CVE-2026-0287 | CVE-2026-0287 | 7.5 High | Updated |
| 2026-08-11 | CVE-2026-0286 | CVE-2026-0286 | 7.2 High | Updated |
| 2026-08-11 | CVE-2026-0284 | CVE-2026-0284 | 9.9 Critical | Updated |
| 2026-08-11 | CVE-2026-0283 | CVE-2026-0283 | 7.2 High | Updated |
| 2026-08-11 | CVE-2026-0281 | CVE-2026-0281 | 7.1 High | Updated |
| 2026-08-11 | CVE-2026-0280 | CVE-2026-0280 | 7.2 High | Updated |
| 2026-08-11 | CVE-2025-40833 | CVE-2025-40833 | 7.5 High | Updated |
| 2026-07-31 | CVE-2026-44106 | CVE-2026-44106 | 7.8 High | Updated |
| 2026-07-31 | CVE-2026-44101 | CVE-2026-44101 | 9.8 Critical | Updated |
| 2026-07-31 | CVE-2026-44096 | CVE-2026-44096 | 7.8 High | Updated |
| 2026-07-31 | CVE-2026-44091 | CVE-2026-44091 | 9.1 Critical | Updated |
| 2026-07-31 | CVE-2026-22620 | CVE-2026-22620 | 8.6 High | Updated |
| 2026-07-30 | CVE-2026-7849 | CVE-2026-7849 | 9.8 Critical | Updated |
| 2026-07-30 | CVE-2026-44108 | CVE-2026-44108 | 9.8 Critical | Updated |
| 2026-07-30 | CVE-2026-44107 | CVE-2026-44107 | 7.5 High | Updated |
| 2026-07-30 | CVE-2026-44104 | CVE-2026-44104 | 9.8 Critical | Updated |
| 2026-07-30 | CVE-2026-44100 | CVE-2026-44100 | 9.4 Critical | Updated |
| 2026-07-30 | CVE-2026-44099 | CVE-2026-44099 | 7.8 High | Updated |
| 2026-07-30 | CVE-2026-44098 | CVE-2026-44098 | 8.6 High | Updated |
| 2026-07-30 | CVE-2026-44097 | CVE-2026-44097 | 7.1 High | Updated |
| 2026-07-30 | CVE-2026-44095 | CVE-2026-44095 | 7.8 High | Updated |
| 2026-07-30 | CVE-2026-44094 | CVE-2026-44094 | 8.6 High | Updated |
| 2026-07-30 | CVE-2026-44093 | CVE-2026-44093 | 7.8 High | Updated |
| 2026-07-30 | CVE-2026-44092 | CVE-2026-44092 | 9.1 Critical | Updated |
| 2026-07-30 | CVE-2026-44090 | CVE-2026-44090 | 9.8 Critical | Updated |
| 2026-07-30 | CVE-2026-14837 | CVE-2026-14837 | 7.8 High | Updated |
| 2026-07-30 | CVE-2026-14354 | CVE-2026-14354 | 8.7 High | Updated |
| 2026-07-30 | CVE-2026-14169 | CVE-2026-14169 | 8.1 High | Updated |
| 2026-07-30 | CVE-2026-14168 | CVE-2026-14168 | 8.8 High | Updated |
| 2026-07-30 | CVE-2026-14167 | CVE-2026-14167 | 8.8 High | Updated |
| 2026-07-30 | CVE-2026-12927 | CVE-2026-12927 | 8.4 High | Updated |
| 2026-07-30 | CVE-2026-0667 | CVE-2026-0667 | 9.3 Critical | Updated |
| 2026-07-28 | CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem Management Plane Executes Injected OS Commands; CISA's July 30th KEV Deadline Has Passed for Covered Entities | 10.0 Critical | KEV |
| 2026-07-24 | CVE-2026-5726 | CVE-2026-5726 | 7.8 High | Updated |
| 2026-07-24 | CVE-2026-44469 | CVE-2026-44469 | 7.8 High | Updated |
| 2026-07-24 | CVE-2026-44468 | CVE-2026-44468 | 7.8 High | Updated |
| 2026-07-24 | CVE-2026-31790 | CVE-2026-31790 | 7.5 High | Updated |
| 2026-07-24 | CVE-2026-31789 | CVE-2026-31789 | 9.8 Critical | Updated |
| 2026-07-24 | CVE-2026-31403 | CVE-2026-31403 | 7.8 High | Updated |
| 2026-07-24 | CVE-2026-31402 | CVE-2026-31402 | 9.8 Critical | Updated |
| 2026-07-24 | CVE-2026-31389 | CVE-2026-31389 | 7.8 High | Updated |
| 2026-07-24 | CVE-2026-28387 | CVE-2026-28387 | 8.1 High | Updated |
