| 2026-09-27 | CVE-2026-84388 | Fortinet FortiPAM Chrome Extension All 8.0 and 7.4 Versions Improperly Restricts Rendered UI Layers, Potentially Enabling Clickjacking Attacks Against Users of the PAM Interface | 9.6 Critical | New |
| 2026-09-26 | CVE-2026-80152 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Set Script Schedule Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root | 9.1 Critical | New |
| 2026-09-26 | CVE-2026-80151 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Set NFS Download Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root | 9.1 Critical | New |
| 2026-09-26 | CVE-2026-80150 | Lantronix Serial Console Servers Allow Unauthenticated Attackers to Redirect WebTelnet Connections to Arbitrary Hosts via a Tampered rooturl Parameter | 7.5 High | New |
| 2026-09-26 | CVE-2026-80149 | Lantronix Serial Console Servers Allow Unauthenticated Attackers to Redirect WebSSH Connections to Arbitrary Hosts via a Tampered rooturl Parameter | 8.6 High | New |
| 2026-09-26 | CVE-2026-80148 | Overlong Username in Lantronix Serial Console Server WebSSH Truncates the Device IP Suffix in snprintf, Redirecting SSH Connections to Attacker-Controlled Hosts | 8.6 High | New |
| 2026-09-26 | CVE-2026-80146 | Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root | 9.9 Critical | New |
| 2026-09-26 | CVE-2026-67279 | MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 28 | 6.5 Medium | KEV |
| 2026-09-26 | CVE-2026-100561 | OpenClaw exec approval policy bypass lets an agent run arbitrary host commands without re-prompting | 8.0 High | New |
| 2026-09-25 | CVE-2026-93616 | Path Traversal Across Check Point Management and Log Server Infrastructure Missed the September 25th CISA KEV Window; Covered Organizations Are Now Out of Compliance | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-85046 | Google Chromium V8's Type Confusion Allows Remote Attackers to Execute Arbitrary Code or Escape the Browser Sandbox via a Crafted Web Page | 8.8 High | KEV |
| 2026-09-25 | CVE-2026-81578 | PaperCut NG/MF's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Perform Administrative Actions Without Logging In; CISA's September 14th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-76461 | Cisco Secure Email Gateway's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Compromise the Email Security Platform | 9.8 Critical | KEV |
| 2026-09-25 | CVE-2026-76460 | Cisco Identity Services Engine's Incorrect Use of Privileged APIs Allows Unauthenticated Remote Attackers to Gain Full Administrative Control; CISA's September 19th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-75650 | Adobe Commerce and Magento's Template Engine Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Server-Side Code on the E-Commerce Platform | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-98123 | Linux Kernel SCTP ASCONF-ACK Parameter Walk Loops Indefinitely on an Unpadded Short Parameter Due to SCTP_PAD4 Rounding, Causing a Soft Lockup | — | New |
| 2026-09-25 | CVE-2026-98044 | Linux Kernel BPF Verifier Fails to Reject Legacy Packet Loads from Callback Subprograms, Which Can Model a Failed BPF_LD_ABS as an Implicit Zero Return Causing Incorrect Program Behavior | — | New |
| 2026-09-25 | CVE-2026-93815 | Linux Kernel au1000 Ethernet Driver Calls free_irq While Holding a Spinlock with Interrupts Disabled, Which Can Sleep and Deadlock on Platforms Without Threaded IRQs | — | New |
| 2026-09-25 | CVE-2026-93804 | Linux Kernel mac80211 IBSS Leave Path Flushes Stations and Turns Off the Carrier Without Waiting for In-Flight TX to Complete, Leading to Use-After-Free on Concurrent Packet Transmission | — | New |
| 2026-09-25 | CVE-2026-93345 | MikroTik RouterOS Labelled-VPN NLRI Prefix-Length Underflow Holds the BGP Plane Down Indefinitely; Fix Is Only in a Development Build | 7.5 High | New |
| 2026-09-25 | CVE-2026-67278 | MikroTik RouterOS Accepts Malformed RSA/PKCS#1 v1.5 Signatures Across TLS and SSH, and Its Trust Store Includes an e=3 Root CA, Letting a Network Attacker Forge Valid Signatures Without the Private Key | 9.1 Critical | Updated |
| 2026-09-25 | CVE-2026-5430 | WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 27 | 10.0 Critical | KEV |
| 2026-09-25 | CVE-2026-51773 | OpenStack Glance Store VMware Datastore Driver Attaches Authentication Headers Without Validating the Destination Host, Leaking Credentials to Attacker-Controlled Servers | 8.1 High | New |
| 2026-09-24 | CVE-2026-9203 | MarkLogic SSRF Flaw Exposes Cloud Instance Credentials to Low-Privilege Users | 8.5 High | Updated |
| 2026-09-24 | CVE-2026-9195 | Crafted Links Let Attackers Hijack MarkLogic Administrator Sessions Through Query Console XSS | 9.3 Critical | Updated |
| 2026-09-24 | CVE-2026-9193 | Low-Privilege Hadoop Role Escalates to Full Control of MarkLogic's Security Database | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-9192 | Unauthenticated Attackers Can Impersonate Any MarkLogic User Through ODBC Authentication Bypass | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-9190 | HTTP Request Smuggling Bypasses MarkLogic Authentication and Hijacks Sessions | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-9089 | ConnectWise Automate agent trusts unverified plugin and update downloads, fixed in 2026.5 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-8709 | MarkLogic's REST document-patch API lets low-privileged users seize administrator control | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-7557 | Unauthenticated attackers impersonate any MarkLogic administrator through a SAML signature flaw | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-7329 | MarkLogic's SQL, SPARQL, and Optic query interfaces open a path from low-privileged access to full admin | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-7327 | MarkLogic's document-processing pipeline lets an administrative REST role escalate further, exposing server-side data | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-7326 | A CSRF flaw in MarkLogic's Admin UI lets attackers hijack lured administrators for configuration changes | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-71474 | Red Hat insights-client logs a long-lived OpenShift pull-secret token that local pod-log access can expose | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-68981 | Apache NiFi's gzip request handling bypasses size limits, opening a memory-exhaustion path, fixed in 2.11.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-68980 | Apache NiFi's asset-deletion API skips ownership checks across Parameter Contexts, fixed in 2.11.0 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-68979 | Missing authorization on Apache NiFi's Parameter Context updates can trigger code execution, fixed in 2.11.0 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-68060 | Pre-authentication attackers can exhaust memory in Apache Qpid Broker-J via oversized type handling, fixed in 10.1.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67589 | Apache Qpid ProtonJ2 lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.2.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67588 | Unbounded symbol caching in Apache Qpid ProtonJ2 lets pre-authentication attackers exhaust memory, fixed in 1.2.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67551 | Apache Qpid Proton-Dotnet lets pre-authentication attackers trigger oversized memory allocations, fixed in 1.1.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-67465 | Unbounded symbol caching in Apache Qpid Proton-Dotnet lets pre-authentication attackers exhaust memory, fixed in 1.1.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66756 | A critical alternate-path flaw in Apache Tika precedes the 4.0.0-beta-1 fix, CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-66755 | Apache Tika's ISA-Tab parser lets crafted filenames leak arbitrary file contents into extracted text, fixed in 3.3.2 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66273 | Apache Qpid Proton-J lets pre-authentication attackers trigger oversized memory allocations, fixed in 0.35.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66257 | Unbounded symbol caching in Apache Qpid Proton-J lets pre-authentication attackers exhaust memory, fixed in 0.35.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-66015 | A JFrog Platform privilege-escalation flaw grants temporary admin access under admin-provisioned accounts | 7.2 High | New |
| 2026-09-24 | CVE-2026-66014 | An authentication weakness in JFrog Artifactory's internal request processing lets attackers escalate access | 8.8 High | New |
| 2026-09-24 | CVE-2026-65922 | Limited-access JFrog Artifactory users can write to restricted internal metadata under specific conditions | 7.1 High | New |
| 2026-09-24 | CVE-2026-65617 | A deserialization flaw in JFrog Artifactory package handling lets low-privileged users compromise confidentiality, integrity, and availability | 8.8 High | New |
| 2026-09-24 | CVE-2026-65616 | Flawed refresh-token signature validation lets non-admin JFrog users obtain a signed administrator token | 8.8 High | New |
| 2026-09-24 | CVE-2026-62391 | An incomplete fix for a prior Kyuubi flaw still lets clients bypass the local-directory allowlist via Spark config aliases, fixed in 1.12.0 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-61372 | A path traversal vulnerability in Apache Jena Fuseki is fixed in 6.2.0 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-6066 | ConnectWise Automate's Solution Center allowed unencrypted client-server traffic open to interception, fixed in 2026.4 | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-60413 | An information-exposure flaw in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-60412 | Insecure deserialization in Oracle Outside In Core lets a logged-in attacker take full control, CVSS 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-60393 | Unauthenticated network attackers can reach all Oracle Hyperion Infrastructure Technology data over HTTP, CVSS 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-60392 | Insecure deserialization in Oracle's Outside In PDF Export SDK lets a logged-in attacker take full control, CVSS 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-60391 | Unauthenticated network attackers can reach all Oracle Hyperion Financial Reporting data over HTTP, CVSS 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-6023 | Tampered RadFilter state in Telerik UI for ASP.NET AJAX enables server-side remote code execution | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-6022 | Telerik UI for ASP.NET AJAX chunked upload flaw lets attackers bypass size limits and exhaust disk space | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-5483 | Red Hat OpenShift AI's odh-dashboard leaks Kubernetes service account tokens through a NodeJS endpoint | 8.5 High | New |
| 2026-09-24 | CVE-2026-54100 | Red Hat's Windows Machine Config Operator skips SSH host-key checks, letting adjacent attackers capture node bootstrap credentials | 8.3 High | Updated |
| 2026-09-24 | CVE-2026-54099 | A compromised Windows node can forge a cluster-administrator certificate through WMCO's CSR auto-approver, CVSS 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-52680 | Path traversal in Apache Kyuubi's REST batch upload lets remote attackers write files outside the intended directory, fixed in 1.12.0 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-5174 | Improper input validation in Progress MOVEit Automation opens a path to privilege escalation | 7.7 High | Updated |
| 2026-09-24 | CVE-2026-47629 | Improper input validation in NVIDIA Triton Inference Server on Linux can trigger denial of service | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-47628 | Unbounded resource allocation in NVIDIA Triton Inference Server on Linux opens a denial-of-service path | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-47627 | A critical path-traversal flaw in NVIDIA Triton Inference Server on Linux enables denial of service, CVSS 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-4740 | Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation | 8.2 High | Updated |
