CVE Records
Page 2 of 19. 1891 curated CVE records with CVSS, EPSS, and CISA KEV status.
Records
1891 total| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-28318 | SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability | SolarWinds | 7.5 | 1.9% | KEV | 2026-06-04 |
| CVE-2026-8037 | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF | Progress Software | 9.6 | 77.4% | KEV | 2026-06-04 |
| CVE-2026-20230 | Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability | Cisco | 8.6 | 88.2% | KEV | 2026-06-03 |
| CVE-2025-48595 | Android Framework Integer Overflow Vulnerability | 8.4 | 1.7% | KEV | 2026-06-01 | |
| CVE-2026-0826 | Poly Voice – Possible Remote Control of Certain Poly Devices | HP Inc. | 9.2 | 32.2% | 2026-06-01 | |
| CVE-2026-10187 | Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow | Totolink | 10.0 | 7.3% | 2026-05-31 | |
| CVE-2026-10061 | TRENDnet TEW-432BRP formWPS command injection | TRENDnet | 6.5 | 5.0% | 2026-05-29 | |
| CVE-2026-10060 | TRENDnet TEW-432BRP formSetRoute command injection | TRENDnet | 6.5 | 5.0% | 2026-05-29 | |
| CVE-2026-46817 | Oracle E-Business Suite Improper Privilege Management Vulnerability | Oracle Corporation | 9.8 | 0.8% | KEV | 2026-05-28 |
| CVE-2026-48027 | Compromised Nx Console version 18.95.0 | nrwl | 9.3 | 1.3% | KEV | 2026-05-27 |
| CVE-2026-48710 | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks | Kludex | 6.5 | 7.1% | KEV | 2026-05-26 |
| CVE-2026-45247 | Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection | Mirasvit | 9.8 | 2.1% | KEV | 2026-05-26 |
| CVE-2026-46368 | luci-app-https-dns-proxy Authenticated Command Injection via setInitAction | mossdef-org | 8.8 | 7.8% | 2026-05-26 | |
| CVE-2026-45659 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 8.8 | 2.7% | KEV | 2026-05-22 |
| CVE-2026-34910 | Ubiquiti UniFi OS Improper Input Validation Vulnerability | Ubiquiti Inc | 10.0 | 45.8% | KEV | 2026-05-22 |
| CVE-2026-34908 | Ubiquiti UniFi OS Improper Access Control Vulnerability | Ubiquiti Inc | 10.0 | 15.2% | KEV | 2026-05-22 |
| CVE-2026-34909 | Ubiquiti UniFi OS Path Traversal Vulnerability | Ubiquiti Inc | 10.0 | 1.8% | KEV | 2026-05-22 |
| CVE-2026-34926 | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | Trend Micro, Inc. | 6.7 | 0.5% | KEV | 2026-05-21 |
| CVE-2026-48172 | LiteSpeed cPanel Plugin Privilege Escalation Vulnerability | LiteSpeed Technologies | 10.0 | 1.0% | KEV | 2026-05-21 |
| CVE-2026-23734 | XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash | xwiki | 9.3 | 19.6% | 2026-05-20 | |
| CVE-2026-9082 | Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 | Drupal | 9.8 | 15.7% | KEV | 2026-05-20 |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability | Microsoft | 7.8 | 0.4% | KEV | 2026-05-20 |
| CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability | Microsoft | 4.0 | 1.3% | KEV | 2026-05-20 |
| CVE-2026-8767 | vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injection | vercel | 5.0 | 7.0% | 2026-05-17 | |
| CVE-2026-8398 | Daemon Tools Lite Embedded Malicious Code Vulnerability | AVB Disc Soft | 9.8 | 1.0% | KEV | 2026-05-15 |
| CVE-2026-42897 | Microsoft Exchange Server Spoofing Vulnerability | Microsoft | 8.1 | 0.5% | KEV | 2026-05-14 |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | Cisco | 10.0 | 91.5% | KEV | 2026-05-14 |
| CVE-2026-0257 | PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities | Palo Alto Networks | 7.8 | 96.4% | KEV | 2026-05-13 |
| CVE-2026-45321 | Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys | @tanstack | 9.6 | 1.1% | KEV | 2026-05-12 |
| CVE-2026-8272 | D-Link DNS-320 webfile_mgr.cgi chown os command injection | D-Link | 5.8 | 6.0% | 2026-05-11 | |
| CVE-2026-8271 | D-Link DNS-320 network_mgr.cgi cgi_upnp_edit os command injection | D-Link | 5.8 | 6.1% | 2026-05-11 | |
| CVE-2026-8265 | Tenda AC6 httpd getLogFile get_log_file os command injection | Tenda | 5.8 | 8.3% | 2026-05-11 | |