| 2026-07-24 | CVE-2026-23457 | CVE-2026-23457 | 8.6 High | Updated |
| 2026-07-24 | CVE-2026-23456 | CVE-2026-23456 | 8.2 High | Updated |
| 2026-07-24 | CVE-2026-23455 | CVE-2026-23455 | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-23454 | CVE-2026-23454 | 7.0 High | Updated |
| 2026-07-24 | CVE-2026-23434 | CVE-2026-23434 | 7.1 High | Updated |
| 2026-07-24 | CVE-2025-15620 | CVE-2025-15620 | 8.6 High | Updated |
| 2026-07-24 | CVE-2025-14859 | CVE-2025-14859 | 7.0 High | Updated |
| 2026-07-24 | CVE-2024-14034 | CVE-2024-14034 | 9.8 Critical | Updated |
| 2026-07-24 | CVE-2024-14033 | CVE-2024-14033 | 7.5 High | Updated |
| 2026-07-24 | CVE-2023-7343 | CVE-2023-7343 | 7.8 High | Updated |
| 2026-07-24 | CVE-2023-7342 | CVE-2023-7342 | 8.8 High | Updated |
| 2026-07-24 | CVE-2022-4987 | CVE-2022-4987 | 7.3 High | Updated |
| 2026-07-24 | CVE-2022-4986 | CVE-2022-4986 | 7.5 High | Updated |
| 2026-07-24 | CVE-2021-4477 | CVE-2021-4477 | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2020-37216 | CVE-2020-37216 | 7.5 High | Updated |
| 2026-07-23 | CVE-2026-8047 | CVE-2026-8047 | 7.5 High | Updated |
| 2026-07-23 | CVE-2026-8046 | CVE-2026-8046 | 8.1 High | Updated |
| 2026-07-23 | CVE-2026-54420 | LiteSpeed's cPanel Plugin Follows Symlinks Across Security Boundaries to Escalate Privileges; CISA's June 18th KEV Remediation Window Has Closed for Covered Entities | 8.5 High | KEV |
| 2026-07-23 | CVE-2026-46749 | CVE-2026-46749 | 7.5 High | Updated |
| 2026-07-23 | CVE-2026-46748 | CVE-2026-46748 | 8.8 High | Updated |
| 2026-07-23 | CVE-2026-46746 | CVE-2026-46746 | 8.8 High | Updated |
| 2026-07-23 | CVE-2026-42542 | TDengine taosd Integer Underflow in RPC Handler Lets Unauthenticated Attackers Crash the Server With One Packet | 7.5 High | Updated |
| 2026-07-23 | CVE-2026-24349 | CVE-2026-24349 | 7.1 High | Updated |
| 2026-07-22 | CVE-2026-41032 | CVE-2026-41032 | 7.5 High | Updated |
| 2026-07-22 | CVE-2026-35085 | CVE-2026-35085 | 8.8 High | Updated |
| 2026-07-22 | CVE-2026-35084 | CVE-2026-35084 | 8.8 High | Updated |
| 2026-07-22 | CVE-2026-35083 | CVE-2026-35083 | 8.8 High | Updated |
| 2026-07-22 | CVE-2026-35082 | CVE-2026-35082 | 8.8 High | Updated |
| 2026-07-22 | CVE-2026-35081 | CVE-2026-35081 | 8.1 High | Updated |
| 2026-07-22 | CVE-2026-35080 | CVE-2026-35080 | 8.1 High | Updated |
| 2026-07-22 | CVE-2026-35079 | CVE-2026-35079 | 8.1 High | Updated |
| 2026-07-22 | CVE-2026-35078 | CVE-2026-35078 | 8.1 High | Updated |
| 2026-07-22 | CVE-2026-35077 | CVE-2026-35077 | 8.1 High | Updated |
| 2026-07-22 | CVE-2026-35076 | CVE-2026-35076 | 8.1 High | Updated |
| 2026-07-22 | CVE-2026-35075 | CVE-2026-35075 | 9.8 Critical | Updated |
| 2026-07-22 | CVE-2026-14448 | CVE-2026-14448 | 7.2 High | Updated |
| 2026-07-22 | CVE-2025-14774 | CVE-2025-14774 | 7.4 High | Updated |
| 2026-07-22 | CVE-2025-14773 | CVE-2025-14773 | 8.0 High | Updated |
| 2026-07-22 | CVE-2025-14772 | CVE-2025-14772 | 8.8 High | Updated |
| 2026-07-22 | CVE-2025-14771 | CVE-2025-14771 | 9.9 Critical | Updated |