| 2026-09-24 | CVE-2026-42017 | An event-handling flaw in JFrog Artifactory exposes privileged authorization material to lower-privileged users | 8.8 High | New |
| 2026-09-24 | CVE-2026-41724 | Stored XSS in VMware Cloud Foundation Operations lets privileged users trigger admin actions via injected scripts | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-41723 | A stored XSS spanning VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-41722 | Another stored XSS across VMware Cloud Foundation Operations and vSphere lets privileged users trigger admin actions via injected scripts | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-41702 | A TOCTOU flaw in a VMware Fusion SETUID binary lets local non-admin users escalate to root | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-4048 | Authenticated Command Injection in Progress LoadMaster UI Enables Remote Code Execution | 8.4 High | EPSS-Imminent |
| 2026-09-24 | CVE-2026-40141 | A critical query-injection flaw in BeyondTrust Remote Support lets low-privileged users reach unauthorized resources, CVSS 9.9 | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2026-40140 | Unauthenticated attackers can crash BeyondTrust Remote Support appliances via a network-communication flaw | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-40139 | Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-40138 | BeyondTrust Privileged Remote Access Shares Pre-Authentication Bypass Flaw with Remote Support | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-39815 | SQL Injection in Fortinet FortiDDoS-F 7.2 May Allow Unauthorized Data Access | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-39304 | Apache ActiveMQ NIO SSL Transports Vulnerable to Denial-of-Service via Memory Exhaustion | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-3692 | Low-Privilege OS Command Injection in Progress Flowmon Reporting Component | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-35554 | Race Condition in Apache Kafka Producer Can Silently Deliver Messages to Wrong Topics | 8.7 High | Updated |
| 2026-09-24 | CVE-2026-3519 | Progress LoadMaster API Exposes Authenticated Command Injection for VS Administration Role | 8.4 High | EPSS-Imminent |
| 2026-09-24 | CVE-2026-34487 | Apache Tomcat Cloud Clustering Component Logs Kubernetes Credentials in Plain Text | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-34483 | Improper Output Encoding in Apache Tomcat JsonAccessLogValve Enables Log Injection | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-34478 | Apache Log4j RFC 5424 Layout Vulnerable to Log Injection in Versions 2.21 through 2.25 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-34020 | Apache OpenMeetings REST Login Exposes Credentials in URL Query String | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-33266 | Apache OpenMeetings Uses Default Hard-Coded Encryption Key for Remember-Me Cookies | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-33105 | Critical Authorization Bypass in Microsoft Azure Kubernetes Service Allows Network Privilege Escalation | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-32590 | Unsafe Deserialization in Red Hat Quay Resumable Upload Handling | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-32200 | Use-After-Free in Microsoft PowerPoint Enables Local Code Execution | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32199 | Use-After-Free in Microsoft Office Excel Enables Local Code Execution | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32198 | Microsoft Office Excel Use-After-Free Lets Local Attacker Execute Code | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32197 | Local Code Execution via Use-After-Free in Microsoft Office Excel | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32190 | Use-After-Free in Microsoft Office Enables Local Code Execution | 8.4 High | Updated |
| 2026-09-24 | CVE-2026-32189 | Microsoft Office Excel Carries Additional Use-After-Free Code Execution Risk | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32188 | Out-of-Bounds Read in Microsoft Office Excel Discloses Information to Local Attackers | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-32186 | Critical SSRF in Microsoft Bing Enables Network-Based Privilege Escalation | 10.0 Critical | Updated |
| 2026-09-24 | CVE-2026-32184 | Deserialization Flaw in Microsoft HPC Pack Allows Authorized User to Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32153 | Use-After-Free in Windows Speech Component Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-32091 | Race Condition in Microsoft Brokering File System Allows Unauthorized Privilege Escalation | 8.4 High | Updated |
| 2026-09-24 | CVE-2026-29145 | Apache Tomcat CLIENT_CERT Authentication Bypass When Soft Fail Is Disabled | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-29129 | Apache Tomcat Fails to Preserve Configured Cipher Preference Order | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-28814 | Apache JSPWiki Renders Wiki Markup Without Authentication, Exposing Sensitive Data | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-28813 | JSON Hijacking in Apache JSPWiki Enables Cross-Site Request Forgery | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-28812 | Apache JSPWiki UserManager Spoofing Flaw Allows Attackers to Escalate Privileges | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-28811 | Apache JSPWiki Leaks Internal Information via Debug Messages | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-27914 | Improper Access Control in Microsoft Management Console Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-27909 | Use-After-Free in Windows Search Component Allows Authorized Attacker to Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-27314 | Apache Cassandra 5.0 CREATE Permission Allows Privilege Escalation in mTLS Environments | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-26181 | Use-After-Free in Microsoft Brokering File System Lets Authorized User Escalate Privileges | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-26170 | Input Validation Flaw in Microsoft PowerShell Allows Local Privilege Escalation | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-26149 | Control Sequence Injection in Microsoft Power Apps Enables Network-Based Spoofing | 9.0 Critical | Updated |
| 2026-09-24 | CVE-2026-26143 | Improper Input Validation in Microsoft PowerShell Allows Unauthorized Security Feature Bypass | 7.8 High | New |
| 2026-09-24 | CVE-2026-24880 | Apache Tomcat Chunk Extension Parsing Allows HTTP Request Smuggling | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24222 | NVIDIA NeMoClaw Sandbox Initialization Exposes System Information to Remote Attackers | 8.6 High | Updated |
| 2026-09-24 | CVE-2026-24217 | Path Traversal in NVIDIA BioNeMo Core Allows Malicious File to Escape Sandbox | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-24216 | Deserialization of Untrusted Data in NVIDIA BioNeMo Enables Code Execution | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-24214 | Integer Overflow in NVIDIA Triton Inference Server DALI Backend | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-24213 | Out-of-Bounds Read in NVIDIA Triton Inference Server DALI Backend | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-24210 | Integer Overflow in NVIDIA Triton Inference Server Allows Code Execution or Denial of Service | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24209 | Path Traversal Vulnerability in NVIDIA Triton Inference Server | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24207 | Critical Authentication Bypass in NVIDIA Triton Inference Server | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-24206 | NVIDIA Triton Inference Server Authentication Bypass via Alternate Path Scores 7.3 | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-24188 | NVIDIA TensorRT Out-of-Bounds Write Scores 8.2 | 8.2 High | Updated |
| 2026-09-24 | CVE-2026-24186 | NVIDIA NVFlare Deserialization of Untrusted Data Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-24184 | NVIDIA Cumulus Linux Buffer Overflow Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24183 | NVIDIA Cumulus Linux Excessive-Privilege Execution Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-24178 | Critical NVIDIA NVFlare Authorization Bypass via User-Controlled Key Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-24175 | NVIDIA Triton Inference Server Uncaught Exception Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24174 | NVIDIA Triton Inference Server Numeric Type Conversion Error Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24173 | NVIDIA Triton Inference Server Integer Overflow Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24163 | NVIDIA TensorRT-LLM Deserialization Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-24156 | NVIDIA Data Loading Library Deserialization Vulnerability Scores 7.3 | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-24146 | NVIDIA Triton Inference Server Oversized Allocation Request Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23708 | Fortinet FortiSOAR Authentication Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23657 | Microsoft Office LTSC Use-After-Free Vulnerability Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23429 | Linux Kernel IOMMU SVA Use-After-Free in Unbind Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23428 | Critical Linux Kernel ksmbd Use-After-Free in Compound Request Handling Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-23427 | Critical Linux Kernel ksmbd Use-After-Free in Durable Handle Replay Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-23425 | Linux Kernel KVM arm64 ID Register Initialization Flaw Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-23424 | Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.1 | 7.1 High | Updated |
| 2026-09-24 | CVE-2026-23422 | Linux Kernel dpaa2-switch Out-of-Bounds Write from Malformed Interrupt Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23415 | Linux Kernel Futex Use-After-Free between Key Lookup and VMA Policy Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23414 | Linux Kernel TLS Memory Leak in Async Decrypt Wait Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-23413 | Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23412 | Linux Kernel Netfilter BPF Use-After-Free in Hook Memory Release Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23411 | Linux Kernel AppArmor Race Condition Frees i_private Data Early Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23410 | Linux Kernel AppArmor Race on Rawdata Dereference Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23408 | Linux Kernel AppArmor Double Free of Namespace Name Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-23407 | Linux Kernel AppArmor Out-of-Bounds Read in DFA Verification Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-22828 | Fortinet FortiManager and FortiAnalyzer Cloud Heap Overflow Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-22619 | Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-22016 | Oracle Java SE JAXP Component Exposes Sensitive Information, Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-22011 | Oracle Applications DBA ADPatch Access Control Weakness Scores 7.6 | 7.6 High | Updated |
| 2026-09-24 | CVE-2026-22010 | Oracle Financial Services Infrastructure Platform Access Control Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-21997 | Oracle Life Sciences Empirica Signal Access Control Weakness Scores 8.5 | 8.5 High | Updated |
| 2026-09-24 | CVE-2026-21662 | Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-20160 | Critical Cisco Smart Software Manager On-Prem Resource Exposure Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-20155 | Cisco Evolved Programmable Network Manager Missing Authorization Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2026-20151 | Cisco Smart Software Manager On-Prem Leaks Sensitive Data in Transmitted Requests | 7.3 High | Updated |
| 2026-09-24 | CVE-2026-20094 | Cisco UCS Command Injection Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2026-18381 | Red Hat Cost Management Metrics Operator SSRF via Crafted Custom Resource Scores 7.6 | 7.6 High | Updated |
