CISA Known Exploited Vulnerabilities (KEV)
Actively exploited CVEs tracked by CISA — updated daily.
View all exploited vulnerabilities (KEV + sightings) →
| CVE ID | PS-HP | Severity | CVSS | Vendor | Product | Date Added | KEV | EPSS | GitHub | RW | Description |
|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2025-34291 | HP1 | HIGH | 8.8 | Langflow | Langflow | 2026-05-21 | KEV | 39.3% | - | - | Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage |
| CVE-2026-34926 | HP1 | MEDIUM | 6.7 | Trend Micro | Apex One | 2026-05-21 | KEV | 1.0% | - | - | Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deplo |
| CVE-2008-4250 | HP1 | CRITICAL | 9.8 | Microsoft | Windows | 2026-05-20 | KEV | 91.8% | 4 | - | Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow duri |
| CVE-2009-1537 | HP1 | HIGH | 8.8 | Microsoft | DirectX | 2026-05-20 | KEV | 53.0% | - | - | Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a craft |
| CVE-2009-3459 | HP1 | HIGH | 8.8 | Adobe | Acrobat and Reader | 2026-05-20 | KEV | 88.1% | - | - | Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption. |
| CVE-2010-0249 | HP1 | HIGH | 8.8 | Microsoft | Internet Explorer | 2026-05-20 | KEV | 88.7% | - | - | Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted p |
| CVE-2010-0806 | HP1 | HIGH | 8.8 | Microsoft | Internet Explorer | 2026-05-20 | KEV | 87.3% | - | - | Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion o |
| CVE-2026-41091 | HP1 | HIGH | 7.8 | Microsoft | Defender | 2026-05-20 | KEV | 8.1% | - | - | Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. |
| CVE-2026-45498 | HP1 | MEDIUM | 4.0 | Microsoft | Defender | 2026-05-20 | KEV | 3.5% | - | - | Microsoft Defender contains an unspecified vulnerability that allows for denial of service. |
| CVE-2026-42897 | HP1 | HIGH | 8.1 | Microsoft | Microsoft | 2026-05-15 | KEV | 7.9% | - | - | Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be ex |
| CVE-2026-20182 | HP1 | CRITICAL | 10.0 | Cisco | Catalyst SD-WAN | 2026-05-14 | KEV | 83.8% | - | - | Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges |
| CVE-2026-42208 | HP1 | CRITICAL | 9.8 | BerriAI | LiteLLM | 2026-05-08 | KEV | 62.6% | - | - | BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the cre |
| CVE-2026-6973 | HP1 | HIGH | 7.2 | Ivanti | Endpoint Manager Mobile (EPMM) | 2026-05-07 | KEV | 5.9% | - | - | Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution. |
| CVE-2026-0300 | HP1 | CRITICAL | 9.8 | Palo Alto Networks | PAN-OS | 2026-05-06 | KEV | 6.1% | - | - | Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrar |
| CVE-2026-31431 | HP1 | HIGH | 7.8 | Linux | Kernel | 2026-05-01 | KEV | 2.6% | - | - | Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. |
| CVE-2026-41940 | HP1 | CRITICAL | 9.8 | WebPros | cPanel & WHM and WP2 (WordPress Squared) | 2026-04-30 | KEV | 90.9% | - | RW | WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized ac |
| CVE-2024-1708 | HP1 | HIGH | 8.4 | ConnectWise | ScreenConnect | 2026-04-28 | KEV | 84.8% | - | RW | ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems. |
| CVE-2026-32202 | HP1 | MEDIUM | 4.3 | Microsoft | Windows | 2026-04-28 | KEV | 53.1% | - | - | Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-29635 | HP1 | HIGH | 7.2 | D-Link | DIR-823X | 2026-04-24 | KEV | 19.9% | - | - | D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via t |
| CVE-2024-7399 | HP1 | HIGH | 8.8 | Samsung | MagicINFO 9 Server | 2026-04-24 | KEV | 69.2% | 1 | - | Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority. |
| CVE-2024-57728 | HP1 | HIGH | 7.2 | SimpleHelp | SimpleHelp | 2026-04-24 | KEV | 53.4% | - | RW | SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited |
| CVE-2024-57726 | HP1 | CRITICAL | 9.9 | SimpleHelp | SimpleHelp | 2026-04-24 | KEV | 38.8% | - | RW | SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges t |
| CVE-2026-39987 | HP1 | CRITICAL | 9.8 | Marimo | Marimo | 2026-04-23 | KEV | 80.7% | - | - | Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands. |