| 2026-07-22 | CVE-2024-14036 | CVE-2024-14036 | 7.5 High | Updated |
| 2026-07-22 | CVE-2022-4992 | CVE-2022-4992 | 8.6 High | Updated |
| 2026-07-22 | CVE-2021-4481 | CVE-2021-4481 | 8.2 High | Updated |
| 2026-07-22 | CVE-2021-4480 | CVE-2021-4480 | 8.2 High | Updated |
| 2026-07-22 | CVE-2021-4478 | CVE-2021-4478 | 8.2 High | Updated |
| 2026-07-22 | CVE-2019-25722 | CVE-2019-25722 | 7.6 High | Updated |
| 2026-07-22 | CVE-2019-25719 | CVE-2019-25719 | 8.6 High | Updated |
| 2026-07-22 | CVE-2019-25718 | CVE-2019-25718 | 8.4 High | Updated |
| 2026-07-21 | CVE-2018-25237 | CVE-2018-25237 | 9.8 Critical | Updated |
| 2026-07-21 | CVE-2018-25236 | CVE-2018-25236 | 9.8 Critical | Updated |
| 2026-07-21 | CVE-2017-20238 | CVE-2017-20238 | 7.1 High | Updated |
| 2026-07-21 | CVE-2017-20237 | CVE-2017-20237 | 9.8 Critical | Updated |
| 2026-07-21 | CVE-2017-20236 | CVE-2017-20236 | 9.8 Critical | Updated |
| 2026-07-21 | CVE-2017-20235 | CVE-2017-20235 | 9.1 Critical | Updated |
| 2026-07-21 | CVE-2017-20234 | CVE-2017-20234 | 9.8 Critical | Updated |
| 2026-07-21 | CVE-2016-15058 | CVE-2016-15058 | 8.1 High | Updated |
| 2026-07-21 | CVE-2015-10148 | CVE-2015-10148 | 8.2 High | Updated |
| 2026-07-15 | CVE-2026-8314 | CVE-2026-8314 | 7.3 High | Updated |
| 2026-07-15 | CVE-2026-8313 | CVE-2026-8313 | 7.3 High | Updated |
| 2026-07-15 | CVE-2026-8312 | CVE-2026-8312 | 7.3 High | Updated |
| 2026-07-15 | CVE-2026-8085 | CVE-2026-8085 | 7.3 High | Updated |
| 2026-07-15 | CVE-2026-56451 | CVE-2026-56451 | 10.0 Critical | Updated |
| 2026-07-15 | CVE-2026-56155 | Microsoft Active Directory Federation Services Insufficient Access Control Allows an Authorized Attacker to Elevate Privileges Locally; CISA's July 28th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-07-15 | CVE-2026-54429 | CVE-2026-54429 | 7.4 High | Updated |
| 2026-07-14 | CVE-2026-9653 | CVE-2026-9653 | 8.7 High | Updated |
| 2026-07-14 | CVE-2026-9650 | CVE-2026-9650 | 7.5 High | Updated |
| 2026-07-14 | CVE-2026-9636 | CVE-2026-9636 | 8.2 High | Updated |
| 2026-07-14 | CVE-2026-9292 | CVE-2026-9292 | 8.4 High | Updated |
| 2026-07-14 | CVE-2026-9140 | CVE-2026-9140 | 8.7 High | Updated |
| 2026-07-14 | CVE-2026-5928 | CVE-2026-5928 | 7.5 High | Updated |
| 2026-07-14 | CVE-2026-5450 | CVE-2026-5450 | 9.8 Critical | Updated |
| 2026-07-14 | CVE-2026-5435 | CVE-2026-5435 | 7.3 High | Updated |
| 2026-07-14 | CVE-2026-46174 | CVE-2026-46174 | 8.8 High | Updated |
| 2026-07-14 | CVE-2026-43057 | CVE-2026-43057 | 7.5 High | Updated |
| 2026-07-14 | CVE-2026-43040 | CVE-2026-43040 | 7.1 High | Updated |
| 2026-07-14 | CVE-2026-43033 | CVE-2026-43033 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-43030 | CVE-2026-43030 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-43028 | CVE-2026-43028 | 7.1 High | Updated |
| 2026-07-14 | CVE-2026-43027 | CVE-2026-43027 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-43025 | CVE-2026-43025 | 7.3 High | Updated |
| 2026-07-14 | CVE-2026-43011 | CVE-2026-43011 | 9.8 Critical | Updated |