| 2026-09-24 | CVE-2026-18378 | Red Hat Cost Management Metrics Operator SSRF via Arbitrary Upload URL Scores 7.6 | 7.6 High | Updated |
| 2026-09-24 | CVE-2026-16443 | Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.4 | 7.4 High | Updated |
| 2026-09-24 | CVE-2026-0270 | Palo Alto Networks Cortex XSOAR Path Traversal Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-0265 | Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-0264 | Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2026-0262 | Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE1808 | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-0261 | Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2026-0258 | Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.1 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-0244 | Palo Alto Networks Prisma SD-WAN Certificate Validation Flaw Scores 8.1 | 8.1 High | Updated |
| 2026-09-24 | CVE-2026-0237 | Palo Alto Networks Prisma Browser Alternate Path Protection Flaw Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-0236 | Palo Alto Networks Prisma Browser Code Injection Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2026-0233 | Palo Alto Networks ADEM Certificate Validation Flaw Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2025-7406 | Nokia MantaRay NM sudo Privilege Escalation Reaches Root, Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2025-65114 | Apache Traffic Server HTTP Request Smuggling Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-62188 | Apache DolphinScheduler Sensitive Information Exposure Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-61848 | Fortinet FortiManager SQL Injection Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2025-58136 | Apache Traffic Server Incorrect Control Flow Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-53681 | Fortinet FortiMail SQL Injection Scores 7.2 | 7.2 High | Updated |
| 2026-09-24 | CVE-2025-33255 | NVIDIA TensorRT-LLM MPI Server Deserialization Flaw Scores 7.5 | 7.5 High | Updated |
| 2026-09-24 | CVE-2025-24818 | Nokia MantaRay NM OS Command Injection in Log Search Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2025-24817 | Nokia MantaRay NM OS Command Injection in Symptom Collector Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2025-24815 | Nokia MantaRay NM Unrestricted File Upload Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2025-14774 | ABB T-MAC Plus Incorrect Authorization Scores 7.4 | 7.4 High | Updated |
| 2026-09-24 | CVE-2025-14773 | ABB T-MAC Plus Cross-Site Scripting Scores 8.0 | 8.0 High | Updated |
| 2026-09-24 | CVE-2025-14772 | ABB T-MAC Plus Authorization Bypass via User-Controlled Key Scores 8.8 | 8.8 High | Updated |
| 2026-09-24 | CVE-2025-14771 | ABB T-MAC Plus Exposes Files to External Parties, Scores 9.9 | 9.9 Critical | Updated |
| 2026-09-24 | CVE-2025-12694 | Forcepoint VPN Client Excessive-Privilege Execution Scores 7.8 | 7.8 High | Updated |
| 2026-09-24 | CVE-2017-20236 | ProSoft ICX35-HWC OS Command Injection via Web UI Scores 9.8 | 9.8 Critical | Updated |
| 2026-09-24 | CVE-2017-20235 | ProSoft ICX35-HWC Authentication Bypass in Web Interface Scores 9.1 | 9.1 Critical | Updated |
| 2026-09-24 | CVE-2026-89028 | MikroTik RouterOS SMB1 SessionSetupAndX Handler Integer Underflow in uniPwdLen Corrupts Adjacent Heap Memory | 7.5 High | New |
| 2026-09-24 | CVE-2026-80156 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Strips Backslash Characters but Not Forward Slashes During Path Validation, Letting Authenticated Attackers Write Files to Arbitrary Filesystem Locations | 9.1 Critical | New |
| 2026-09-24 | CVE-2026-80155 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Requires No Authentication, Allowing Unauthenticated Attackers to Read Configuration Files and Upload to Arbitrary Filesystem Locations, Scoring CVSS 10.0 | 10.0 Critical | New |
| 2026-09-24 | CVE-2026-80154 | Lantronix SLC8000, SLC9000, EMG, and SLB Series Web Portal Derives Session Tokens Deterministically from Device Model and Current Second, Letting Unauthenticated Attackers Predict and Forge Valid Sessions on All Firmware Versions | 9.6 Critical | New |
| 2026-09-24 | CVE-2026-80147 | Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root | 9.9 Critical | New |
| 2026-09-24 | CVE-2026-80145 | Lantronix SLC8000/SLC9000 and EMG Series Set CIFS Password Command Passes User Input Unsanitized to system(), Enabling Authenticated Users with Services Permission to Run Commands as Root | 9.1 Critical | New |
| 2026-09-24 | CVE-2026-80144 | Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution | 9.9 Critical | New |
| 2026-09-24 | CVE-2026-80143 | Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution | 9.9 Critical | New |
| 2026-09-24 | CVE-2026-5857 | Contiki-NG MQTT Client parse_publish_vhdr Persists a Flag Past an Over-Length Topic, Skipping the Length Guard on the Next Segment and Overflowing the Topic Buffer | 8.1 High | New |
| 2026-09-24 | CVE-2026-48594 | elixir-tesla DecompressResponse Middleware Decompresses HTTP Response Bodies Without a Size Limit, Enabling Denial of Service via Decompression Bombs | 7.5 High | Updated |
| 2026-09-24 | CVE-2026-28325 | SolarWinds Observability Self-Hosted unauthenticated remote code execution via deserialization in specific communication mode | 8.8 High | New |
| 2026-09-24 | CVE-2026-28324 | SolarWinds Observability Self-Hosted Insufficient Integrity Checks Allow Unauthenticated Remote Code Execution on Non-Default, Non-Hardened Installations | 9.8 Critical | New |
| 2026-09-24 | CVE-2026-13249 | Honeywell PD45 Industrial Printer F10.19.010040 Web Management Interface Allows Unauthenticated File Upload of Attacker-Controlled Files, Enabling Remote Code Execution Without Credentials | 9.8 Critical | New |
| 2026-09-24 | CVE-2026-13248 | Honeywell PD45 Industrial Printer Fingerprint command interface allows authenticated admin to write arbitrary files and execute code | 8.8 High | New |
| 2026-09-24 | CVE-2008-4128 | Cisco IOS's Multiple Cross-Site Request Forgery Flaws Allow Remote Attackers to Execute Arbitrary Commands via Show Privilege and Alias Exec Requests; CISA's July 16th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-23 | CVE-2026-3517 | Progress LoadMaster OS Command Injection via Geo Administration API Scores 8.4 | 8.4 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-29146 | Apache Tomcat EncryptInterceptor Padding Oracle Scores 7.5 | 7.5 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-20180 | Critical Cisco ISE Path Traversal Enables Remote Code Execution, Scores 9.9 | 9.9 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-39813 | Fortinet FortiSandbox Path Traversal Enables Privilege Escalation, Scores 9.8 | 9.8 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-40688 | Fortinet FortiWeb Out-of-Bounds Write Scores 7.2 | 7.2 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-4670 | Critical Progress MOVEit Automation Authentication Bypass Scores 9.8 | 9.8 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-59309 | Critical VMware vCenter Authentication Bypass in Directory Service Scores 9.8 | 9.8 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-3518 | Progress LoadMaster OS Command Injection via Full-Permission API Scores 8.4 | 8.4 High | EPSS-Imminent |
| 2026-09-23 | CVE-2026-20147 | Critical Cisco ISE and ISE-PIC Command Injection Scores 9.9 | 9.9 Critical | EPSS-Imminent |
| 2026-09-23 | CVE-2026-94127 | CISA's September 25th Remediation Deadline for F5 BIG-IP APM's OAuth Profile Heap Overflow Has Passed; Covered Entities Running Affected Virtual Servers Are Out of Compliance | 9.8 Critical | KEV |
| 2026-09-23 | CVE-2026-93952 | Arista VeloCloud Orchestrator Input Validation Gap Lets Remote Attackers Reach Privileged APIs; CISA's September 25th KEV Deadline for Covered Entities Has Now Passed | 10.0 Critical | KEV |
| 2026-09-23 | CVE-2026-85102 | Check Point Firewall Certificate Validation Bypass Across Site-to-Site and Remote Access VPN Carries a Lapsed September 25th CISA KEV Requirement for Covered Entities | 9.8 Critical | KEV |
| 2026-09-23 | CVE-2026-73176 | Advantech EKI-1242IEIMS Web Management Interface Passes Request Parameters to OS Commands Without Sanitization, Enabling Root Execution for Authenticated Administrators | 8.6 High | New |
| 2026-09-23 | CVE-2026-73175 | Adjacent Unauthenticated Attacker Can Exhaust the Advantech EKI-1242EIMS OPC UA Session Pool by Opening Multiple Anonymous Connections | 7.1 High | New |
| 2026-09-23 | CVE-2026-73174 | Advantech EKI-1242EIMS edgserver Management Protocol Transmits Device Identity and Network Metadata in Cleartext, Recoverable by a Network-Adjacent Passive Observer | 8.7 High | New |
| 2026-09-23 | CVE-2026-73173 | Advantech EKI-1242EIMS edgserver on TCP Port 5058 Requires No Authentication, Allowing Remote Attackers to Reconfigure the Network, Reboot, Reset, or Replace Firmware | 8.8 High | New |
| 2026-09-23 | CVE-2026-73172 | Advantech EKI-1242EIMS Firmware V1.06.01 edgserver Management Service Passes Unsanitized Input to the OS Shell, Enabling Unauthenticated Remote Attackers to Execute Arbitrary Commands | 9.3 Critical | New |
| 2026-09-23 | CVE-2026-73171 | Advantech EKI-1242EIMS Backup-Restore Workflow Accepts Crafted Archives That Overwrite Arbitrary Files on the Device Filesystem | 8.6 High | New |
| 2026-09-23 | CVE-2026-73170 | Advantech EKI-1242EIMS Modbus CSV Import Evaluates Crafted File Content as Lua, Allowing Authenticated Administrators to Execute Arbitrary Code | 8.6 High | New |
| 2026-09-23 | CVE-2026-73167 | Authenticated Administrator Can Inject OS Commands as Root via Crafted Request Parameters in the Advantech EKI-1242IEIMS Web Management Interface | 8.6 High | New |
| 2026-09-23 | CVE-2026-73166 | Advantech EKI-1242IEIMS Web Management Interface Evaluates Code from Request Parameters, Giving Authenticated Administrators Root-Level Code Execution | 8.6 High | New |
| 2026-09-23 | CVE-2026-73165 | Advantech EKI-1242IEIMS Web Management Endpoint Executes Attacker-Supplied OS Commands as Root When Request Parameters Are Not Sanitized | 8.6 High | New |
| 2026-09-23 | CVE-2026-73164 | Crafted HTTP Request Parameters Reach Root-Level OS Execution in Advantech EKI-1242IEIMS Due to Unsanitized Web Interface Input | 8.6 High | New |
| 2026-09-23 | CVE-2026-73163 | Advantech EKI-1242IEIMS Web Interface OS Command Injection Grants Root Access to Authenticated Administrators | 8.6 High | New |
| 2026-09-23 | CVE-2026-53983 | Ground Station Socket.IO Server Accepts Attacker-Supplied Orbital Source URLs Without Authentication, Enabling Unauthenticated SSRF via the Orbital Sync Trigger | 8.6 High | New |
| 2026-09-23 | CVE-2026-19535 | Advantech EKI-1242IEIMS LuCI admin interface CSRF allows unauthenticated attacker to trigger privileged management actions | 8.6 High | New |
| 2026-09-23 | CVE-2026-12974 | Forcepoint NGFW security policy bypass affects versions across 7.1, 7.3, 7.4, and 7.5 branches | 7.9 High | New |
| 2026-09-22 | CVE-2026-9586 | Sangoma Switchvox's SQL Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Database Queries and Compromise the Telephony Platform | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9198 | IBM Langflow's Code Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the AI Workflow Platform; CISA's August 7th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-9082 | Drupal Core's SQL Injection via Specially Crafted Database Abstraction API Requests Enables Privilege Escalation and Remote Code Execution; CISA's May 27th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-86218 | N-able N-central's Static Code Injection Flaw Allows Remote Attackers to Inject and Execute Arbitrary Code on the RMM Platform Without Prior Authentication | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-85706 | GitLab Community and Enterprise Edition's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Read Arbitrary Files on the Server and Fully Compromise the GitLab Instance | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-83549 | SonicWall SMA1000 Appliances' OS Command Injection Allows Authenticated Local Attackers to Execute Arbitrary Commands with Root Privileges; CISA's September 5th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-83548 | SonicWall SMA1000 Appliances' Server-Side Request Forgery Allows Unauthenticated Remote Attackers to Reach Internal Services and Compromise the Secure Mobile Access Gateway; CISA's September 5th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-82329 | JFrog Artifactory Carries a 9.8 Critical Improper Authentication Flaw That Lets Unauthenticated Attackers Bypass Login Controls on the Artifact Repository | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-8037 | Progress LoadMaster's Command Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary OS Commands on the Load Balancer Appliance; CISA's August 10th KEV Deadline Has Passed | 9.6 Critical | KEV |