| CVE-2026-33825 | HP1 | HIGH | 7.8 | Microsoft | Defender | 2026-04-22 | KEV | 9.0% | - | - | Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. |
| CVE-2026-20122 | HP1 | MEDIUM | 5.4 | Cisco | Catalyst SD-WAN Manger | 2026-04-20 | KEV | 1.4% | - | - | Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulner |
| CVE-2026-20133 | HP1 | MEDIUM | 6.5 | Cisco | Catalyst SD-WAN Manager | 2026-04-20 | KEV | 2.0% | - | - | Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems. |
| CVE-2025-2749 | HP1 | HIGH | 7.2 | Kentico | Kentico Xperience | 2026-04-20 | KEV | 4.8% | - | - | Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations. |
| CVE-2023-27351 | HP1 | HIGH | 7.5 | PaperCut | NG/MF | 2026-04-20 | KEV | 65.6% | - | RW | PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class. |
| CVE-2025-48700 | HP1 | MEDIUM | 6.1 | Synacor | Zimbra Collaboration Suite (ZCS) | 2026-04-20 | KEV | 18.2% | - | - | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unau |
| CVE-2026-20128 | HP1 | HIGH | 7.5 | Cisco | Catalyst SD-WAN Manager | 2026-04-20 | KEV | 0.1% | - | - | Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file |
| CVE-2025-32975 | HP1 | CRITICAL | 10.0 | Quest | KACE Systems Management Appliance (SMA) | 2026-04-20 | KEV | 39.3% | - | - | Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials. |
| CVE-2024-27199 | HP1 | HIGH | 7.3 | JetBrains | TeamCity | 2026-04-20 | KEV | 90.9% | - | RW | JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. |
| CVE-2026-34197 | HP1 | HIGH | 8.8 | Apache | ActiveMQ | 2026-04-16 | KEV | 83.5% | - | - | Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. |
| CVE-2009-0238 | HP1 | HIGH | 8.8 | Microsoft | Office | 2026-04-14 | KEV | 74.7% | - | - | Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that in |
| CVE-2026-32201 | HP1 | MEDIUM | 6.5 | Microsoft | SharePoint Server | 2026-04-14 | KEV | 7.9% | - | - | Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2012-1854 | HP1 | HIGH | 7.8 | Microsoft | Visual Basic for Applications (VBA) | 2026-04-13 | KEV | 3.1% | - | - | Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. |
| CVE-2025-60710 | HP1 | HIGH | 7.8 | Microsoft | Windows | 2026-04-13 | KEV | 16.6% | 1 | - | Microsoft Windows contains a link following vulnerability that allows for privilege escalation |
| CVE-2023-21529 | HP1 | HIGH | 8.8 | Microsoft | Exchange Server | 2026-04-13 | KEV | 27.0% | - | RW | Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. |
| CVE-2023-36424 | HP1 | HIGH | 7.8 | Microsoft | Windows | 2026-04-13 | KEV | 9.8% | 1 | - | Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation |
| CVE-2020-9715 | HP1 | HIGH | 7.8 | Adobe | Acrobat | 2026-04-13 | KEV | 79.2% | 2 | - | Adobe Acrobat contains a use-after-free vulnerability that allows for code execution |
| CVE-2026-21643 | HP1 | CRITICAL | 9.8 | Fortinet | FortiClient EMS | 2026-04-13 | KEV | 70.9% | - | - | Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. |
| CVE-2026-34621 | HP1 | HIGH | 8.6 | Adobe | Acrobat and Reader | 2026-04-13 | KEV | 11.0% | - | - | Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. |
| CVE-2026-1340 | HP1 | CRITICAL | 9.8 | Ivanti | Endpoint Manager Mobile (EPMM) | 2026-04-08 | KEV | 73.9% | - | - | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. |
| CVE-2026-35616 | HP1 | CRITICAL | 9.8 | Fortinet | FortiClient EMS | 2026-04-06 | KEV | 35.7% | - | - | Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. |
| CVE-2026-3502 | HP1 | HIGH | 7.8 | TrueConf | Client | 2026-04-02 | KEV | 2.7% | - | - | TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payloa |
| CVE-2026-5281 | HP1 | HIGH | 8.8 | Dawn | 2026-04-01 | KEV | 0.9% | - | - | Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability c | |
| CVE-2026-3055 | HP1 | CRITICAL | 9.8 | Citrix | NetScaler | 2026-03-30 | KEV | 89.9% | - | - | Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP lead |
| CVE-2025-53521 | HP1 | CRITICAL | 9.8 | F5 | BIG-IP | 2026-03-27 | KEV | 8.8% | - | - | F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution. |
