Skip to main content

Records

1891 total
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-76504
Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability
Cisco9.81.1%KEV2026-09-30
CVE-2026-86950
Apple Multiple Products Out-of-Bounds Write Vulnerability
Apple8.81.2%KEV2026-09-28
CVE-2026-88772
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
Citrix NetScaler9.51.3%KEV2026-09-27
CVE-2026-88771
A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
Citrix NetScaler9.51.1%KEV2026-09-27
CVE-2026-87902
WordPress Core Remote File Inclusion Vulnerability
WordPress8.119.8%KEV2026-09-22
CVE-2026-94127
BIG-IP APM OAuth vulnerability
F59.82.2%KEV2026-09-22
CVE-2026-93616
Directory Traversal and File upload allows execution of arbitrary script on the Management Server
checkpoint9.819.7%KEV2026-09-22
CVE-2026-93952
Security Advisory 0183
Arista Networks10.01.1%KEV2026-09-22
CVE-2026-87886
Acronis Backup Incorrect Default Permissions Vulnerability
Acronis7.80.2%KEV2026-09-17
CVE-2026-76460
Cisco Identity Services Engine Authentication Bypass Vulnerability
Cisco10.014.0%KEV2026-09-16
CVE-2026-58704
Google Pixel Improper Authorization Vulnerability
Google8.80.6%KEV2026-09-15
CVE-2026-76461
Cisco Secure Email Gateway SQL Injection Vulnerability
Cisco9.828.3%KEV2026-09-14
CVE-2026-85706
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
GitLab10.093.0%KEV2026-09-12
CVE-2026-85102
Improper Certificate Validation in Quantum Security Gateway
checkpoint9.87.5%KEV2026-09-09
CVE-2026-87491
Google Chromium V8 Out of Bounds Write Vulnerability
Google8.83.1%KEV2026-09-09
CVE-2026-84869
ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
ConnectWise9.90.9%KEV2026-09-08
CVE-2026-81963
Windows Update Stack Elevation of Privilege Vulnerability
Microsoft7.80.4%KEV2026-09-08
CVE-2026-85880
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Microsoft7.83.6%KEV2026-09-08
CVE-2026-75650
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
Adobe10.03.9%KEV2026-09-07
CVE-2026-86218
pre-authentication remote code execution
N-able10.012.9%KEV2026-09-06
CVE-2026-86060
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
Mikrotik9.21.8%KEV2026-09-05
CVE-2026-67279
SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
Mikrotik6.91.0%KEV2026-09-05
CVE-2026-67277
Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
Mikrotik8.81.6%KEV2026-09-05
CVE-2026-67276
SSH user impersonation possible in Mikrotik RouterOS
Mikrotik9.26.5%2026-09-05
CVE-2026-85046
Google Chromium V8 Type Confusion Vulnerability
Google8.848.9%KEV2026-09-03
CVE-2026-83549
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
SonicWall7.810.8%KEV2026-09-01
CVE-2026-83548
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall10.08.8%KEV2026-09-01
CVE-2026-82329
Potential authentication bypass leading to administrative access in Artifactory
jfrog9.814.1%KEV2026-08-28
CVE-2026-82078
PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
PaperCut9.461.4%KEV2026-08-28
CVE-2026-81578
PaperCut MF/NG: Authentication Bypass
PaperCut8.885.2%KEV2026-08-28
CVE-2026-60004
Gitea Code Injection Vulnerability
Gitea9.824.0%KEV2026-08-26
CVE-2026-72530
TrueConf Server Code Injection Vulnerability
TrueConf9.51.7%KEV2026-08-19
CVE-2026-72529
TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf9.81.5%KEV2026-08-19
CVE-2026-19490
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
NetScaler9.38.0%KEV2026-08-19
CVE-2026-64849
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
mlflow9.39.8%KEV2026-08-17
CVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
GitLab9.460.2%2026-08-17
CVE-2026-73570
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Zimbra8.911.7%KEV2026-08-13
CVE-2026-42018
Anonymous user token generation exposure in JFrog Artifactory
jfrog7.59.8%KEV2026-08-12
CVE-2026-66384
Authenticated users may write data outside the intended Docker cache path
jfrog5.30.7%KEV2026-08-12
CVE-2026-71362
Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe9.187.5%KEV2026-08-11
CVE-2026-20349
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
Cisco8.61.0%KEV2026-08-11
CVE-2026-68820
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Microsoft7.00.3%KEV2026-08-11
CVE-2026-65660
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft8.82.1%KEV2026-08-11
CVE-2026-72898
Metabase SQL injection via password reset endpoint
Metabase10.019.0%KEV2026-08-10
CVE-2026-15733
WGDashboard Remote Code Execution vulnerability
WGDashboard9.810.0%2026-08-06
CVE-2026-65400
Apple macOS Improper Authentication Vulnerability
Apple9.81.7%KEV2026-08-06
CVE-2026-5430
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
WSO210.00.6%KEV2026-08-06
CVE-2026-18577
Incomplete patch leads to administrative account takeover
N-able8.214.6%KEV2026-08-02
CVE-2026-18556
Unauthenticated administrative account takeover
N-able8.27.9%KEV2026-08-01
CVE-2026-59310
vCenter directory-traversal vulnerability
VMware9.82.6%KEV2026-07-30
CVE-2026-20316
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Cisco5.335.1%KEV2026-07-29
CVE-2026-42016
Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
jfrog8.18.6%KEV2026-07-27
CVE-2026-63077
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
JetBrains9.889.6%KEV2026-07-27
CVE-2026-16812
VeloCloud Orchestrator OS Command Injection
Arista Networks10.01.0%KEV2026-07-27
CVE-2026-61511
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
vBulletin9.85.6%2026-07-27
CVE-2026-16232
Authentication Bypass in the SmartConsole Login Process Using an Application Token
checkpoint9.378.0%KEV2026-07-22
CVE-2026-8985
Unauthenticated Command Injection
Autel10.07.1%2026-07-21
CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
WordPress9.810.1%KEV2026-07-17
CVE-2026-60137
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
WordPress9.15.9%KEV2026-07-17
CVE-2026-9198
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
IBM9.828.7%KEV2026-07-17
CVE-2026-9586
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
Sangoma9.319.0%KEV2026-07-17
CVE-2021-27137
DD-WRT Stack-Based Buffer Overflow Vulnerability
DD-WRT8.14.0%KEV2026-07-16
CVE-2026-15410
SonicWall SMA1000 Appliances Code Injection Vulnerability
SonicWall7.211.8%KEV2026-07-14
CVE-2026-15409
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall10.06.8%KEV2026-07-14
CVE-2026-55040
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Microsoft9.117.5%KEV2026-07-14
CVE-2026-58644
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft9.815.9%KEV2026-07-14
CVE-2026-50522
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft9.83.0%KEV2026-07-14
CVE-2026-56164
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft5.31.0%KEV2026-07-14
CVE-2026-56155
Active Directory Federation Services Elevation of Privilege Vulnerability
Microsoft7.80.3%KEV2026-07-14
CVE-2026-56291
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
balbooa.com10.014.9%KEV2026-07-09
CVE-2026-59822
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
BerriAI8.80.8%KEV2026-07-08
CVE-2026-43825
Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel
Apache Software Foundation7.313.9%2026-07-06
CVE-2026-53362
ipv6: account for fraggap on the paged allocation path
Linux7.80.7%KEV2026-07-04
CVE-2026-58138
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
conductor-oss9.814.7%2026-06-30
CVE-2026-48282
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe10.042.4%KEV2026-06-30
CVE-2026-8452
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
NetScaler8.81.0%KEV2026-06-30
CVE-2026-56290
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
joomlack.fr10.030.9%KEV2026-06-29
CVE-2026-13545
D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection
D-Link9.05.5%2026-06-29
CVE-2026-49869
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
kestra-io10.02.1%KEV2026-06-26
CVE-2026-53266
netfilter: bridge: make ebt_snat ARP rewrite writable
Linux8.80.6%KEV2026-06-25
CVE-2026-55255
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
langflow-ai8.40.9%KEV2026-06-23
CVE-2026-48908
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
joomshaper.net10.088.5%KEV2026-06-20
CVE-2026-48939
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
icagenda.com10.020.1%KEV2026-06-20
CVE-2026-12569
Remote Code Execution (RCE) vulnerability in Windchill PDMlink
PTC9.346.0%KEV2026-06-18
CVE-2026-7273
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Zyxel8.82.5%KEV2026-06-16
CVE-2026-20262
Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
Cisco6.528.2%KEV2026-06-15
CVE-2026-54420
LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
LiteSpeed Technologies8.50.8%KEV2026-06-14
CVE-2026-48558
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
SimpleHelp10.05.7%KEV2026-06-12
CVE-2026-35273
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle Corporation9.89.4%KEV2026-06-11
CVE-2026-20253
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
Splunk9.896.9%KEV2026-06-10
CVE-2026-20251
Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
Splunk8.832.2%2026-06-10
CVE-2026-10727
-
Ivanti7.213.6%2026-06-09
CVE-2026-25089
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet9.176.1%KEV2026-06-09
CVE-2026-10523
-
ivanti9.953.1%2026-06-09
CVE-2026-10520
Ivanti Sentry OS Command Injection Vulnerability
ivanti10.099.9%KEV2026-06-09
CVE-2026-11645
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google8.82.2%KEV2026-06-08
CVE-2026-50751
User Authentication Bypass in VPN Remote Access and Mobile Access
checkpoint9.36.3%KEV2026-06-08
CVE-2026-7473
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
Arista Networks6.90.6%KEV2026-06-05
CVE-2026-48907
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
joomlacontenteditor.net10.016.2%KEV2026-06-05
CVE-2026-20245
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
Cisco7.825.3%KEV2026-06-04