| 2026-09-22 | CVE-2026-73570 | Zimbra Collaboration Suite's OS Command Injection Allows Authenticated Attackers to Execute Arbitrary Commands on the Email Server with Elevated Privileges; CISA's August 24th KEV Deadline Has Passed | 8.9 High | KEV |
| 2026-09-22 | CVE-2026-72898 | Metabase's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Achieve Full Platform Compromise; CISA's August 14th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-6973 | Ivanti Endpoint Manager Mobile's Improper Input Validation Allows a Remotely Authenticated Administrator to Execute Code Remotely; CISA's May 10th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock's Use-After-Free Allows a Local Attacker to Gain Elevated Privileges via a Freed Memory Reference; CISA's August 25th KEV Deadline Has Passed | 7.0 High | KEV |
| 2026-09-22 | CVE-2026-65400 | Apple macOS's Improper Authentication Flaw Allows a Network Attacker to Bypass Login Controls and Gain Unauthorized Access to the Operating System; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-64849 | MLflow's Server-Side Request Forgery Flaw Allows Remote Attackers to Use the ML Platform Server as a Proxy to Access Internal Services and Steal Credentials; CISA's September 2nd KEV Deadline Has Passed | 9.3 Critical | KEV |
| 2026-09-22 | CVE-2026-63077 | JetBrains TeamCity's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the CI/CD Server; CISA's August 8th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-63030 | WordPress Core Input Interpretation Conflict Exploited in the Wild Carries a Lapsed July 24th CISA KEV Mandate for Covered Entities | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-60137 | WordPress Core SQL Injection Enabling Database Access Joins CISA's Known Exploited Vulnerabilities Catalog; Covered Entities Past the August 4th Remediation Deadline | 5.9 Medium | KEV |
| 2026-09-22 | CVE-2026-60004 | Gitea's Code Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Repository Platform; CISA's August 28th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-59310 | Broadcom VMware vCenter's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Access Files Outside the Web Root and Potentially Compromise the Virtualization Platform; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-56291 | Balbooa Forms Unrestricted File Upload Requiring No Authentication Has Missed CISA's July 13th KEV Remediation Deadline; Covered Entities Are Now Out of Compliance | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-56290 | Joomlack Page Builder Lets Unauthenticated Users Upload Arbitrary Files, Enabling Remote Code Execution; CISA's July 10th KEV Mandate Has Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-55040 | Microsoft SharePoint's Weak Authentication Allows Attackers to Bypass Login Controls and Gain Unauthorized Access to SharePoint Sites and Data; CISA's August 21st KEV Deadline Has Passed | 9.1 Critical | KEV |
| 2026-09-22 | CVE-2026-50751 | Check Point Security Gateway's IKEv1 Key Exchange Flaw Lets Unauthenticated Attackers Establish Remote Access VPN Tunnels Without a Valid Password; CISA's June 11th KEV Deadline Has Passed | 9.3 Critical | KEV |
| 2026-09-22 | CVE-2026-48939 | iCagenda Joomla Event Calendar Extension Accepts Unrestricted File Uploads Without Authentication, Enabling Remote Code Execution; CISA's July 13th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48908 | JoomShaper SP Page Builder Accepts Arbitrary File Uploads from Unauthenticated Users; CISA's July 10th KEV Deadline for Covered Entities Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48907 | Joomla Content Editor Plugin Exposes Privileged Functions Without Proper Authorization; CISA's June 19th KEV Deadline for Covered Entities Has Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-48710 | Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-48558 | SimpleHelp Accepts Unverified Cryptographic Signatures, Letting Remote Attackers Bypass Authentication; CISA's July 2nd KEV Deadline for Covered Entities Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-48172 | Any cPanel User Can Escalate Privileges Through LiteSpeed's Plugin; CISA's May 29th KEV Remediation Requirement for Covered Entities Has Expired | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-46817 | Oracle E-Business Suite's Improper Privilege Management in Oracle Payments Allows an Unauthenticated Network Attacker to Take Over the Payments Module via HTTP; CISA's July 18th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-45498 | Microsoft Defender's Unspecified Vulnerability Allows for Denial of Service; CISA's June 3rd KEV Deadline Has Passed | 4.0 Medium | KEV |
| 2026-09-22 | CVE-2026-45247 | Mirasvit Full Page Cache Warmer's Deserialization Flaw Lets Unauthenticated Attackers Reach Remote Code Execution via a Crafted PHP Object in the CacheWarmer Cookie; CISA's June 6th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-42897 | Microsoft Exchange Server's Outlook Web Access Cross-Site Scripting Flaw Executes Arbitrary JavaScript When Interaction Conditions Are Met; CISA's May 29th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-22 | CVE-2026-42018 | JFrog Artifactory's Improper Authentication Allows Network-Based Attackers to Bypass Login Controls and Gain Unauthorized Access to the Artifact Repository | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-42016 | JFrog Artifactory's Incorrect Authorization Allows Authenticated Users to Access Artifacts and Repositories Outside Their Permitted Scope | 8.1 High | KEV |
| 2026-09-22 | CVE-2026-41940 | WebPros cPanel and WHM's Login Flow Authentication Bypass Gives Unauthenticated Attackers Unauthorized Access to the Control Panel; CISA's May 3rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-41091 | Microsoft Defender's Link Following Flaw Enables an Authorized Attacker to Elevate Privileges Locally; CISA's June 3rd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-39987 | Marimo's Pre-Authentication Flaw Gives Unauthenticated Attackers Shell Access and Arbitrary Command Execution; CISA's May 7th KEV Remediation Requirement for Covered Entities Has Long Lapsed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-39808 | Fortinet FortiSandbox's OS Command Injection Gives Unauthenticated Attackers Remote Code Execution via Crafted HTTP Requests; CISA's July 19th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-35616 | Fortinet FortiClient EMS Access Control Bypass Entered CISA's Known Exploited Vulnerabilities Catalog with an April 9th Federal Deadline That Has Long Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools' Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Take Over the Platform; CISA's June 15th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-34926 | Pre-Authenticated Local Attackers Can Use Relative Path Traversal in Trend Micro Apex One to Modify Key Configuration Data; CISA's June 4th KEV Mandate for Covered Entities Has Lapsed | 6.7 Medium | KEV |
| 2026-09-22 | CVE-2026-34910 | Network-Adjacent Attackers Can Inject Commands into Ubiquiti UniFi OS Through an Input Validation Flaw; CISA's June 26th KEV Remediation Window Has Closed for Covered Entities | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34909 | Ubiquiti UniFi OS's Path Traversal Lets a Network-Adjacent Attacker Access Files on the Underlying System and Manipulate an Underlying Account; CISA's June 26th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34908 | Ubiquiti UniFi OS's Improper Access Control Lets a Network-Adjacent Attacker Make Unauthorized Changes to the System; CISA's June 26th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-34486 | Apache Tomcat's Missing Encryption of Sensitive Session Data Exposes Credentials and Tokens to Network Interception; CISA's August 7th KEV Deadline Has Passed | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-34197 | Apache ActiveMQ's Improper Input Validation Enables Code Injection Affecting Both ActiveMQ and Broker Deployments; CISA's April 30th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2026-33825 | Microsoft Defender's Insufficient Access Control Allows an Authorized Attacker to Escalate Privileges Locally; CISA's May 6th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-33824 | Microsoft Windows IKE Service Extensions' Double Free Enables Unauthenticated Remote Attackers to Execute Arbitrary Code; CISA's August 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-32202 | Microsoft Windows Shell's Protection Mechanism Failure Allows an Unauthorized Attacker to Perform Spoofing Over the Network; CISA's May 12th KEV Deadline Has Passed | 4.3 Medium | KEV |
| 2026-09-22 | CVE-2026-31431 | Linux Kernel Resource Mishandling That Allows Privilege Escalation Carries a Lapsed May 15th CISA KEV Mandate; Covered Entities on Unpatched Kernels Remain Out of Compliance | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-28318 | SolarWinds Serv-U File Transfer Server Resource Exhaustion Exploited in the Wild Carries a Lapsed June 19th CISA KEV Federal Deadline | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-25089 | Fortinet FortiSandbox's Unauthenticated OS Command Injection via Crafted HTTP Requests Covers Cloud and PaaS Deployments; CISA's July 19th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-21962 | Oracle HTTP Server and WebLogic Server Proxy Plug-in's Improper Access Control Allows Unauthenticated Network Attackers to Fully Compromise the Middleware Platform; CISA's August 27th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-21643 | Fortinet FortiClient EMS's SQL Injection Allows Unauthenticated Attackers to Execute Unauthorized Code via Crafted HTTP Requests; CISA's April 16th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-20316 | Cisco Secure Firewall Management Center Hard-Coded Password Lets Attackers Bypass Authentication; CISA's August 1st KEV Deadline for Covered Entities Has Passed | 5.3 Medium | KEV |
| 2026-09-22 | CVE-2026-20262 | Authenticated Path Traversal in Cisco Catalyst SD-WAN Manager Lets Remote Attackers Write Files Outside Allowed Directories; CISA's June 29th KEV Deadline Has Passed | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-20253 | Splunk Enterprise's Missing Authentication on a PostgreSQL Sidecar Service Endpoint Lets Unauthenticated Users Create or Truncate Arbitrary Files; CISA's June 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-20245 | Cisco Catalyst SD-WAN Manager's Improper Encoding Allows an Authenticated Local Attacker to Execute Arbitrary Commands as Root via a Crafted File; CISA's June 23rd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2026-20230 | Cisco Unified Communications Manager SSRF Flaw Routes Attacker Requests to Internal Resources; CISA's June 28th KEV Deadline for Covered Entities Has Lapsed | 8.6 High | KEV |
| 2026-09-22 | CVE-2026-20200 | Cisco Unified Computing System's Argument Delimiter Injection Allows an Authenticated Attacker to Execute Arbitrary Commands on the Management Controller | 8.8 High | Exploited |
| 2026-09-22 | CVE-2026-20182 | Cisco Catalyst SD-WAN Controller and Manager's Authentication Bypass Gives Unauthenticated Remote Attackers Administrative Privileges; CISA's May 17th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Leaks Sensitive Configuration Data to Unauthorized Users; CISA's April 23rd KEV Remediation Requirement Has Expired for Covered Entities | 6.5 Medium | KEV |
| 2026-09-22 | CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed | 7.5 High | KEV |