| CVE-2026-8264 | Tenda AC6 httpd WifiApScan formWifiApScan os command injection | Tenda | 6.5 | 6.5% | 2026-05-11 | |
| CVE-2026-8263 | Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection | Tenda | 5.8 | 8.7% | 2026-05-11 | |
| CVE-2026-8259 | Tenda AC6 httpd telnet os command injection | Tenda | 5.8 | 8.3% | 2026-05-11 | |
| CVE-2026-8230 | Wavlink NU516U1 login.cgi sys_login1 os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8229 | Wavlink NU516U1 wireless.cgi WifiBasic os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8228 | Wavlink NU516U1 wireless.cgi advance os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8227 | Wavlink NU516U1 adm.cgi wzdapMesh os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8192 | Wavlink NU516U1 adm.cgi wzdap os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8191 | Wavlink NU516U1 adm.cgi wifi_region os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8190 | Wavlink NU516U1 adm.cgi wan os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8189 | Wavlink NU516U1 adm.cgi wzdrepeater os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8188 | Wavlink NU516U1 adm.cgi change_wifi_password os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-42208 | LiteLLM: SQL injection in Proxy API key verification | BerriAI | 9.3 | 5.8% | KEV | 2026-05-08 |
| CVE-2026-42271 | LiteLLM: Authenticated command execution via MCP stdio test endpoints | BerriAI | 8.7 | 92.6% | KEV | 2026-05-08 |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability | Ivanti | 7.2 | 2.5% | KEV | 2026-05-07 |
| CVE-2026-0300 | PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal | Palo Alto Networks | 9.3 | 31.7% | KEV | 2026-05-06 |
| CVE-2026-41922 | WDR201A WiFi Extender OS Command Injection via wireless.cgi | Shenzhen Yipu Commercial and Trading Co., Ltd | 9.3 | 6.7% | 2026-05-04 | |
| CVE-2026-23918 | Apache HTTP Server: http2: double free and possible RCE on early reset | Apache Software Foundation | 8.8 | 49.7% | 2026-05-04 | |
| CVE-2026-7690 | Wavlink WL-WN570HA1 adm.cgi set_sys_adm command injection | Wavlink | 6.5 | 6.0% | 2026-05-03 | |
| CVE-2026-7609 | TRENDnet TEW-821DAP Firmware Udpate diagnostic tools_diagnostic os command injection | TRENDnet | 6.5 | 5.7% | 2026-05-02 | |
| CVE-2026-7608 | TRENDnet TEW-821DAP tools_diagnostic os command injection | TRENDnet | 5.5 | 9.8% | 2026-05-02 | |
| CVE-2026-41940 | WebPros cPanel and WHM Authentication Bypass via Login Flow | WebPros | 9.8 | 98.5% | KEV | 2026-04-29 |
| CVE-2026-7102 | Tenda F456 httpd WriteFacMac FromWriteFacMac command injection | Tenda | 6.5 | 6.5% | 2026-04-27 | |
| CVE-2026-6992 | Linksys MR9600 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus os command injection | Linksys | 8.6 | 8.0% | 2026-04-25 | |
| CVE-2026-6989 | Tenda F453 Telnet Service telnet TendaTelnet command injection | Tenda | 6.5 | 6.3% | 2026-04-25 | |
| CVE-2026-31431 | crypto: algif_aead - Revert to operating out-of-place | Linux | 7.8 | 3.4% | KEV | 2026-04-22 |
| CVE-2026-20147 | Cisco Identity Services Engine Remote Code Execution Vulnerability | Cisco | 9.9 | 10.4% | 2026-04-15 | |
| CVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability | Microsoft | 9.8 | 1.6% | KEV | 2026-04-14 |
| CVE-2026-32201 | Microsoft SharePoint Server Spoofing Vulnerability | Microsoft | 6.5 | 1.0% | KEV | 2026-04-14 |
| CVE-2026-33825 | Microsoft Defender Elevation of Privilege Vulnerability | Microsoft | 7.8 | 0.4% | KEV | 2026-04-14 |
| CVE-2026-32202 | Windows Shell Spoofing Vulnerability | Microsoft | 4.3 | 4.9% | KEV | 2026-04-14 |
| CVE-2026-20945 | Microsoft SharePoint Server Spoofing Vulnerability | Microsoft | 4.6 | 19.1% | 2026-04-14 | |
| CVE-2026-39808 | Fortinet FortiSandbox OS Command Injection Vulnerability | Fortinet | 9.1 | 47.4% | KEV | 2026-04-14 |
| CVE-2026-34621 | Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321) | Adobe | 8.6 | 2.2% | KEV | 2026-04-11 |
