CVE Records
Page 4 of 19. 1892 curated CVE records with CVSS, EPSS, and CISA KEV status.
Records
1892 total| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-1448 | D-Link DIR-615 Web Management wiz_policy_3_machine.php os command injection | D-Link | 8.6 | 5.8% | 2026-01-26 | |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability | Microsoft | 7.8 | 70.8% | KEV | 2026-01-26 |
| CVE-2026-1419 | D-Link DCS700l Web Form setDayNightMode command injection | D-Link | 5.8 | 17.2% | 2026-01-26 | |
| CVE-2026-24423 | SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API | SmarterTools | 9.3 | 88.2% | KEV | 2026-01-23 |
| CVE-2026-0770 | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability | Langflow | 9.8 | 63.8% | KEV | 2026-01-23 |
| CVE-2026-0769 | Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability | Langflow | 9.8 | 32.3% | 2026-01-23 | |
| CVE-2026-23760 | SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API | SmarterTools | 9.3 | 96.5% | KEV | 2026-01-22 |
| CVE-2026-1324 | Sangfor Operation and Maintenance Management System SSH Protocol session SessionController os command injection | Sangfor | 9.0 | 7.1% | 2026-01-22 | |
| CVE-2026-21852 | Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation | anthropics | 5.3 | 27.9% | 2026-01-21 | |
| CVE-2026-20045 | Cisco Unified Communications Products Remote Code Execution Vulnerability | Cisco | 8.2 | 4.5% | KEV | 2026-01-21 |
| CVE-2026-24061 | GNU InetUtils Argument Injection Vulnerability | GNU | 9.8 | 99.0% | KEV | 2026-01-21 |
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | Oracle Corporation | 10.0 | 70.9% | KEV | 2026-01-20 |
| CVE-2026-22844 | Zoom Node Deployments - Command Injection | Zoom Communications Inc. | 9.9 | 13.6% | 2026-01-20 | |
| CVE-2026-22219 | Chainlit < 2.9.4 SQLAlchemy Data Layer SSRF via /project/element | Chainlit | 8.3 | 5.1% | 2026-01-19 | |
| CVE-2026-22218 | Chainlit < 2.9.4 Arbitrary File Read via /project/element | Chainlit | 7.1 | 9.5% | 2026-01-19 | |
| CVE-2026-1192 | Tosei Online Store Management System ネット店舗管理システム imode_alldata.php command injection | Tosei | 7.5 | 6.9% | 2026-01-19 | |
| CVE-2026-1125 | D-Link DIR-823X set_wifidog_settings sub_412E7C command injection | D-Link | 7.5 | 15.7% | 2026-01-18 | |
| CVE-2026-1066 | kalcaddle kodbox Compression zip command injection | kalcaddle | 6.5 | 5.6% | 2026-01-17 | |
| CVE-2026-23744 | REC in MCPJam inspector due to HTTP Endpoint exposes | MCPJam | 9.8 | 67.5% | 2026-01-16 | |
| CVE-2026-23550 | WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability | Modular DS | 10.0 | 21.7% | 2026-01-14 | |
| CVE-2026-20872 | NTLM Hash Disclosure Spoofing Vulnerability | Microsoft | 6.5 | 20.1% | 2026-01-13 | |
| CVE-2026-20947 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Microsoft | 8.8 | 18.8% | 2026-01-13 | |
| CVE-2026-20963 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 9.8 | 29.6% | KEV | 2026-01-13 |
| CVE-2026-20925 | NTLM Hash Disclosure Spoofing Vulnerability | Microsoft | 6.5 | 18.2% | 2026-01-13 | |
| CVE-2026-20805 | Desktop Window Manager Information Disclosure Vulnerability | Microsoft | 5.5 | 7.2% | KEV | 2026-01-13 |
| CVE-2025-25249 | Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability | Fortinet | 7.4 | 3.9% | KEV | 2026-01-13 |
| CVE-2026-22755 | Legacy Vivotek Camera Firmware Command Injection in upload_map.cgi | Vivotek | 9.3 | 20.4% | 2026-01-13 | |
| CVE-2026-22812 | OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution | anomalyco | 8.8 | 16.8% | 2026-01-12 | |
| CVE-2026-22200 | osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read | Enhancesoft | 8.7 | 73.9% | 2026-01-12 | |
| CVE-2026-0732 | D-Link DI-8200G upgrade_filter.asp command injection | D-Link | 6.5 | 11.7% | 2026-01-08 | |
| CVE-2026-21876 | OWASP CRS has multipart bypass using multiple content-type parts | coreruleset | 9.3 | 17.5% | 2026-01-08 | |
| CVE-2026-21858 | n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling | n8n-io | 10.0 | 78.4% | 2026-01-07 | |