| 2026-09-22 | CVE-2026-20122 | Cisco Catalyst SD-WAN Manager Exposes Privileged API Functions to Unauthorized Callers; CISA's April 23rd KEV Remediation Deadline for Covered Entities Has Long Passed | 5.4 Medium | KEV |
| 2026-09-22 | CVE-2026-20079 | Cisco Firewall Management Center's Authentication Bypass via an Alternate Path Grants Unauthenticated Remote Attackers Full Administrative Control; CISA's September 12th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-19490 | Citrix NetScaler's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access Protected Resources Without Valid Credentials | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-16232 | Check Point SmartConsole's Improper Authentication Allows Unauthenticated Remote Attackers to Obtain a Login Token and Authenticate with Full Administrative Privileges; CISA's July 25th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-15410 | SonicWall SMA1000's Code Injection Allows a Remote Authenticated Administrator to Execute Arbitrary OS Commands Under Specific Conditions; CISA's July 17th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2026-15409 | SonicWall SMA1000 Secure Access Appliances Accept Forged Server-Side Requests, Enabling Internal Network Pivoting; CISA's July 17th KEV Remediation Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-1340 | Ivanti Endpoint Manager Mobile's Code Injection Vulnerability Allows Attackers to Achieve Unauthenticated Remote Code Execution; CISA's April 11th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-12569 | PTC Windchill and FlexPLM's Improper Input Validation Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via Malicious Network Requests; CISA's June 28th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-10520 | Ivanti Sentry's OS Command Injection Gives Remote Unauthenticated Attackers Root-Level Remote Code Execution; CISA's June 14th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-09-22 | CVE-2026-0300 | PAN-OS Out-of-Bounds Write Enabling Code Execution Affects Both Palo Alto Networks Firewalls and Siemens RUGGEDCOM APE1808 Industrial Appliances; CISA's May 9th KEV Window Has Closed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-0257 | PAN-OS Authentication Bypass Enabling Unauthorized VPN Tunnels Affects Palo Alto Networks Prisma Access and Siemens RUGGEDCOM APE1808; Now Listed in CISA's Known Exploited Vulnerabilities Catalog | 9.1 Critical | KEV |
| 2026-09-22 | CVE-2025-68686 | Fortinet FortiOS's Information Exposure Flaw Allows a Remote Unauthenticated Attacker to Bypass the Previously Issued Patch for Symbolic Link Persistency; CISA's August 10th KEV Deadline Has Passed | 5.9 Medium | KEV |
| 2026-09-22 | CVE-2025-67038 | Lantronix EDS5000's Code Injection via the Username Parameter Executes Injected OS Commands with Root Privileges; CISA's June 26th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2025-62593 | Ray-Project Ray's Code Injection Flaw Allows Remote Attackers to Execute Arbitrary Code on the Distributed ML Framework's Cluster Nodes; CISA's August 20th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2025-60710 | Microsoft Windows Link Following Flaw Enables Privilege Escalation; CISA's April 27th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2025-29635 | D-Link DIR-823X's set_prohibiting POST Endpoint Accepts Injected Commands and Executes Them on Remote Devices; CISA's May 8th KEV Deadline Has Passed for This Potentially End-of-Life Router | 7.2 High | KEV |
| 2026-09-22 | CVE-2025-2749 | Kentico Xperience's Path Traversal in the Staging Sync Server Allows Authenticated Users to Upload Arbitrary Data Outside Expected Directories; CISA's May 4th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2024-7399 | Samsung MagicINFO 9 Path Traversal Enabling Arbitrary File Writes as System Authority Has Missed CISA's May 8th KEV Deadline; Covered Entities Remain Out of Compliance | 8.8 High | KEV |
| 2026-09-22 | CVE-2024-57728 | SimpleHelp's Zip Slip Path Traversal Lets Admin Users Write Arbitrary Files to Any Location on the Server and Execute Code as the Service Account; CISA's May 8th KEV Deadline Has Passed | 7.2 High | KEV |
| 2026-09-22 | CVE-2024-57726 | SimpleHelp Lets Low-Privilege Technicians Mint Overpowered API Keys Through a Missing Authorization Check; CISA's May 8th KEV Deadline for Covered Entities Has Lapsed | 9.9 Critical | KEV |
| 2026-09-22 | CVE-2024-21182 | Unauthenticated T3 and IIOP Network Access to Oracle WebLogic Enables System Compromise; CISA's June 4th KEV Mandate for Covered Entities Has Been Lapsed for Months | 7.5 High | KEV |
| 2026-09-22 | CVE-2024-1708 | ConnectWise ScreenConnect's Path Traversal Enables Remote Code Execution or Direct Access to Confidential Data and Critical Systems; CISA's May 12th KEV Deadline Has Passed | 8.4 High | KEV |
| 2026-09-22 | CVE-2023-49105 | ownCloud's Improper Authentication Allows Unauthenticated Remote Attackers to Gain Access to Protected Files Without Valid Credentials; CISA's August 30th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2023-36424 | Microsoft Windows Common Log File System Driver's Out-of-Bounds Read Enables Privilege Escalation; CISA's April 27th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2023-21529 | Microsoft Exchange Server's Deserialization of Untrusted Data Enables Authenticated Attackers to Achieve Remote Code Execution; CISA's April 27th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2022-0995 | Linux Kernel's Out-of-Bounds Write Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 9th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2022-0492 | Linux Kernel's cgroup v1 release_agent Feature Enables Privilege Escalation; CISA's June 5th KEV Deadline for Covered Entities Has Lapsed | 7.8 High | KEV |
| 2026-09-22 | CVE-2021-27137 | Unauthenticated Attackers Can Overflow DD-WRT's UPnP Stack Buffer; CISA's July 24th KEV Mandate for Covered Entities Has Lapsed | 8.1 High | KEV |
| 2026-09-22 | CVE-2021-23758 | Ajax.NET Professional's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via a Crafted Serialized Object; CISA's September 9th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-22 | CVE-2019-1068 | Microsoft SQL Server's Unspecified Flaw Allows Authenticated Attackers to Execute Arbitrary Code on the Database Server; CISA's August 29th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool's Privilege Escalation Flaw Allows Local Attackers to Gain Root Access on Affected Enterprise Linux Systems; CISA's September 9th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2015-3246 | Red Hat Enterprise Linux's Libuser Race Condition in Password File Writes Allows Local Attackers to Corrupt System Files; CISA's September 9th KEV Deadline Has Passed | 5.1 Medium | KEV |
| 2026-09-22 | CVE-2012-1854 | Microsoft Visual Basic for Applications Loads Libraries Insecurely, Enabling Remote Code Execution; CISA's April 27th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-22 | CVE-2010-0806 | Microsoft Internet Explorer's Use-After-Free Enables Remote Code Execution via Invalid Pointer Access After Object Deletion; CISA's June 3rd KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2010-0249 | Microsoft Internet Explorer's Use-After-Free Gives Remote Attackers Code Execution via a Pointer to a Deleted Object; CISA's June 3rd KEV Deadline Has Passed for This End-of-Life Browser | 8.8 High | KEV |
| 2026-09-22 | CVE-2009-1537 | Microsoft DirectX's QuickTime Movie Parser Filter Lets Remote Attackers Execute Arbitrary Code via a Crafted Media File; CISA's June 3rd KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2009-0238 | Microsoft Office Code Injection From 2009 Added to CISA's Known Exploited Vulnerabilities Catalog with an April 28th Federal Deadline That Has Since Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2008-4250 | Microsoft Windows Server Service's Path Canonicalization Buffer Overflow Enables Remote Code Execution via Crafted RPC Requests; CISA's June 3rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-22 | CVE-2026-7273 | Zyxel GS1900 Series Switches' CGI Program Stack-Based Buffer Overflow Allows a LAN-Side Unauthenticated Attacker to Execute OS Commands via Crafted HTTP Requests; CISA's September 24th KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-22 | CVE-2026-31278 | Suprema BioStar 2 Active Directory service account credentials exposed in cleartext via GET request | 7.7 High | New |
| 2026-09-22 | CVE-2026-17599 | Nexus Repository 3 onboarding password-change endpoint accessible after setup allows privileged user to replace admin password | 7.2 High | Updated |
| 2026-09-21 | CVE-2026-43629 | llama.cpp KV Cache State Restore Computes Write Size Without Overflow Checking, Allowing Heap Corruption via a Crafted State File in slot_save_path | 8.1 High | Updated |
| 2026-09-21 | CVE-2026-18951 | Red Hat OpenShift AI training operator misconfiguration lets namespace editor create and delete TrainJobs enabling cluster RCE | 8.8 High | New |
| 2026-09-20 | CVE-2026-87886 | Acronis Backup's Incorrect Default Permissions Allow a Local Attacker to Access Backup Files and Configurations Not Intended for Their Account; CISA's September 19th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-86060 | MikroTik RouterOS's Argument Injection in a Command-Processing Component Allows Unauthenticated Attackers to Execute Arbitrary Commands on the Router; CISA's September 13th KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-20 | CVE-2026-85880 | Microsoft Windows' Heap-Based Buffer Overflow Allows Local Attackers to Escalate Privileges by Corrupting Heap Memory; CISA's September 22nd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-84869 | ConnectWise ScreenConnect's Improper Privilege Management and Missing Authorization Allow Unauthenticated Attackers to Gain Administrative Control of the Remote Support Platform; CISA's September 14th KEV Deadline Has Passed | 9.9 Critical | KEV |
| 2026-09-20 | CVE-2026-81963 | Microsoft Windows' Improper Link Resolution Before File Access Allows a Local Attacker to Follow Symbolic Links to Privileged Files and Gain Elevated Access; CISA's September 22nd KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-70468 | Fortinet FortiManager's Authentication Bypass via an Alternate Path Grants Unauthenticated Attackers Access to Management Functions | 8.1 High | Updated |
| 2026-09-20 | CVE-2026-70465 | Fortinet FortiClient's Classic Buffer Overflow Allows an Attacker to Corrupt Memory and Potentially Execute Arbitrary Code | 8.1 High | Updated |
| 2026-09-20 | CVE-2026-67277 | MikroTik RouterOS's Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Access and Modify Router Configuration; CISA's September 13th KEV Deadline Has Passed | 8.2 High | KEV |
| 2026-09-20 | CVE-2026-53362 | Linux Kernel's Unspecified Flaw Allows Local Attackers to Gain Elevated Privileges on Affected Systems; CISA's August 30th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2026-53266 | Linux Kernel's Out-of-Bounds Write Vulnerability Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 21st KEV Deadline Has Passed | 8.8 High | KEV |
| 2026-09-20 | CVE-2026-50516 | Microsoft Azure Kubernetes Service's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Interact with Privileged Cluster Management Endpoints | 9.4 Critical | Updated |
| 2026-09-20 | CVE-2026-26035 | Fortinet FortiWeb's Improper Authentication Allows Unauthenticated Attackers to Bypass Login Controls and Access the Web Application Firewall Management Interface | 9.8 Critical | Updated |
| 2026-09-20 | CVE-2026-20349 | Cisco Secure Firewall ASA and FTD's Heap Inspection Vulnerability Allows Remote Attackers to Extract Sensitive Memory Contents from the Firewall Device; CISA's August 14th KEV Deadline Has Passed | 8.6 High | KEV |
| 2026-09-20 | CVE-2026-20301 | Cisco IOS XE's Unchecked Loop Condition Input Allows Network-Accessible Devices to Be Crashed via a Specially Crafted Packet | 8.6 High | Exploited |
| 2026-09-20 | CVE-2026-20273 | Cisco IOS XE's Improper Input Validation Allows a Remote Attacker to Trigger a Device Crash or Disruption via a Specially Crafted Input | 8.6 High | Updated |