| 2026-07-14 | CVE-2026-31768 | CVE-2026-31768 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-31761 | CVE-2026-31761 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-31682 | CVE-2026-31682 | 9.1 Critical | Updated |
| 2026-07-14 | CVE-2026-31680 | CVE-2026-31680 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-31674 | CVE-2026-31674 | 7.1 High | Updated |
| 2026-07-14 | CVE-2026-31669 | CVE-2026-31669 | 9.8 Critical | Updated |
| 2026-07-14 | CVE-2026-31665 | CVE-2026-31665 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-31649 | CVE-2026-31649 | 9.8 Critical | Updated |
| 2026-07-14 | CVE-2026-31563 | CVE-2026-31563 | 7.5 High | Updated |
| 2026-07-14 | CVE-2026-31533 | CVE-2026-31533 | 9.8 Critical | Updated |
| 2026-07-14 | CVE-2026-31508 | CVE-2026-31508 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-31507 | CVE-2026-31507 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-31504 | CVE-2026-31504 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-31494 | CVE-2026-31494 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-31485 | CVE-2026-31485 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-31469 | CVE-2026-31469 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-31452 | CVE-2026-31452 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-31450 | CVE-2026-31450 | 8.8 High | Updated |
| 2026-07-14 | CVE-2026-31448 | CVE-2026-31448 | 9.4 Critical | Updated |
| 2026-07-14 | CVE-2026-31447 | CVE-2026-31447 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-31417 | CVE-2026-31417 | 7.5 High | Updated |
| 2026-07-14 | CVE-2026-31414 | CVE-2026-31414 | 9.8 Critical | Updated |
| 2026-07-14 | CVE-2026-31396 | CVE-2026-31396 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-25789 | CVE-2026-25789 | 7.1 High | Updated |
| 2026-07-14 | CVE-2026-25787 | CVE-2026-25787 | 9.1 Critical | Updated |
| 2026-07-14 | CVE-2026-25786 | CVE-2026-25786 | 9.1 Critical | Updated |
| 2026-07-14 | CVE-2026-23449 | CVE-2026-23449 | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-12659 | CVE-2026-12659 | 8.7 High | Updated |
| 2026-07-14 | CVE-2026-10714 | CVE-2026-10714 | 8.8 High | Updated |
| 2026-07-14 | CVE-2026-0265 | Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.1 | 8.1 High | Updated |
| 2026-07-14 | CVE-2026-0264 | Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.8 | 9.8 Critical | Updated |
| 2026-07-14 | CVE-2026-0262 | Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE1808 | 7.5 High | Updated |
| 2026-07-14 | CVE-2026-0261 | Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.2 | 7.2 High | Updated |
| 2026-07-14 | CVE-2026-0258 | Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.1 | 9.1 Critical | Updated |
| 2026-07-09 | CVE-2026-54801 | CVE-2026-54801 | 7.2 High | Updated |
| 2026-07-01 | CVE-2026-9717 | CVE-2026-9717 | 7.2 High | Updated |
| 2026-07-01 | CVE-2026-9716 | CVE-2026-9716 | 7.5 High | Updated |
| 2026-07-01 | CVE-2026-14193 | CVE-2026-14193 | 7.5 High | Updated |
| 2026-07-01 | CVE-2026-12579 | CVE-2026-12579 | 7.4 High | Updated |