| CVE-2026-0628 | - | 8.8 | 21.2% | 2026-01-06 | ||
| CVE-2026-0581 | Tenda AC1206 httpd BehaviorManager formBehaviorManager command injection | Tenda | 6.5 | 9.5% | 2026-01-05 | |
| CVE-2025-66376 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability | Zimbra | 7.2 | 19.6% | KEV | 2026-01-05 |
| CVE-2026-21445 | Langflow Missing Authentication on Critical API Endpoints | langflow-ai | 8.8 | 33.3% | 2026-01-02 | |
| CVE-2025-52691 | Upload Arbitrary Files | SmarterTools | 10.0 | 85.7% | KEV | 2025-12-29 |
| CVE-2025-68645 | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability | - | 8.8 | 48.9% | KEV | 2025-12-22 |
| CVE-2025-68613 | n8n Vulnerable to Remote Code Execution via Expression Injection | n8n-io | 10.0 | 99.0% | KEV | 2025-12-19 |
| CVE-2025-14847 | Zlib compressed protocol header length confusion may allow memory read | MongoDB Inc. | 8.7 | 83.2% | KEV | 2025-12-19 |
| CVE-2025-14733 | WatchGuard Firebox iked Out of Bounds Write Vulnerability | WatchGuard | 9.3 | 26.5% | KEV | 2025-12-19 |
| CVE-2025-40602 | SonicWall SMA1000 Missing Authorization Vulnerability | SonicWall | 6.6 | 2.8% | KEV | 2025-12-18 |
| CVE-2025-68461 | RoundCube Webmail Cross-site Scripting Vulnerability | Roundcube | 7.2 | 26.8% | KEV | 2025-12-18 |
| CVE-2025-43529 | Apple Multiple Products Use-After-Free WebKit Vulnerability | Apple | 8.8 | 8.8% | KEV | 2025-12-17 |
| CVE-2025-20393 | Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability | Cisco | 10.0 | 32.4% | KEV | 2025-12-17 |
| CVE-2025-59374 | ASUS Live Update Embedded Malicious Code Vulnerability | ASUS | 9.3 | 1.2% | KEV | 2025-12-17 |
| CVE-2025-37164 | Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability | Hewlett Packard Enterprise (HPE) | 10.0 | 90.2% | KEV | 2025-12-16 |
| CVE-2025-14611 | Gladinet CentreStack and TrioFox Hard Coded AES Keys | Gladinet | 7.1 | 53.3% | KEV | 2025-12-12 |
| CVE-2025-43510 | Apple Multiple Products Improper Locking Vulnerability | Apple | 7.8 | 0.4% | KEV | 2025-12-12 |
| CVE-2025-43520 | Apple Multiple Products Classic Buffer Overflow Vulnerability | Apple | 5.5 | 0.4% | KEV | 2025-12-12 |
| CVE-2025-14174 | Google Chromium Out of Bounds Memory Access Vulnerability | 8.8 | 22.3% | KEV | 2025-12-12 | |
| CVE-2025-8110 | File overwrite in file update API in Gogs | Gogs | 8.7 | 85.2% | KEV | 2025-12-10 |
| CVE-2025-62221 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.5% | KEV | 2025-12-09 |
| CVE-2025-59718 | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability | Fortinet | 9.1 | 68.3% | KEV | 2025-12-09 |
| CVE-2025-48633 | Android Framework Information Disclosure Vulnerability | 5.5 | 0.3% | KEV | 2025-12-08 | |
| CVE-2025-48572 | Android Framework Privilege Escalation Vulnerability | 7.8 | 0.3% | KEV | 2025-12-08 | |
| CVE-2025-34291 | Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE | Langflow | 9.4 | 92.8% | KEV | 2025-12-05 |
| CVE-2025-66644 | Array Networks ArrayOS AG OS Command Injection Vulnerability | Array Networks | 7.2 | 3.4% | KEV | 2025-12-05 |
| CVE-2025-55182 | Meta React Server Components Remote Code Execution Vulnerability | Meta | 10.0 | 99.8% | KEV | 2025-12-03 |
| CVE-2025-62593 | Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack | ray-project | 9.4 | 62.5% | KEV | 2025-11-26 |
| CVE-2025-58360 | GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature | geoserver | 8.2 | 60.5% | KEV | 2025-11-25 |
| CVE-2025-58034 | Fortinet FortiWeb OS Command Injection Vulnerability | Fortinet | 6.7 | 55.6% | KEV | 2025-11-18 |
| CVE-2025-13223 | Google Chromium V8 Type Confusion Vulnerability | 8.8 | 5.0% | KEV | 2025-11-17 | |
| CVE-2025-64446 | Fortinet FortiWeb Path Traversal Vulnerability | Fortinet | 9.4 | 91.8% | KEV | 2025-11-14 |
| CVE-2025-62215 | Windows Kernel Elevation of Privilege Vulnerability | Microsoft | 7.0 | 6.0% | KEV | 2025-11-11 |
| CVE-2025-60710 | Host Process for Windows Tasks Elevation of Privilege Vulnerability | Microsoft | 7.8 | 4.6% | KEV | 2025-11-11 |