| 2026-09-20 | CVE-2026-20272 | Cisco IOS XE's Injection Flaw Allows Remote Attackers to Execute Arbitrary Commands via a Specially Crafted Input Reaching a Downstream Component | 9.8 Critical | Updated |
| 2026-09-20 | CVE-2026-20271 | Cisco IOS XE's Insufficient Control Flow Management Allows a Remote Attacker to Disrupt Device Operation via a Crafted Packet | 8.6 High | Updated |
| 2026-09-20 | CVE-2026-20270 | Cisco IOS XE's Incorrect Calculation Vulnerability Allows a Remote Attacker to Cause an Unrecoverable Device Condition via a Specially Crafted Input | 8.6 High | Updated |
| 2026-09-20 | CVE-2026-20269 | Cisco IOS XE's Improper Resource Lifetime Management Allows Remote Attackers to Exhaust Device Resources and Cause a Denial of Service | 8.6 High | Updated |
| 2026-09-20 | CVE-2026-20268 | Cisco IOS XE's Improper Restriction of Memory Buffer Operations Allows Remote Attackers to Potentially Execute Code or Crash the Device via a Malformed Packet | 8.6 High | Updated |
| 2026-09-20 | CVE-2026-20267 | Cisco IOS XE's Improper Access Control Allows Network-Based Attackers to Access Protected Functions or Data Without Proper Authorization | 9.0 Critical | Updated |
| 2026-09-20 | CVE-2026-20124 | Cisco IOS XE's Memory Resource Leak Allows Remote Attackers to Exhaust Device Memory and Cause a Denial of Service via Repeated Packet Transmission | 7.7 High | Exploited |
| 2026-09-20 | CVE-2026-0301 | Palo Alto Networks Cloud NGFW and Prisma Access Use of Uninitialized Resource Allows a Network-Based Attacker to Access Sensitive Information | 7.5 High | Exploited |
| 2026-09-20 | CVE-2026-0299 | Palo Alto Networks GlobalProtect's Untrusted Search Path Allows a Local Attacker to Load a Malicious Library and Execute Code in the Application's Context | 7.8 High | Exploited |
| 2026-09-20 | CVE-2026-0298 | Palo Alto Networks GlobalProtect's Code Injection Vulnerability Allows an Authenticated Remote Attacker to Execute Arbitrary Code in the Context of the VPN Client | 8.1 High | Exploited |
| 2026-09-20 | CVE-2026-0297 | Palo Alto Networks GlobalProtect's Out-of-Bounds Write Allows a Remote Attacker to Corrupt Memory and Execute Code or Crash the Application | 8.1 High | Exploited |
| 2026-09-20 | CVE-2026-0296 | Palo Alto Networks GlobalProtect's Improper Certificate Validation Allows a Network Adversary to Present a Forged Certificate and Intercept the VPN Connection | 7.4 High | Exploited |
| 2026-09-20 | CVE-2026-0295 | Palo Alto Networks GlobalProtect's Race Condition Allows a Local Attacker to Exploit a Timing Window and Gain Elevated Privileges | 7.0 High | Exploited |
| 2026-09-20 | CVE-2026-0294 | Palo Alto Networks Prisma Access Agent's Uncontrolled Search Path Allows a Local Attacker to Place a Malicious Library Where the Agent Will Load It | 7.8 High | Exploited |
| 2026-09-20 | CVE-2025-39964 | Linux Kernel's Race Condition Allows a Local Attacker to Exploit a Timing Window and Gain Elevated Privileges on the System; CISA's September 21st KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-09-20 | CVE-2025-39682 | Linux Kernel's Improper Check for Exceptional Conditions Allows Remote Attackers to Execute Arbitrary Code or Crash Affected Systems; CISA's September 21st KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-20 | CVE-2025-25249 | Fortinet Multiple Products' Heap-Based Buffer Overflow Allows Remote Attackers to Potentially Execute Arbitrary Code or Crash Affected Devices; CISA's September 12th KEV Deadline Has Passed | 8.1 High | KEV |
| 2026-09-20 | CVE-2026-82078 | PaperCut NG/MF's Unsafe Reflection Allows Remote Attackers to Manipulate Class Loading and Execute Arbitrary Code on the Print Management Server; CISA's September 14th KEV Deadline Has Passed | 9.1 Critical | KEV |
| 2026-09-20 | CVE-2026-72530 | TrueConf Server's Code Injection Vulnerability Allows Remote Attackers to Execute Arbitrary Code on the Video Conferencing Platform; CISA's September 3rd KEV Deadline Has Passed | 9.0 Critical | KEV |
| 2026-09-20 | CVE-2026-72529 | TrueConf Server's Missing Authentication on a Critical Function Allows Unauthenticated Remote Attackers to Access Administrative Capabilities; CISA's August 23rd KEV Deadline Has Passed | 9.8 Critical | KEV |
| 2026-09-20 | CVE-2026-70332 | Microsoft SharePoint Online's Cross-Site Scripting Flaw Lets Attackers Execute Arbitrary JavaScript in the Victim's Browser Session | 9.6 Critical | Updated |
| 2026-09-20 | CVE-2026-66322 | Microsoft Edge's Origin Validation Error Allows a Cross-Origin Attacker to Bypass Boundary Enforcement and Access Content from a Different Origin | 7.1 High | Updated |
| 2026-09-20 | CVE-2026-66321 | Microsoft Edge's Type Confusion in the Browser Engine Allows a Remote Attacker to Execute Arbitrary Code via a Crafted Web Page | 7.4 High | Updated |
| 2026-09-20 | CVE-2026-66318 | Microsoft Edge's Origin Validation Error Exposes Protected Resources to Cross-Origin Content Access by a Network Attacker | 8.1 High | Updated |
| 2026-09-20 | CVE-2026-66315 | Microsoft Edge's Use After Free Vulnerability Lets a Remote Attacker Corrupt the Browser Heap and Potentially Execute Code via a Crafted Web Page | 7.5 High | Updated |
| 2026-09-20 | CVE-2026-66310 | Microsoft Edge's Externally Controlled File Path Allows a Crafted Web Page to Reference Arbitrary Files on the Local System | 7.7 High | Updated |
| 2026-09-20 | CVE-2026-65802 | Microsoft Edge's External Control of a File Path Flaw Allows Attackers to Read or Write Files Outside the Intended Browsing Sandbox via a Crafted Page | 7.4 High | Updated |
| 2026-09-20 | CVE-2026-65668 | Microsoft Purview eDiscovery's Improper Access Control Allows Authenticated Attackers to Access Data Outside Their Authorized Scope | 8.8 High | Updated |
| 2026-09-20 | CVE-2026-65667 | Microsoft Teams Carries a Critical 10.0 CVSS Score for a Missing Authorization Flaw That Lets Authenticated Users Access Privileged Functions | 10.0 Critical | Updated |
| 2026-09-20 | CVE-2026-63508 | Microsoft Planetary Computer's Missing Authentication on a Critical Endpoint Allows Unauthenticated Attackers to Access and Execute Privileged Functions | 10.0 Critical | Updated |
| 2026-09-20 | CVE-2026-62918 | Microsoft Teams' Improper Cryptographic Signature Verification Allows Attackers to Submit Forged Messages That the Application Accepts as Authentic | 7.5 High | Updated |
| 2026-09-20 | CVE-2026-62896 | Microsoft Teams' Improper Authentication Allows Unauthenticated Remote Attackers to Access the Platform Without Valid Credentials | 9.6 Critical | Updated |
| 2026-09-20 | CVE-2026-62873 | Microsoft Windows Admin Center's Improper Cryptographic Signature Verification Enables Unauthenticated Attackers to Forge Signed Requests and Gain Unauthorized Access | 9.8 Critical | Updated |
| 2026-09-20 | CVE-2026-62870 | Microsoft Excel's Use After Free Vulnerability Lets Remote Attackers Execute Arbitrary Code via a Specially Crafted Workbook | 8.8 High | Updated |
| 2026-09-20 | CVE-2026-59115 | Microsoft Entra Provisioning Service's Path Traversal Flaw Allows Attackers to Navigate Outside the Intended Directory and Access Provisioned Tenant Data | 9.9 Critical | Updated |
| 2026-09-20 | CVE-2026-58612 | Microsoft PowerShell's High-Severity Flaw Allows a Network-Based Attacker to Gain Unauthorized Access on Affected Installations | 7.4 High | Updated |
| 2026-09-20 | CVE-2026-57105 | Microsoft SharePoint Server's Unspecified Flaw Allows an Authenticated Attacker to Gain Unauthorized Access to Server Resources | 8.0 High | Updated |
| 2026-09-20 | CVE-2025-40582 | Siemens SCALANCE LPE9403's Configuration Parameter Handling Flaw Lets Non-Privileged Local Attackers Execute Commands as Root When SINEMA Remote Connect Edge Client Is Installed | 7.8 High | Updated |
| 2026-09-20 | CVE-2025-40581 | Siemens SCALANCE LPE9403's Authentication Bypass Allows Non-Privileged Local Attackers to Bypass Authentication Controls on Affected Versions | 7.1 High | Updated |
| 2026-09-20 | CVE-2025-40574 | Siemens SCALANCE LPE9403's Incorrect Permissions on Critical Resources Expose the Backup Manager Service to Non-Privileged Local Attackers | 7.8 High | Updated |
| 2026-09-19 | CVE-2026-27553 | A Manipulated Schema Path Parameter in Pepperl+Fuchs ICE-Series IO-Link Masters' Diagnostics Endpoint Exposes Every User's Password Hash to Low-Privileged Accounts | 6.5 Medium | Updated |
| 2026-09-18 | CVE-2026-87491 | Google Chromium V8's Out-of-Bounds Write Allows Remote Attackers to Corrupt the JavaScript Engine's Heap and Execute Arbitrary Code via a Crafted Web Page | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-59822 | BerriAI LiteLLM's Improper Authentication Allows Unauthenticated Attackers to Access the AI Model Gateway and Interact with Configured LLM Endpoints Without Credentials | 8.2 High | KEV |
| 2026-09-18 | CVE-2026-58704 | Google Pixel's Improper Authorization Flaw Allows an Attacker with Physical or Local Access to Bypass Permission Controls and Access Protected Device Functions | 8.8 High | KEV |
| 2026-09-18 | CVE-2026-49869 | Kestra OSS's OS Command Injection Flaw Lets Unauthenticated Remote Attackers Execute Arbitrary Commands on the Workflow Orchestration Server with Full System Privileges | 10.0 Critical | KEV |
| 2026-09-18 | CVE-2026-93177 | Linux Kernel amdgpu Vega10 VBIOS Table Indices Lack Bounds Checks Across Nine Voltage Lookup Sites | 7.3 High | New |
| 2026-09-18 | CVE-2026-86520 | Bransys ELD Hardcoded MQTT Credentials Expose Real-Time Location Data for Every Active Device Across Connected Carriers | 7.5 High | New |
| 2026-09-18 | CVE-2026-73568 | py-libp2p yamux Reads Attacker-Controlled Frame Length Before Validating It, Allowing Any Noise-Authenticated Peer to Stall an Entire Connection; No Fix Available | 7.5 High | New |
| 2026-09-18 | CVE-2026-28326 | SolarWinds Access Rights Manager unauthenticated remote code execution via hardcoded static key | 8.8 High | New |
| 2026-09-18 | CVE-2026-27563 | Crafted GET Request to the Datastorage API Lets Admin Credentials Trigger Root Command Execution on Pepperl+Fuchs ICE-Series IO-Link Masters | 7.2 High | Updated |
| 2026-09-18 | CVE-2026-27558 | Operator Access to the IODD File Removal Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Allows Root Command Injection | 8.8 High | Updated |
| 2026-09-18 | CVE-2026-27548 | Command Injection in the IODD Port Info Endpoint Grants Root Access on Pepperl+Fuchs ICE-Series IO-Link Masters to Any User or Operator Account | 8.8 High | Updated |
| 2026-09-18 | CVE-2026-20334 | Cisco ASA/FTD/FMC internal security review hardening release addresses multiple internally discovered vulnerabilities | 8.4 High | New |
| 2026-09-18 | CVE-2026-1758 | Secomea GateManager webserver module session fixation vulnerability in versions 11.4 and 11.5 | 8.3 High | New |
| 2026-09-18 | CVE-2026-15688 | Mitsubishi Electric GX Works3 and Motion Control Setting Authentication Algorithm Allows a Local Attacker to Successfully Authenticate with an Invalid Block Password by Modifying the Executable Module in Memory | 9.2 Critical | New |
| 2026-09-18 | CVE-2026-13584 | Mitsubishi Electric MELSEC CC-Link IE TSN improper message integrity enforcement allows network traffic manipulation | 7.1 High | New |
| 2026-09-18 | CVE-2026-12745 | Ivanti Neurons for ITSM Before 2026.2 Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Server | 9.8 Critical | Updated |
| 2026-09-18 | CVE-2026-12744 | Ivanti Neurons for ITSM Before 2026.2 Deserialization of Untrusted Data Allows a Second Unauthenticated Remote Code Execution Path on the Server | 9.8 Critical | Updated |
| 2026-09-18 | CVE-2026-12651 | Ivanti Neurons for ITSM deserialization of untrusted data allows authenticated remote attacker to execute arbitrary code | 8.8 High | Updated |
| 2026-09-18 | CVE-2026-12650 | Ivanti Neurons for ITSM Before 2026.2 Deserialization of Untrusted Data Allows Authenticated Remote Attackers to Execute Arbitrary Code on the Server, Scoring CVSS 9.9 | 9.9 Critical | Updated |
| 2026-09-18 | CVE-2026-12648 | Ivanti Neurons for ITSM deserialization provides a second authenticated path to remote code execution before version 2026.2 | 8.8 High | Updated |