| CVE-2026-33634 | HP1 | HIGH | 8.8 | Aquasecurity | Trivy | 2026-03-26 | KEV | 26.6% | - | - | Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentia |
| CVE-2026-33017 | HP1 | CRITICAL | 9.8 | Langflow | Langflow | 2026-03-25 | KEV | 24.7% | - | - | Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication. |
| CVE-2025-32432 | HP1 | CRITICAL | 10.0 | Craft CMS | Craft CMS | 2026-03-20 | KEV | 93.1% | 5 | - | Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code. |
| CVE-2025-54068 | HP1 | CRITICAL | 9.8 | Laravel | Livewire | 2026-03-20 | KEV | 58.9% | 3 | - | Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. |
| CVE-2025-43510 | HP1 | HIGH | 7.8 | Apple | Multiple Products | 2026-03-20 | KEV | 0.3% | - | - | Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes. |
| CVE-2025-43520 | HP1 | MEDIUM | 5.5 | Apple | Multiple Products | 2026-03-20 | KEV | 0.3% | - | - | Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel m |
| CVE-2025-31277 | HP1 | HIGH | 8.8 | Apple | Multiple Products | 2026-03-20 | KEV | 0.3% | - | - | Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corrup |
| CVE-2026-20131 | HP1 | CRITICAL | 10.0 | Cisco | Secure Firewall Management Center (FMC) | 2026-03-19 | KEV | 1.7% | - | RW | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management |
| CVE-2025-66376 | HP1 | HIGH | 7.2 | Synacor | Zimbra Collaboration Suite (ZCS) | 2026-03-18 | KEV | 10.9% | - | - | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML. |
| CVE-2026-20963 | HP1 | CRITICAL | 9.8 | Microsoft | SharePoint | 2026-03-18 | KEV | 8.1% | - | - | Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. |
| CVE-2025-47813 | HP1 | MEDIUM | 4.3 | Wing FTP Server | Wing FTP Server | 2026-03-16 | KEV | 25.3% | - | - | Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie. |
| CVE-2026-3910 | - | HIGH | 8.8 | Chromium V8 | 2026-03-13 | KEV | - | - | - | Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a | |
| CVE-2026-3909 | - | HIGH | 8.8 | Skia | 2026-03-13 | KEV | - | - | - | Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome an | |
| CVE-2025-68613 | - | CRITICAL | 9.9 | n8n | n8n | 2026-03-11 | KEV | - | - | - | n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution. |
| CVE-2021-22054 | - | HIGH | 7.5 | Omnissa | Workspace One UEM | 2026-03-09 | KEV | - | - | - | Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send t |
| CVE-2025-26399 | - | CRITICAL | 9.8 | SolarWinds | Web Help Desk | 2026-03-09 | KEV | - | - | - | SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine. |
| CVE-2026-1603 | - | HIGH | 8.6 | Ivanti | Endpoint Manager (EPM) | 2026-03-09 | KEV | - | - | - | Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential d |
| CVE-2017-7921 | - | CRITICAL | 9.8 | Hikvision | Multiple Products | 2026-03-05 | KEV | - | - | - | Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information. |
| CVE-2021-22681 | - | CRITICAL | 9.8 | Rockwell | Multiple Products | 2026-03-05 | KEV | - | - | - | Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controlle |
| CVE-2023-43000 | - | HIGH | 8.8 | Apple | Multiple Products | 2026-03-05 | KEV | - | - | - | Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption. |
| CVE-2021-30952 | - | HIGH | 7.8 | Apple | Multiple Products | 2026-03-05 | KEV | - | - | - | Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution |
| CVE-2023-41974 | - | HIGH | 7.8 | Apple | iOS and iPadOS | 2026-03-05 | KEV | - | - | - | Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges. |
| CVE-2026-22719 | - | HIGH | 8.1 | Broadcom | VMware Aria Operations | 2026-03-03 | KEV | - | - | - | Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentia |
| CVE-2026-21385 | - | HIGH | 7.8 | Qualcomm | Multiple Chipsets | 2026-03-03 | KEV | - | - | - | Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. |
| CVE-2022-20775 | - | HIGH | 7.8 | Cisco | SD-WAN | 2026-02-25 | KEV | - | - | - | Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CL |