Frequently Asked Questions

What is a CVE?→

CVE (Common Vulnerabilities and Exposures) is the standard identifier for a publicly known security flaw. Each record has a unique ID, a description, affected products, and references. MITRE coordinates the program and CVE Numbering Authorities assign the IDs.

What does a CVE number mean?→

A CVE ID has the format CVE-YYYY-NNNNN: the year the record was assigned, followed by a sequential number of at least four digits. The number identifies the vulnerability; it says nothing about severity.

What is the difference between CVE, NVD, and CISA KEV?→
  • +CVE is the identifier and base record, published by a CVE Numbering Authority.
  • +NVD is the US National Vulnerability Database. It enriches CVE records with CVSS scores, CWE weakness data, and affected-product data.
  • +CISA KEV is a catalog of CVEs confirmed as exploited in the wild. It is a small subset of all CVEs and carries remediation deadlines for federal agencies.
How do I read a CVE entry?→

Start with the description and the affected vendor, product, and version ranges. Check the CVSS score for severity, the EPSS score for exploitation probability, and the KEV flag for confirmed exploitation. References link to advisories, patches, and technical writeups.

How do I find a specific CVE here?→

Records live at /vulnerabilities/{cve-id}/ in lowercase, for example /vulnerabilities/cve-2026-1234/. This index only covers KEV entries and high-signal records from 2026 onward; for anything else use NVD or MITRE.