| 2026-09-18 | CVE-2026-12647 | Ivanti Neurons for ITSM Before 2026.2 Missing Authorization Lets Authenticated Remote Attackers Execute Arbitrary Code on the Server, Scoring CVSS 9.9 | 9.9 Critical | Updated |
| 2026-09-18 | CVE-2026-12646 | Ivanti Neurons for ITSM Before 2026.2 Missing Authorization Lets Authenticated Remote Attackers Execute Arbitrary Code on the Server via a Second Unprotected Path | 9.9 Critical | Updated |
| 2026-09-18 | CVE-2026-12645 | Ivanti Neurons for ITSM Before 2026.2 Missing Authorization Lets Authenticated Remote Attackers Execute Arbitrary Code on the Server via a Third Unprotected Path | 9.9 Critical | Updated |
| 2026-09-17 | CVE-2026-93188 | Linux Kernel HID Roccat Driver Uses an 8-bit Device-Supplied Profile Value as an Array Index Without Bounds Checking, Enabling an Out-of-Bounds Memory Access via a Crafted USB Device | — | New |
| 2026-09-17 | CVE-2026-90099 | Linux Kernel TC Classifier Filter Allocations in the change() Path Use Plain GFP Flags Without Accounting to memcg, Allowing Container Workloads to Exhaust Host Memory Without Being Charged | — | New |
| 2026-09-17 | CVE-2026-90058 | Linux Kernel qdisc_calculate_pkt_len Amplifies User-Supplied Size Table Values Without Bounds Checking, Allowing a Crafted Size Table to Cause a Soft Lockup in the Packet Scheduler | — | New |
| 2026-09-17 | CVE-2026-73464 | Authenticated gNMI Client Can Execute Arbitrary Code with Root Privileges on Arista EOS via a Specially Crafted Request | 8.8 High | New |
| 2026-09-17 | CVE-2026-73454 | Crafted gNSI Credentialz Request on Arista EOS Can Assign an Account Elevated Privileges Beyond Administrator Intent | 8.1 High | New |
| 2026-09-17 | CVE-2026-73453 | Arista EOS P4Runtime Client Interface Allows Unauthenticated Arbitrary Code Execution Under Certain Conditions on Platforms Running EOS with P4Runtime Configured, Scoring CVSS 10.0 | 10.0 Critical | New |
| 2026-09-17 | CVE-2026-73447 | Arista EOS gRPC Network Security Interface Certz Service Lets a Privileged Authenticated User Execute Arbitrary Commands with Root Privileges, Leading to Full Device Compromise | 9.1 Critical | New |
| 2026-09-17 | CVE-2026-73439 | Arista EOS gNMI Fails to Enforce gNSI Pathz Policy When Both Group and User Rules Exist for the Same Path, Granting Unauthorized Access | 7.5 High | New |
| 2026-09-17 | CVE-2026-73437 | Arista EOS DHCP Relay Forwards Crafted Reply Packets From Non-Helper-Address Sources to Clients Without Validation, Letting Unauthenticated Network Attackers Inject Arbitrary DHCP Responses to Hosts | 9.6 Critical | New |
| 2026-09-17 | CVE-2026-73177 | Advantech EKI-1242EIMS Firmware Upgrade Endpoint Accepts Images Without Signature Verification, Allowing Authenticated Administrators to Achieve Persistent Full Compromise | 8.6 High | New |
| 2026-09-16 | CVE-2026-89873 | Linux Kernel V4L2 HEVC SPS Control Accepts Out-of-Range RPS Counts, Exposing Decoder Drivers to Out-of-Bounds Indexing | 7.8 High | New |
| 2026-09-16 | CVE-2026-89803 | Linux Kernel DRM Nouveau Tears Down the Fence Context Before Unsubscribing Channel-Kill Events, Creating a Use-After-Free Window | 7.8 High | New |
| 2026-09-16 | CVE-2026-73459 | Unauthenticated Attacker on an Adjacent Segment Can Inject a Crafted IS-IS LSP PDU into Arista EOS, Purging Legitimate Entries and Causing Traffic Loss | 7.4 High | New |
| 2026-09-16 | CVE-2026-73458 | Specially Crafted Packet Bypasses BFD Session Authentication on Arista EOS and Takes Down BFD Sessions, Disrupting Dependent Routing Protocols | 8.2 High | New |
| 2026-09-16 | CVE-2026-73455 | Specially Crafted Packet Causes the Arista EOS OSPFv3 Agent to Restart Unexpectedly | 7.5 High | New |
| 2026-09-16 | CVE-2026-73446 | Unauthenticated Attacker on a Broadcast Segment Can Tear Down Arista EOS IS-IS Adjacencies by Sending a Crafted Hello PDU | 7.4 High | New |
| 2026-09-16 | CVE-2026-73435 | Unauthenticated Attacker on the Same Broadcast Segment Can Cause Arista EOS OSPFv2 Adjacency Flapping Despite Authentication Being Configured | 8.2 High | New |
| 2026-09-16 | CVE-2026-5856 | Contiki-NG DNS Resolver skip_name Walks Past the UDP Packet Buffer Without Boundary Checks, Reachable from Any Local-Segment Peer on mDNS-Enabled Builds | 7.1 High | New |
| 2026-09-16 | CVE-2026-27565 | Unauthenticated IODD File Upload on Pepperl+Fuchs ICE-Series IO-Link Masters Executes a Root Shell Script That Persists Across Reboots | 9.8 Critical | Updated |
| 2026-09-16 | CVE-2026-27564 | Pepperl+Fuchs ICE-Series IO-Link Masters Run Injected Root Commands When Admin Credentials Submit a Crafted PUT Request to the Datastorage API | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27562 | Admin-Level PUT Requests to the IODD Configuration API Execute Injected Commands as Root on Pepperl+Fuchs ICE-Series IO-Link Masters | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27561 | Admin Credentials Enable Root Command Injection via the IODD Config GET API on Pepperl+Fuchs ICE-Series IO-Link Masters | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27560 | Admin-Credentialed DELETE Requests to Pepperl+Fuchs ICE-Series IO-Link Masters' Status API Carry Injected Commands Executed at Root | 7.2 High | Updated |
| 2026-09-16 | CVE-2026-27559 | User Credentials Are Enough to Inject Root-Level Commands via the Status Data API on Pepperl+Fuchs ICE-Series IO-Link Masters | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27557 | Unauthenticated Path Traversal in Pepperl+Fuchs ICE-Series IO-Link Masters Exposes the Device's SSH Server Private Keys | 7.5 High | Updated |
| 2026-09-16 | CVE-2026-27556 | Operator Cookie Enables Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Parameter Save Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27555 | A Valid User Cookie Triggers Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Port Info Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27554 | IODD Parameter Save Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Accepts Injected Commands from Operator-Level Accounts, Yielding Root Access | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27552 | Pepperl+Fuchs ICE-Series IO-Link Masters Allow Low-Privileged Users to Upload Arbitrary IODD Files via a Missing Authorization Check, Enabling Device Manipulation or Crashes | 8.1 High | Updated |
| 2026-09-16 | CVE-2026-27551 | User-Level Credentials Give Root Shell on Pepperl+Fuchs ICE-Series IO-Link Masters via the Parameter Management Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27550 | Operator Credentials Can Inject Root-Level OS Commands via the Field_Shadow_Password Handler on Pepperl+Fuchs ICE-Series IO-Link Masters | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27549 | Operator-Level Credentials Suffice to Run Root Commands on Pepperl+Fuchs ICE-Series IO-Link Masters via the IODD Upload Endpoint | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27547 | IODD Menu Info Request on Pepperl+Fuchs ICE-Series IO-Link Masters Passes Unvalidated Parameters to Root-Level Commands, Reachable with User-Level Credentials | 8.8 High | Updated |
| 2026-09-16 | CVE-2026-27546 | The _account_log Function in Pepperl+Fuchs ICE-Series IO-Link Masters Lets Unauthenticated Attackers Log In as Admin Regardless of Account Configuration | 9.8 Critical | Updated |
| 2026-09-16 | CVE-2026-2380 | Arista EOS OpenConfig services log sensitive data including credentials in cleartext on local device and remote servers | 7.4 High | New |
| 2026-09-14 | CVE-2026-89478 | Linux Kernel SCTP Authenticated ASCONF DEL-IP Removes a Transport While a Backlogged Chunk Still Holds a Pointer to It, Enabling Use-After-Free on the Next SACK | 9.8 Critical | New |
| 2026-09-14 | CVE-2026-89477 | Linux Kernel SCTP Dereferences a NULL Transport on Untransmitted Stream Reconfiguration Completion, Reachable by a Remote Peer | 7.5 High | New |
| 2026-09-14 | CVE-2026-80994 | Linux Kernel Open vSwitch CMD_DEL Races the RCU Grace Period Against ovs_flow_cmd_fill_info, Causing Use-After-Free on the Flow Mask | 7.8 High | New |
| 2026-09-11 | CVE-2026-84390 | Fortinet FortiMonitorOnSight 7.2.0 Through 7.2.7 Embeds Sensitive Information in Source Code, Potentially Allowing Attackers to Gain Unauthorized Access via Exposed Credentials | 9.8 Critical | New |
| 2026-09-11 | CVE-2026-79698 | Advantech WISE-6610 Series Management Interface Fails to Neutralize Special Elements in a Command Argument, Allowing Unauthenticated Remote Attackers to Inject Arbitrary Application Commands | 9.9 Critical | New |
| 2026-09-11 | CVE-2026-63298 | LXD NVIDIA Instance Configuration Handler Accepts Newline Characters in nvidia.driver.capabilities and nvidia.require.* Values, Letting Authenticated Attackers Inject Arbitrary Directives into the GPU Configuration | 9.9 Critical | Updated |
| 2026-09-11 | CVE-2026-54874 | OpenSSL DTLS Buffers Future-Epoch Records Without a Size Cap During Handshake, Allowing a Peer to Exhaust Memory with Minimal Traffic | 7.5 High | Updated |
| 2026-09-11 | CVE-2026-0310 | PAN-OS XML processing buffer overflow enables unauthenticated attacker to crash or compromise PA-Series firewalls | 7.2 High | New |
| 2026-09-10 | CVE-2026-84393 | Fortinet FortiOS and FortiProxy Certificate Host-Mismatch Validation Flaw Exposes Sensitive Information to Network Interception | 8.1 High | New |
| 2026-09-10 | CVE-2026-69247 | Python cryptography Package PKCS#7 Decrypt Functions Report Distinguishable RSA Padding Outcomes, Exposing a Bleichenbacher Oracle Against the Content-Encryption Key | 8.2 High | New |
| 2026-09-10 | CVE-2026-69240 | Sequelize Before 6.37.4 Fails to Escape Quotes in the Oracle Dialect When a String Value Starts with TO_TIMESTAMP or TO_DATE, Enabling SQL Injection Against Oracle Databases | 9.8 Critical | New |
| 2026-09-10 | CVE-2026-42807 | Bosch Sensortec COINES_SDK Bridge Decoder Trusts Peripheral-Supplied Packet Length Without Bounds Checking, Allowing a Malicious USB or BLE Device to Cause Heap Overflow | 8.0 High | New |
| 2026-09-10 | CVE-2026-42805 | Bosch Sensortec BHI385 SensorAPI Debug Message Parser Trusts an Attacker-Controlled 8-Bit Length Field, Causing Stack Buffer Overflow via Crafted FIFO Events | 8.4 High | New |
| 2026-09-10 | CVE-2026-42804 | Bosch Sensortec BHI360 SensorAPI FIFO Debug Frame Parser Trusts Attacker-Controlled Message Length, Causing Stack Buffer Overflow | 7.6 High | New |
| 2026-09-10 | CVE-2026-32589 | Red Hat Quay authenticated push access enables interference with other users' in-progress image uploads across repositories | 7.4 High | Updated |
| 2026-09-09 | CVE-2026-84942 | OpenSearch Dashboards Vega Validator Fails to Recurse into Arrays, Letting Dashboard Writers Inject JavaScript into Other Users' Sessions | 8.7 High | New |
| 2026-09-09 | CVE-2026-67609 | Telenia TVox Insecure sudoers Configuration Grants the apache User Unlimited Command Execution as Root via /bin/nice | 7.8 High | New |
| 2026-09-09 | CVE-2026-67608 | Telenia TVox action_audio.php Passes the pid Parameter Directly to exec() Without Sanitization, Allowing Authenticated Administrators to Inject OS Commands | 7.2 High | New |
| 2026-09-09 | CVE-2026-55245 | Bifrost AI Gateway SSRF Deny-List Misclassifies CGNAT, 6to4, and NAT64 Addresses as Public, Exposing Instance Metadata to Requests Using Encoded Internal Addresses | 8.7 High | New |
| 2026-09-09 | CVE-2026-47719 | FUXA SCADA Socket.IO Request Handlers Skip Authorization, Allowing Unauthenticated Attackers to Initiate Requests to Arbitrary HTTP, OPC UA, and ODBC Destinations | 8.2 High | New |
| 2026-09-09 | CVE-2026-18851 | Ivanti EPMM missing authorization check allows authenticated remote attacker to escalate privileges to admin | 8.8 High | Updated |
| 2026-09-08 | CVE-2026-9165 | Authenticated RHACS API Token Holder Can Exhaust Central Resources with Unbounded GraphQL Query Depth | 7.7 High | New |
| 2026-09-08 | CVE-2026-86313 | Samsung Walrus Out-of-Bounds Write Enables Local Code Execution | 7.8 High | New |
| 2026-09-08 | CVE-2026-85012 | Shell Metacharacters in .ownership-file's Owner Field Reach popen in Amazon CodeCatalyst Blueprint Resynthesis, Enabling Command Injection for Repository Committers | 8.0 High | New |