| CVE-2026-20127 | - | CRITICAL | 10.0 | Cisco | Catalyst SD-WAN Controller and Manager | 2026-02-25 | KEV | - | - | - | Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, rem |
| CVE-2026-25108 | - | HIGH | 8.7 | Soliton Systems K.K | FileZen | 2026-02-24 | KEV | - | - | - | Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request. |
| CVE-2025-49113 | - | CRITICAL | 9.9 | Roundcube | Webmail | 2026-02-20 | KEV | - | - | - | RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/a |
| CVE-2025-68461 | - | HIGH | 7.2 | Roundcube | Webmail | 2026-02-20 | KEV | - | - | - | RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document. |
| CVE-2021-22175 | - | MEDIUM | 6.8 | GitLab | GitLab | 2026-02-18 | KEV | - | - | - | GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled. |
| CVE-2026-22769 | - | CRITICAL | 10.0 | Dell | RecoverPoint for Virtual Machines (RP4VMs) | 2026-02-18 | KEV | - | - | - | Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlyin |
| CVE-2020-7796 | - | CRITICAL | 9.8 | Synacor | Zimbra Collaboration Suite | 2026-02-17 | KEV | - | - | - | Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled. |
| CVE-2024-7694 | - | HIGH | 7.2 | TeamT5 | ThreatSonar Anti-Ransomware | 2026-02-17 | KEV | - | - | - | TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Remo |
| CVE-2008-0015 | - | HIGH | 8.8 | Microsoft | Windows | 2026-02-17 | KEV | - | - | - | Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the |
| CVE-2026-2441 | - | HIGH | 8.8 | Chromium | 2026-02-17 | KEV | - | - | - | Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple | |
| CVE-2026-1731 | - | CRITICAL | 9.9 | BeyondTrust | Remote Support (RS) and Privileged Remote Access (PRA) | 2026-02-13 | KEV | - | - | RW | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute opera |
| CVE-2026-20700 | - | HIGH | 7.8 | Apple | Multiple Products | 2026-02-12 | KEV | - | - | - | Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capabi |
| CVE-2024-43468 | - | CRITICAL | 9.8 | Microsoft | Configuration Manager | 2026-02-12 | KEV | - | - | - | Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment wh |
| CVE-2025-15556 | - | HIGH | 7.7 | Notepad++ | Notepad++ | 2026-02-12 | KEV | - | - | - | Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute |
| CVE-2025-40536 | - | HIGH | 8.1 | SolarWinds | Web Help Desk | 2026-02-12 | KEV | - | - | - | SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality. |
| CVE-2026-21513 | - | HIGH | 8.8 | Microsoft | Windows | 2026-02-10 | KEV | - | - | - | Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-21525 | - | MEDIUM | 6.2 | Microsoft | Windows | 2026-02-10 | KEV | - | - | - | Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. |
| CVE-2026-21510 | - | HIGH | 8.8 | Microsoft | Windows | 2026-02-10 | KEV | - | - | - | Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-21533 | - | HIGH | 7.8 | Microsoft | Windows | 2026-02-10 | KEV | - | - | - | Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. |
| CVE-2026-21519 | - | HIGH | 7.8 | Microsoft | Windows | 2026-02-10 | KEV | - | - | - | Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. |
| CVE-2026-21514 | - | HIGH | 7.8 | Microsoft | Office | 2026-02-10 | KEV | - | - | - | Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally. |
| CVE-2025-11953 | - | CRITICAL | 9.8 | React Native Community | CLI | 2026-02-05 | KEV | - | - | - | React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary ex |
| CVE-2026-24423 | - | CRITICAL | 9.3 | SmarterTools | SmarterMail | 2026-02-05 | KEV | - | - | RW | SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a mali |
| CVE-2021-39935 | - | MEDIUM | 6.8 | GitLab | Community and Enterprise Editions | 2026-02-03 | KEV | - | - | - | GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API. |
| CVE-2025-64328 | - | HIGH | 8.6 | Sangoma | FreePBX | 2026-02-03 | KEV | - | - | - | Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> ch |