| 2026-07-01 | CVE-2026-12577 | CVE-2026-12577 | 8.7 High | Updated |
| 2026-07-01 | CVE-2026-12576 | CVE-2026-12576 | 7.5 High | Updated |
| 2026-07-01 | CVE-2026-12575 | CVE-2026-12575 | 7.5 High | Updated |
| 2026-06-30 | CVE-2026-12578 | CVE-2026-12578 | 8.4 High | Updated |
| 2026-06-30 | CVE-2026-10763 | CVE-2026-10763 | 7.0 High | Updated |
| 2026-06-29 | CVE-2026-44411 | CVE-2026-44411 | 7.8 High | Updated |
| 2026-06-29 | CVE-2026-22925 | CVE-2026-22925 | 7.5 High | Updated |
| 2026-06-29 | CVE-2026-22924 | CVE-2026-22924 | 9.1 Critical | Updated |
| 2026-06-29 | CVE-2025-40949 | CVE-2025-40949 | 9.1 Critical | Updated |
| 2026-06-29 | CVE-2025-40947 | CVE-2025-40947 | 7.5 High | Updated |
| 2026-06-27 | CVE-2024-54013 | CVE-2024-54013 | 8.8 High | Updated |
| 2026-06-24 | CVE-2026-6866 | CVE-2026-6866 | 7.5 High | Updated |
| 2026-06-23 | CVE-2026-10521 | CVE-2026-10521 | 7.2 High | Updated |
| 2026-06-22 | CVE-2026-8024 | CVE-2026-8024 | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-8398 | Daemon Tools Lite Contains Embedded Malicious Code; CISA Added It to KEV with a May 30th Deadline That Has Since Passed for Covered Entities | 9.8 Critical | KEV |
| 2026-06-17 | CVE-2026-7473 | Arista Extensible Operating System Validation Bypass Added to CISA's Known Exploited Vulnerabilities List; Federal Remediation Window for Covered Entities Closed June 23rd | 5.8 Medium | KEV |
| 2026-06-17 | CVE-2026-6888 | CVE-2026-6888 | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-6865 | CVE-2026-6865 | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-6332 | CVE-2026-6332 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-5416 | CVE-2026-5416 | 8.8 High | Updated |
| 2026-06-17 | CVE-2026-5387 | CVE-2026-5387 | 9.3 Critical | Updated |
| 2026-06-17 | CVE-2026-4827 | CVE-2026-4827 | 8.7 High | Updated |
| 2026-06-17 | CVE-2026-48027 | Nx Console Developer Tooling Published Packages Contain Embedded Malicious Code; CISA's June 10th KEV Mandate for Covered Entities Has Passed | 9.8 Critical | KEV |
| 2026-06-17 | CVE-2026-45321 | TanStack JavaScript Library Suite Added to CISA's Known Exploited Vulnerabilities Catalog; Federal Remediation Deadline for Covered Entities Was June 10th | 9.6 Critical | KEV |
| 2026-06-17 | CVE-2026-44412 | CVE-2026-44412 | 7.8 High | Updated |
| 2026-06-17 | CVE-2026-41551 | CVE-2026-41551 | 9.1 Critical | Updated |
| 2026-06-17 | CVE-2026-40852 | CVE-2026-40852 | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-40851 | CVE-2026-40851 | 8.4 High | Updated |
| 2026-06-17 | CVE-2026-40850 | CVE-2026-40850 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-40836 | CVE-2026-40836 | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-40834 | CVE-2026-40834 | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-40833 | CVE-2026-40833 | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-40819 | CVE-2026-40819 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-40818 | CVE-2026-40818 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-40817 | CVE-2026-40817 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-40816 | CVE-2026-40816 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-40815 | CVE-2026-40815 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-40814 | CVE-2026-40814 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-40813 | CVE-2026-40813 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-40812 | CVE-2026-40812 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-40811 | CVE-2026-40811 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-40810 | CVE-2026-40810 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-33893 | CVE-2026-33893 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-33892 | CVE-2026-33892 | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-33862 | CVE-2026-33862 | 7.3 High | Updated |
| 2026-06-17 | CVE-2026-33616 | CVE-2026-33616 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-33615 | CVE-2026-33615 | 9.1 Critical | Updated |
| 2026-06-17 | CVE-2026-33614 | CVE-2026-33614 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-33613 | CVE-2026-33613 | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-3323 | CVE-2026-3323 | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-27668 | CVE-2026-27668 | 8.8 High | Updated |
| 2026-06-17 | CVE-2026-27662 | CVE-2026-27662 | 7.7 High | Updated |
| 2026-06-17 | CVE-2026-25654 | CVE-2026-25654 | 8.8 High | Updated |
| 2026-06-17 | CVE-2026-24032 | CVE-2026-24032 | 7.3 High | Updated |
| 2026-06-17 | CVE-2026-1952 | Delta Electronics AS320T Denial of Service via Undocumented Subfunction Call, Exploitable Remotely Without Authentication | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1951 | Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing Directory Name Length Check, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1950 | Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing File Name Length Check, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1949 | Delta Electronics AS320T GET/PUT Request Handler Incorrectly Calculates Stack Buffer Size, Enabling Unauthenticated Remote Code Execution via the Web Service | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-11317 | CVE-2026-11317 | 8.7 High | Updated |
| 2026-06-17 | CVE-2026-10829 | CVE-2026-10829 | 8.6 High | Updated |
| 2026-06-17 | CVE-2026-10825 | CVE-2026-10825 | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-0647 | CVE-2026-0647 | 8.8 High | Updated |
| 2026-06-17 | CVE-2026-0646 | CVE-2026-0646 | 8.7 High | Updated |
| 2026-06-17 | CVE-2025-41670 | CVE-2025-41670 | 7.8 High | Updated |
| 2026-06-17 | CVE-2025-41669 | CVE-2025-41669 | 8.8 High | Updated |
| 2026-06-17 | CVE-2025-40946 | CVE-2025-40946 | 8.3 High | Updated |
| 2026-06-17 | CVE-2025-40899 | CVE-2025-40899 | 8.9 High | Updated |
| 2026-06-17 | CVE-2025-40897 | CVE-2025-40897 | 8.1 High | Updated |
| 2026-06-17 | CVE-2024-43384 | CVE-2024-43384 | 8.0 High | Updated |
| 2026-06-17 | CVE-2024-1490 | CVE-2024-1490 | 7.2 High | Updated |
| 2026-06-17 | CVE-2023-3634 | CVE-2023-3634 | 8.8 High | Updated |