| CVE-2025-12480 | Gladinet Triofox Improper Access Control Vulnerability | TrioFox | 9.1 | 95.4% | KEV | 2025-11-10 |
| CVE-2025-64328 | FreePBX Administration GUI is Vulnerable to Authenticated Command Injection | FreePBX | 8.6 | 84.6% | KEV | 2025-11-07 |
| CVE-2023-43000 | Apple Multiple products Use-After-Free Vulnerability | Apple | 8.8 | 3.9% | KEV | 2025-11-05 |
| CVE-2025-11953 | Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests | - | 9.8 | 94.0% | KEV | 2025-11-03 |
| CVE-2025-61757 | Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability | Oracle Corporation | 9.8 | 88.6% | KEV | 2025-10-21 |
| CVE-2025-61932 | Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability | MOTEX Inc. | 9.8 | 2.8% | KEV | 2025-10-20 |
| CVE-2025-53521 | BigIP APM Vulnerability | F5 | 9.8 | 2.3% | KEV | 2025-10-15 |
| CVE-2025-59287 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | Microsoft | 9.8 | 100.0% | KEV | 2025-10-14 |
| CVE-2025-59230 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.7% | KEV | 2025-10-14 |
| CVE-2025-24990 | Windows Agere Modem Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 6.4% | KEV | 2025-10-14 |
| CVE-2025-39964 | crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg | Linux | 7.8 | 1.0% | KEV | 2025-10-13 |
| CVE-2025-61884 | Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability | Oracle Corporation | 7.5 | 95.9% | KEV | 2025-10-12 |
| CVE-2025-11371 | Gladinet CentreStack and TrioFox Local File Inclusion Flaw | Gladinet | 7.5 | 92.1% | KEV | 2025-10-09 |
| CVE-2025-61882 | Oracle E-Business Suite Unspecified Vulnerability | Oracle Corporation | 9.8 | 99.7% | KEV | 2025-10-05 |
| CVE-2025-41244 | VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246) | VMware | 7.8 | 8.4% | KEV | 2025-09-29 |
| CVE-2025-20362 | Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability | Cisco | 6.5 | 87.1% | KEV | 2025-09-25 |
| CVE-2025-20333 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability | Cisco | 9.9 | 70.7% | KEV | 2025-09-25 |
| CVE-2025-20352 | Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability | Cisco | 7.7 | 39.4% | KEV | 2025-09-24 |
| CVE-2025-10585 | Google Chromium V8 Type Confusion Vulnerability | 8.8 | 5.4% | KEV | 2025-09-24 | |
| CVE-2025-26399 | SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability | SolarWinds | 9.8 | 89.5% | KEV | 2025-09-23 |
| CVE-2025-59689 | Libraesva Email Security Gateway Command Injection Vulnerability | Libraesva | 6.1 | 1.9% | KEV | 2025-09-19 |
| CVE-2025-48703 | CWP Control Web Panel OS Command Injection Vulnerability | centos-webpanel | 9.0 | 99.7% | KEV | 2025-09-19 |
| CVE-2025-10035 | Deserialization Vulnerability in GoAnywhere MFT's License Servlet | Fortra | 10.0 | 99.8% | KEV | 2025-09-18 |
| CVE-2025-9242 | WatchGuard Firebox iked Out of Bounds Write Vulnerability | WatchGuard | 9.3 | 91.3% | KEV | 2025-09-17 |
| CVE-2025-21043 | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | Samsung Mobile | 8.8 | 2.1% | KEV | 2025-09-12 |
| CVE-2025-21042 | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | Samsung Mobile | 8.8 | 33.2% | KEV | 2025-09-12 |
| CVE-2025-54236 | Adobe Commerce | Improper Input Validation (CWE-20) | Adobe | 9.1 | 94.5% | KEV | 2025-09-09 |
| CVE-2025-39682 | tls: fix handling of zero-length records on the rx_list | Linux | 9.8 | 2.9% | KEV | 2025-09-05 |
| CVE-2025-48543 | Android Runtime Use-After-Free Vulnerability | 8.8 | 0.5% | KEV | 2025-09-04 | |
| CVE-2025-53690 | Sitecore Products ViewState Deserialization Vulnerability | Sitecore | 9.0 | 51.1% | KEV | 2025-09-03 |
| CVE-2025-9377 | Authenticated RCE via Parental Control command injection | TP-Link Systems Inc. | 8.6 | 33.5% | KEV | 2025-08-29 |
| CVE-2025-55177 | Meta Platforms WhatsApp Incorrect Authorization Vulnerability | 5.4 | 4.3% | KEV | 2025-08-29 | |
| CVE-2025-57819 | FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE | FreePBX | 10.0 | 85.5% | KEV | 2025-08-28 |
| CVE-2025-7775 | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service | NetScaler | 9.2 | 19.6% | KEV | 2025-08-26 |