| CVE-2019-19006 | - | CRITICAL | 9.8 | Sangoma | FreePBX | 2026-02-03 | KEV | - | - | - | Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin. |
| CVE-2025-40551 | - | CRITICAL | 9.8 | SolarWinds | Web Help Desk | 2026-02-03 | KEV | - | - | - | SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This co |
| CVE-2026-1281 | - | CRITICAL | 9.8 | Ivanti | Endpoint Manager Mobile (EPMM) | 2026-01-29 | KEV | - | - | - | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. |
| CVE-2026-24858 | - | CRITICAL | 9.8 | Fortinet | Multiple Products | 2026-01-27 | KEV | - | - | - | Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registere |
| CVE-2018-14634 | - | HIGH | 7.8 | Linux | Kernel | 2026-01-26 | KEV | - | - | - | Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalat |
| CVE-2025-52691 | - | CRITICAL | 10.0 | SmarterTools | SmarterMail | 2026-01-26 | KEV | - | - | RW | SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail se |
| CVE-2026-23760 | - | CRITICAL | 9.3 | SmarterTools | SmarterMail | 2026-01-26 | KEV | - | - | RW | SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and |
| CVE-2026-24061 | - | CRITICAL | 9.8 | GNU | InetUtils | 2026-01-26 | KEV | - | - | - | GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable. |
| CVE-2026-21509 | - | HIGH | 7.8 | Microsoft | Office | 2026-01-26 | KEV | - | - | - | Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a secu |
| CVE-2024-37079 | - | CRITICAL | 9.8 | Broadcom | VMware vCenter Server | 2026-01-23 | KEV | - | - | - | Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to s |
| CVE-2025-68645 | - | HIGH | 8.8 | Synacor | Zimbra Collaboration Suite (ZCS) | 2026-01-22 | KEV | - | - | - | Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal reques |
| CVE-2025-34026 | - | CRITICAL | 9.2 | Versa | Concerto | 2026-01-22 | KEV | - | - | - | Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The |
| CVE-2025-31125 | - | MEDIUM | 5.3 | Vite | Vitejs | 2026-01-22 | KEV | - | - | - | Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the ne |
| CVE-2025-54313 | - | HIGH | 7.5 | Prettier | eslint-config-prettier | 2026-01-22 | KEV | - | - | - | Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows. |
| CVE-2026-20045 | - | HIGH | 8.2 | Cisco | Unified Communications Manager | 2026-01-21 | KEV | - | - | - | Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified |
| CVE-2026-20805 | - | MEDIUM | 5.5 | Microsoft | Windows | 2026-01-13 | KEV | - | - | - | Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally. |
| CVE-2025-8110 | - | HIGH | 8.7 | Gogs | Gogs | 2026-01-12 | KEV | - | - | - | Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution. |
| CVE-2009-0556 | - | HIGH | 8.8 | Microsoft | Office | 2026-01-07 | KEV | - | - | - | Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index |
| CVE-2025-37164 | - | CRITICAL | 10.0 | Hewlett Packard Enterprise (HPE) | OneView | 2026-01-07 | KEV | - | - | - | Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution. |
| CVE-2025-14847 | - | HIGH | 8.7 | MongoDB | MongoDB and MongoDB Server | 2025-12-29 | KEV | - | - | - | MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an |
| CVE-2023-52163 | - | HIGH | 8.8 | Digiever | DS-2105 Pro | 2025-12-22 | KEV | - | - | - | Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi. |
| CVE-2025-14733 | - | CRITICAL | 9.3 | WatchGuard | Firebox | 2025-12-19 | KEV | - | - | - | WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and a |
| CVE-2025-59374 | - | CRITICAL | 9.3 | ASUS | Live Update | 2025-12-17 | KEV | - | - | - | ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause |
| CVE-2025-40602 | - | MEDIUM | 6.6 | SonicWall | SMA1000 appliance | 2025-12-17 | KEV | - | - | - | SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices. |
| CVE-2025-20393 | - | CRITICAL | 10.0 | Cisco | Multiple Products | 2025-12-17 | KEV | - | - | - | Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with |
| CVE-2025-59718 | - | CRITICAL | 9.8 | Fortinet | Multiple Products | 2025-12-16 | KEV | - | - | - | Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCl |
| CVE-2025-14611 | - | HIGH | 7.1 | Gladinet | CentreStack and Triofox | 2025-12-15 | KEV | - | - | - | Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoint |
| CVE-2025-43529 | - | HIGH | 8.8 | Apple | Multiple Products | 2025-12-15 | KEV | - | - | - | Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could |
| CVE-2018-4063 | - | HIGH | 8.8 | Sierra Wireless | AirLink ALEOS | 2025-12-12 | KEV | - | - | - | Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded |
| CVE-2025-14174 | - | HIGH | 8.8 | Chromium | 2025-12-12 | KEV | - | - | - | Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability cou | |
| CVE-2025-58360 | - | HIGH | 8.2 | OSGeo | GeoServer | 2025-12-11 | KEV | - | - | - | OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation |
| CVE-2025-6218 | - | HIGH | 7.8 | RARLAB | WinRAR | 2025-12-09 | KEV | - | - | - | RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user. |
| CVE-2025-62221 | - | HIGH | 7.8 | Microsoft | Windows | 2025-12-09 | KEV | - | - | - | Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally. |
| CVE-2022-37055 | - | CRITICAL | 9.8 | D-Link | Routers | 2025-12-08 | KEV | - | - | - | D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service ( |
| CVE-2025-66644 | - | HIGH | 7.2 | Array Networks | ArrayOS AG | 2025-12-08 | KEV | - | - | - | Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands. |
| CVE-2025-55182 | - | CRITICAL | 10.0 | Meta | React Server Components | 2025-12-05 | KEV | - | - | RW | Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Serv |
| CVE-2021-26828 | - | HIGH | 8.8 | OpenPLC | ScadaBR | 2025-12-03 | KEV | - | - | - | OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm. |
| CVE-2025-48633 | - | MEDIUM | 5.5 | Android | Framework | 2025-12-02 | KEV | - | - | - | Android Framework contains an unspecified vulnerability that allows for information disclosure. |
| CVE-2025-48572 | - | HIGH | 7.8 | Android | Framework | 2025-12-02 | KEV | - | - | - | Android Framework contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2021-26829 | - | MEDIUM | 5.4 | OpenPLC | ScadaBR | 2025-11-28 | KEV | - | - | - | OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm. |
| CVE-2025-61757 | - | CRITICAL | 9.8 | Oracle | Fusion Middleware | 2025-11-21 | KEV | - | - | - | Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager. |
| CVE-2025-13223 | - | HIGH | 8.8 | Chromium V8 | 2025-11-19 | KEV | - | - | - | Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption. | |
| CVE-2025-58034 | - | HIGH | 7.2 | Fortinet | FortiWeb | 2025-11-18 | KEV | - | - | - | Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI command |
| CVE-2025-64446 | - | CRITICAL | 9.8 | Fortinet | FortiWeb | 2025-11-14 | KEV | - | - | - | Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests. |
| CVE-2025-12480 | - | CRITICAL | 9.1 | Gladinet | Triofox | 2025-11-12 | KEV | - | - | - | Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete. |
| CVE-2025-62215 | - | HIGH | 7.0 | Microsoft | Windows | 2025-11-12 | KEV | - | - | - | Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enab |
| CVE-2025-9242 | - | CRITICAL | 9.3 | WatchGuard | Firebox | 2025-11-12 | KEV | - | - | - | WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code. |
| CVE-2025-21042 | - | HIGH | 8.8 | Samsung | Mobile Devices | 2025-11-10 | KEV | - | - | - | Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code. |
| CVE-2025-48703 | - | CRITICAL | 9.0 | CWP | Control Web Panel | 2025-11-04 | KEV | - | - | - | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in |
| CVE-2025-11371 | - | HIGH | 7.5 | Gladinet | CentreStack and Triofox | 2025-11-04 | KEV | - | - | - | Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files. |
| CVE-2025-41244 | - | HIGH | 7.8 | Broadcom | VMware Aria Operations and VMware Tools | 2025-10-30 | KEV | - | - | - | Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VM |
| CVE-2025-24893 | - | CRITICAL | 9.8 | XWiki | Platform | 2025-10-30 | KEV | - | - | - | XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch. |