| CVE-2026-34486 | Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor | Apache Software Foundation | 7.5 | 6.6% | KEV | 2026-04-09 |
| CVE-2026-39987 | marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass | marimo-team | 9.3 | 37.9% | KEV | 2026-04-09 |
| CVE-2026-5844 | D-Link DIR-882 HNAP1 SetNetworkSettings prog.cgi sprintf os command injection | D-Link | 8.6 | 6.2% | 2026-04-09 | |
| CVE-2026-23696 | Windmill < 1.603.3 File Ownership Handling SQLi RCE | Windmill Labs | 9.9 | 13.6% | 2026-04-07 | |
| CVE-2026-22679 | Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint | Weaver Network Co., Ltd. | 9.8 | 20.4% | 2026-04-07 | |
| CVE-2026-22666 | Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard() | Dolibarr | 8.6 | 15.5% | 2026-04-07 | |
| CVE-2026-34197 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans | Apache Software Foundation | 8.8 | 15.5% | KEV | 2026-04-07 |
| CVE-2026-0740 | Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload | SaturdayDrive | 9.8 | 62.9% | 2026-04-07 | |
| CVE-2026-35616 | Fortinet FortiClient EMS Improper Access Control Vulnerability | Fortinet | 9.1 | 9.1% | KEV | 2026-04-04 |
| CVE-2026-5355 | Trendnet TEW-657BRM setup.cgi vpn_drop os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5354 | Trendnet TEW-657BRM setup.cgi vpn_connect os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5353 | Trendnet TEW-657BRM setup.cgi ping_test os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5352 | Trendnet TEW-657BRM setup.cgi edit os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5351 | Trendnet TEW-657BRM setup.cgi add_wps_client os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5339 | Tenda G103 Setting gpon.lua action_set_net_settings command injection | Tenda | 5.8 | 10.2% | 2026-04-02 | |
| CVE-2026-5338 | Tenda G103 Setting system.lua action_set_system_settings command injection | Tenda | 5.8 | 8.3% | 2026-04-02 | |
| CVE-2026-5281 | Google Dawn Use-After-Free Vulnerability | 8.8 | 0.7% | KEV | 2026-04-01 | |
| CVE-2026-5184 | TRENDnet TEW-713RE setSysAdm command injection | TRENDnet | 6.5 | 8.5% | 2026-03-31 | |
| CVE-2026-5183 | TRENDnet TEW-713RE addRouting sub_421494 command injection | TRENDnet | 6.5 | 8.9% | 2026-03-31 | |
| CVE-2026-5153 | Tenda CH22 WriteFacMac FormWriteFacMac command injection | Tenda | 6.5 | 6.5% | 2026-03-30 | |
| CVE-2026-4257 | Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality | supsysticcom | 9.8 | 32.8% | 2026-03-30 | |
| CVE-2026-21710 | - | nodejs | 7.5 | 25.0% | 2026-03-30 | |
| CVE-2026-3502 | TrueConf Client Update Integrity Verification Bypass | TrueConf | 7.8 | 0.3% | KEV | 2026-03-30 |
| CVE-2026-33526 | Squid vulnerable to Denial of Service in ICP Request handling | squid-cache | 9.2 | 12.8% | 2026-03-26 | |
| CVE-2026-33634 | Trivy ecosystem supply chain briefly compromised | aquasecurity | 9.4 | 1.7% | KEV | 2026-03-23 |
| CVE-2026-3055 | Insufficient input validation leading to memory overread | NetScaler | 9.3 | 4.0% | KEV | 2026-03-23 |
| CVE-2026-33478 | AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection | WWBN | 10.0 | 11.2% | 2026-03-23 | |
| CVE-2026-4585 | Tiandy Easy7 Integrated Management Platform Configuration ImportSystemConfiguration.jsp os command injection | Tiandy | 10.0 | 5.7% | 2026-03-23 | |
| CVE-2026-4558 | Linksys MR9600 SmartConnect.lua smartConnectConfigure os command injection | Linksys | 9.0 | 7.8% | 2026-03-22 | |
| CVE-2026-4554 | Tenda F453 WriteFacMac FormWriteFacMac privilege escalation | Tenda | 6.5 | 6.5% | 2026-03-22 | |
| CVE-2026-33017 | Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint | langflow-ai | 9.3 | 24.8% | KEV | 2026-03-20 |
| CVE-2026-22557 | - | Ubiquiti Inc | 10.0 | 28.1% | 2026-03-19 | |
| CVE-2026-4253 | Tenda AC8 Web UploadCfg route_set_user_policy_rule os command injection | Tenda | 5.8 | 8.2% | 2026-03-16 | |
| CVE-2026-4228 | LB-LINK BL-WR9000 set_wifi sub_458754 command injection | LB-LINK | 6.5 | 8.9% | 2026-03-16 |