| CVE-2025-6204 | - | HIGH | 8.0 | Dassault Systèmes | DELMIA Apriso | 2025-10-28 | KEV | - | - | - | Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code. |
| CVE-2025-6205 | - | CRITICAL | 9.1 | Dassault Systèmes | DELMIA Apriso | 2025-10-28 | KEV | - | - | - | Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application. |
| CVE-2025-54236 | - | CRITICAL | 9.1 | Adobe | Commerce and Magento | 2025-10-24 | KEV | - | - | - | Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. |
| CVE-2025-59287 | - | CRITICAL | 9.8 | Microsoft | Windows | 2025-10-24 | KEV | - | - | - | Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution. |
| CVE-2025-61932 | - | CRITICAL | 9.3 | Motex | LANSCOPE Endpoint Manager | 2025-10-22 | KEV | - | - | - | Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets |
| CVE-2022-48503 | - | HIGH | 8.8 | Apple | Multiple Products | 2025-10-20 | KEV | - | - | - | Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be |
| CVE-2025-2746 | - | CRITICAL | 9.8 | Kentico | Xperience CMS | 2025-10-20 | KEV | - | - | - | Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects. |
| CVE-2025-2747 | - | CRITICAL | 9.8 | Kentico | Xperience CMS | 2025-10-20 | KEV | - | - | - | Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects. |
| CVE-2025-33073 | - | HIGH | 8.8 | Microsoft | Windows | 2025-10-20 | KEV | - | - | - | Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the v |
| CVE-2025-61884 | - | HIGH | 7.5 | Oracle | E-Business Suite | 2025-10-20 | KEV | - | - | RW | Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication. |
| CVE-2025-54253 | - | CRITICAL | 10.0 | Adobe | Experience Manager (AEM) Forms | 2025-10-15 | KEV | - | - | - | Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution. |
| CVE-2025-47827 | - | MEDIUM | 4.6 | IGEL | IGEL OS | 2025-10-14 | KEV | - | - | - | IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a cra |
| CVE-2025-24990 | - | HIGH | 7.8 | Microsoft | Windows | 2025-10-14 | KEV | - | - | - | Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain |
| CVE-2025-59230 | - | HIGH | 7.8 | Microsoft | Windows | 2025-10-14 | KEV | - | - | - | Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally. |
| CVE-2016-7836 | - | CRITICAL | 9.8 | SKYSEA | Client View | 2025-10-14 | KEV | - | - | - | SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program |
| CVE-2021-43798 | - | HIGH | 7.5 | Grafana Labs | Grafana | 2025-10-09 | KEV | - | - | - | Grafana contains a path traversal vulnerability that could allow access to local files. |
| CVE-2025-27915 | - | MEDIUM | 5.4 | Synacor | Zimbra Collaboration Suite (ZCS) | 2025-10-07 | KEV | - | - | - | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user |
| CVE-2021-22555 | - | HIGH | 8.3 | Linux | Kernel | 2025-10-06 | KEV | - | - | - | Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space. |
| CVE-2010-3962 | - | HIGH | 8.1 | Microsoft | Internet Explorer | 2025-10-06 | KEV | - | - | - | Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service |
| CVE-2021-43226 | - | HIGH | 7.8 | Microsoft | Windows | 2025-10-06 | KEV | - | - | - | Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms. |
| CVE-2013-3918 | - | HIGH | 8.8 | Microsoft | Windows | 2025-10-06 | KEV | - | - | - | Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a spe |
| CVE-2011-3402 | - | HIGH | 8.8 | Microsoft | Windows | 2025-10-06 | KEV | - | - | - | Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via c |
| CVE-2010-3765 | - | CRITICAL | 9.8 | Mozilla | Multiple Products | 2025-10-06 | KEV | - | - | - | Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameCon |
| CVE-2025-61882 | - | CRITICAL | 9.8 | Oracle | E-Business Suite | 2025-10-06 | KEV | - | - | RW | Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Or |
| CVE-2014-6278 | - | HIGH | 8.8 | GNU | GNU Bash | 2025-10-02 | KEV | - | - | - | GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment. |
| CVE-2017-1000353 | - | CRITICAL | 9.8 | Jenkins | Jenkins | 2025-10-02 | KEV | - | - | - | Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would |
| CVE-2015-7755 | - | CRITICAL | 9.8 | Juniper | ScreenOS | 2025-10-02 | KEV | - | - | - | Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device. |
| CVE-2025-21043 | - | HIGH | 8.8 | Samsung | Mobile Devices | 2025-10-02 | KEV | - | - | - | Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code. |
| CVE-2025-4008 | - | HIGH | 8.7 | Smartbedded | Meteobridge | 2025-10-02 | KEV | - | - | - | Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected dev |
| CVE-2025-32463 | - | CRITICAL | 9.3 | Sudo | Sudo | 2025-09-29 | KEV | - | - | - | Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands |
| CVE-2025-59689 | - | MEDIUM | 6.1 | Libraesva | Email Security Gateway | 2025-09-29 | KEV | - | - | - | Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment. |
| CVE-2025-10035 | - | CRITICAL | 10.0 | Fortra | GoAnywhere MFT | 2025-09-29 | KEV | - | - | RW | Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, p |
| CVE-2025-20352 | - | HIGH | 7.7 | Cisco | IOS and IOS XE | 2025-09-29 | KEV | - | - | - | Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A |
| CVE-2021-21311 | - | HIGH | 7.2 | Adminer | Adminer | 2025-09-29 | KEV | - | - | - | Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to obtain potentially sensitive information. |
| CVE-2025-20362 | - | MEDIUM | 6.5 | Cisco | Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | 2025-09-25 | KEV | - | - | - | Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chai |
| CVE-2025-20333 | - | CRITICAL | 9.9 | Cisco | Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | 2025-09-25 | KEV | - | - | - | Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. |
| CVE-2025-10585 | - | CRITICAL | 9.8 | Chromium V8 | 2025-09-23 | KEV | - | - | - | Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine. | |
| CVE-2025-5086 | - | CRITICAL | 9.0 | Dassault Systèmes | DELMIA Apriso | 2025-09-11 | KEV | - | - | - | Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability that could lead to a remote code execution. |
| CVE-2025-38352 | - | HIGH | 7.4 | Linux | Kernel | 2025-09-04 | KEV | - | - | - | Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability. |
| CVE-2025-48543 | - | HIGH | 8.8 | Android | Runtime | 2025-09-04 | KEV | - | - | - | Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation. |
| CVE-2025-53690 | - | CRITICAL | 9.0 | Sitecore | Multiple Products | 2025-09-04 | KEV | - | - | - | Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the use of default machine k |
| CVE-2023-50224 | - | MEDIUM | 6.5 | TP-Link | TL-WR841N | 2025-09-03 | KEV | - | - | - | TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impa |
| CVE-2025-9377 | - | HIGH | 8.6 | TP-Link | Multiple Routers | 2025-09-03 | KEV | - | - | - | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or end-of-servic |
| CVE-2020-24363 | - | HIGH | 8.8 | TP-Link | TL-WA855RE | 2025-09-02 | KEV | - | - | - | TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST r |
| CVE-2025-55177 | - | MEDIUM | 5.4 | Meta Platforms | 2025-09-02 | KEV | - | - | - | Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vulnerability could allow an unrelated user | |
| CVE-2025-57819 | - | CRITICAL | 10.0 | Sangoma | FreePBX | 2025-08-29 | KEV | - | - | - | Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database |
| CVE-2025-7775 | - | CRITICAL | 9.2 | Citrix | NetScaler | 2025-08-26 | KEV | - | - | - | Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service. |
| CVE-2025-48384 | - | HIGH | 8.0 | Git | Git | 2025-08-25 | KEV | - | - | - | Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files. |
| CVE-2024-8068 | - | MEDIUM | 5.1 | Citrix | Session Recording | 2025-08-25 | KEV | - | - | - | Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user i |
| CVE-2024-8069 | - | MEDIUM | 5.1 | Citrix | Session Recording | 2025-08-25 | KEV | - | - | - | Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an aut |