| 2026-09-08 | CVE-2026-84387 | Fortinet FortiSandbox Command Injection Is Reachable by an Authenticated Administrator | 7.2 High | New |
| 2026-09-08 | CVE-2026-81939 | SonicWall Network Security Manager On-Prem File Upload Extracts Archive Entries Without Validating Path Components, Enabling Zip Slip File Placement Outside the Intended Destination Directory | 9.1 Critical | New |
| 2026-09-08 | CVE-2026-79697 | Advantech WISE-6610 Series Management Interface Exposes a Second Special-Element Injection Path, Allowing Unauthenticated Remote Attackers to Manipulate Application Command Execution | 9.9 Critical | New |
| 2026-09-08 | CVE-2026-7867 | udisks2 Filesystem.Mount D-Bus Method Accepts a Spoofed as-user Parameter, Enabling Mount Point Injection and Local Privilege Escalation | 7.8 High | New |
| 2026-09-08 | CVE-2026-78328 | SonicWall Network Security Manager On-Prem Lets a Lower-Privileged Admin Escalate to SuperAdmin Due to a Missing Authorization Check | 9.1 Critical | New |
| 2026-09-08 | CVE-2026-78327 | SonicWall Network Security Manager On-Prem Management Interface Passes Authenticated User Input to the OS Shell, Enabling Arbitrary Command Execution | 9.1 Critical | New |
| 2026-09-08 | CVE-2026-75925 | IXON VPN Client Before 1.4.7 Writes Local Service Configuration Values to a File Without Stripping Line-Ending Sequences, Letting an Attacker Inject Commands That Execute as Root or SYSTEM via a Privileged Subprocess | 9.6 Critical | New |
| 2026-09-08 | CVE-2026-56671 | ComfyUI Model Preview Endpoint Joins an Unrestricted Filename Route Capture to the Model Directory Without a Containment Check, Allowing Unauthenticated Attackers to Read Arbitrary Image Files | 7.5 High | New |
| 2026-09-08 | CVE-2026-45538 | OpenSIPS 4.0.0 and Prior Stack Buffer Overflow in sip_to_json When a SIP Header Name Exceeds 255 Bytes, Enabling Remote Code Execution via Crafted SIP Messages | 9.8 Critical | New |
| 2026-09-08 | CVE-2026-26084 | Fortinet FortiSandbox 4.4.x and 5.0.x Improper Access Control Lets Attackers Access Sensitive Information via Crafted HTTP Requests | 9.9 Critical | New |
| 2026-09-08 | CVE-2026-16745 | Red Hat OpenShift AI odh-dashboard network binding flaw allows in-cluster attacker to bypass authentication and impersonate any user | 8.8 High | New |
| 2026-09-08 | CVE-2026-12562 | RCU II+ and Multiload II+ unauthenticated TCF service exposes root-level access to the embedded Linux environment | 8.8 High | New |
| 2026-09-08 | CVE-2026-10090 | Red Hat Advanced Cluster Management Application Subscription Controller Lets a User with Namespace-Scoped Edit Privileges Create a Channel Pointing to an Attacker-Controlled Helm Repository, Enabling Privilege Escalation | 9.0 Critical | New |
| 2026-09-08 | CVE-2025-46418 | Westermo WeOS 5.x OS command injection via media definition starting from version 5.24 | 7.6 High | New |
| 2026-09-04 | CVE-2026-85224 | D-Link DNS-320 ShareCenter 2.06B01 File Sharing CGI Passes the fileurl Parameter Unsanitized to the Shell, Enabling Remote Code Execution by Authenticated Admin Users | 9.1 Critical | New |
| 2026-09-04 | CVE-2026-85223 | D-Link DNS-340L 1.01B04 Dropbox CGI Injects the callback_url and sync_interval Fields Directly into the Shell, Allowing Low-Privileged Authenticated Attackers to Execute Remote Commands | 9.9 Critical | New |
| 2026-09-04 | CVE-2026-85222 | D-Link DNS-340L 1.01B04 Add-On Center CGI Passes f_name, f_url, and f_flag Unsanitized to the Shell, Enabling Authenticated Admin Remote Code Execution | 9.1 Critical | New |
| 2026-09-04 | CVE-2026-72669 | Kibana Observability Onboarding Flow State Is Not Bound to Its Creator, Letting Any Space Reader Read or Tamper with Other Users' Onboarding Progress | 7.6 High | Updated |
| 2026-09-04 | CVE-2026-67620 | Flowise SSRF Deny-List Omits Oracle Cloud and Alibaba Cloud Instance Metadata Endpoints, Exposing Instance Identity and Role Credentials | 7.7 High | Updated |
| 2026-09-04 | CVE-2026-60956 | Low-Privileged Attacker Can Take Over JD Edwards EnterpriseOne US Payroll via JDENET | 7.5 High | Updated |
| 2026-09-03 | CVE-2026-79679 | B&R mapp Audit Uses Weak Credentials, Enabling Network-Based Access with High Severity Impact | 8.7 High | New |
| 2026-09-03 | CVE-2026-64887 | Johnson Controls Airwall Hardcoded Cryptographic Key Enables Cryptanalytic Attack on Versions Before 4.1 | 7.0 High | New |
| 2026-09-03 | CVE-2026-34492 | Johnson Controls Airwall external filename control allows file manipulation before version 4.1 | 7.0 High | New |
| 2026-09-03 | CVE-2026-13505 | Bouncy Castle BC-FJA key material zeroisation depends on garbage collection finalization and may be delayed indefinitely | 8.7 High | New |
| 2026-09-02 | CVE-2026-82691 | D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 USB Device Handler Passes Unsanitized Input to the Shell, Enabling Authenticated Admin Remote Code Execution | 9.1 Critical | New |
| 2026-09-02 | CVE-2026-72658 | Kibana Vega Visualization Can Save Crafted Requests That Execute in Another User's Authenticated Session, Enabling Privilege Escalation via CSRF | 7.3 High | Updated |
| 2026-09-01 | CVE-2026-82688 | D-Link DNS-340L and DNS-345 Virtual Volume CGI Injects Input Arguments Unsanitized into the Shell, Enabling Authenticated Admin Remote Code Execution | 9.1 Critical | New |
| 2026-09-01 | CVE-2026-82593 | D-Link DIR-825M 1.1.8 LTE Fibocom Firmware Upgrade Handler Copies Unbounded User Input into a Fixed Stack Buffer, Enabling Unauthenticated Remote Code Execution | 9.9 Critical | New |
| 2026-09-01 | CVE-2026-0392 | eParakstītājs Windows auto-updater fetches and executes installer without certificate or integrity verification | 7.3 High | New |
| 2026-08-31 | CVE-2026-82692 | D-Link DNS-340L and DNS-345 iSCSI Manager CGI Passes alias, username, and password Arguments Directly to the Shell, Allowing Low-Privileged Attackers to Execute Remote Code | 9.9 Critical | New |
| 2026-08-31 | CVE-2026-82690 | D-Link DNS-327L and DNS-340L Virtual Environment Manager CGI Injects Unsanitized User Arguments into the Shell, Enabling Authenticated Admin Remote Code Execution | 9.1 Critical | New |
| 2026-08-31 | CVE-2026-82689 | D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 ISO Image Mount Handler Passes Mount Arguments Unsanitized to the Shell, Allowing Low-Privileged Attackers to Execute Remote Commands | 9.9 Critical | New |
| 2026-08-31 | CVE-2026-82680 | D-Link DSM-G600 Multipart Handler Out-of-Bounds Write in load_file.cgi Has a Public Exploit | 8.8 High | New |
| 2026-08-31 | CVE-2026-82595 | D-Link DIR-825M System Command Endpoint Passes sysCmd Unsanitized to the Shell; Public Exploit Available | 7.4 High | New |
| 2026-08-31 | CVE-2026-82592 | D-Link DIR-825M 1.1.8 Disk Format Handler Overflows a Stack Buffer When the manipulation Parameter Exceeds Its Declared Bounds, Enabling Unauthenticated Remote Code Execution | 9.9 Critical | New |
| 2026-08-31 | CVE-2026-72853 | Budibase Oracle Connector Post-Write Row Lookup Fails to Escape Table Names in SQL Identifiers, Enabling Injection for Users with Write Access to Specially Named Tables | 7.6 High | New |
| 2026-08-31 | CVE-2026-71957 | D-Link DWR-M961 C1 app.cgi Overflows a Stack Buffer on a Long netAcc.addlist[].name Value, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-71956 | D-Link DWR-M961 C1 app.cgi Injects the netDig.ping.dst Field Unsanitized into the Shell, Enabling Unauthenticated Remote Code Execution with Root Privileges | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-71952 | D-Link DWR-M961 C1 PIN Management Setup Handler Injects the oldPIn Field Into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-71951 | D-Link DWR-M961 C1 IMEI Setup Handler Passes the IMEI_value Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-71950 | D-Link DWR-M961 C1 SMS Management Handler Injects the action_value Field Directly into the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-71947 | D-Link DWR-M961 C1 Traceroute Diagnostic Handler Injects the host and ipVer Fields into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-71946 | D-Link DWR-M961 C1 Ping Diagnostic Run Handler Passes the host Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-31 | CVE-2026-69089 | Grav CMS Image Watermark Path Traversal Leaks Arbitrary Files to Anonymous Visitors via Public Cache URLs | 7.5 High | New |
| 2026-08-31 | CVE-2026-67298 | FreeRDP Server-Side RAIL Handler Integer Underflow in orderLength Bypasses Capacity Check and Writes Out of Bounds on the Heap; Fixed in 3.29.0 | 7.5 High | New |
| 2026-08-31 | CVE-2026-66152 | SonicWall NetExtender Linux File Extractor Path Traversal Lets an Authenticated Attacker Write Arbitrary Files as Root | 8.8 High | New |
| 2026-08-31 | CVE-2026-18129 | Ivanti Endpoint Manager cleartext credential transmission lets MITM attacker capture external SQL database credentials | 8.1 High | New |
| 2026-08-31 | CVE-2026-18127 | Ivanti Endpoint Manager filename control flaw gives authenticated attacker full write control over S3 session recording bucket | 7.7 High | New |
| 2026-08-31 | CVE-2025-14821 | libssh Windows insecure config loading from C:\etc exposes SSH connections to local MITM and downgrade attacks | 7.8 High | Updated |
| 2026-08-28 | CVE-2026-80660 | Linux Kernel OCC hwmon Driver Unregisters sysfs Devices While Holding the OCC Lock, Causing a Deadlock When hwmon_device_unregister Tries to Flush sysfs Work Items | — | New |
| 2026-08-28 | CVE-2026-80659 | Linux Kernel MMC vub300 Driver Issues a Reset While Holding cmd_mutex, Blocking the Command Thread That Must Complete Before the Reset Can Proceed | — | New |
| 2026-08-28 | CVE-2026-71958 | D-Link DWR-M961 C1 quicksetup.cgi Overflows a Stack Buffer on Long test4, ssid2, or username Values, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71955 | D-Link DWR-M961 C1 formWsc Handler Injects localPin, targetAPSsid, peerPin, and peerRptPin Fields into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71954 | D-Link DWR-M961 C1 L2TPv3 Configuration Handler Injects tunnelid and sessionid Fields Directly into the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71953 | D-Link DWR-M961 C1 NTP Setup Handler Passes the ntpServerIp1 Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71949 | D-Link DWR-M961 C1 USSD Setup Handler Injects ussdValue and selectMenuValue into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71948 | D-Link DWR-M961 C1 Debug Diagnostic Run Handler Passes the host Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71945 | D-Link DWR-M961 C1 LTE Fibocom Firmware Upgrade Handler Injects the fota_url Field into the Shell Without Sanitization, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-71944 | D-Link DWR-M961 C1 LTE Quectel Firmware Upgrade Handler Passes the fota_url Field Unsanitized to the Shell, Enabling Unauthenticated Remote Root Code Execution | 9.8 Critical | New |
| 2026-08-28 | CVE-2026-69109 | Siemens License Server Path Traversal Allows an Unauthenticated Remote Attacker to Read Arbitrary Files | 7.5 High | New |
| 2026-08-28 | CVE-2026-66153 | SonicWall NetExtender Linux Auto-Upgrade Process Handles Temporary Files Insecurely, Allowing Attackers to Manipulate File Paths | 7.0 High | New |
| 2026-08-28 | CVE-2026-66150 | Authenticated SonicWall Email Security CLI User Can Inject Arbitrary OS Commands as Root via SNMP | 7.8 High | New |
| 2026-08-28 | CVE-2026-66149 | Authenticated SonicWall Email Security CLI User Can Inject Arbitrary OS Commands as Root via Netmask Configuration | 7.8 High | New |
| 2026-08-28 | CVE-2026-61273 | Low-Privileged Network Attacker Can Achieve Full Takeover of JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.4 via HTTP | 8.8 High | Updated |
| 2026-08-28 | CVE-2026-61268 | Low-Privileged Network Attacker Can Modify and Read Critical Data in JD Edwards EnterpriseOne Tools Business Logic Infrastructure via HTTP | 8.1 High | Updated |
| 2026-08-28 | CVE-2026-18485 | NI-PAL kernel driver improper environment variable handling allows local privilege escalation on Windows through version 26.3.1 | 7.8 High | New |
| 2026-08-28 | CVE-2026-12587 | Hard-coded HMAC key in badge QR generation allows attacker with API access to forge physical access codes | 8.6 High | New |
| 2026-08-28 | CVE-2025-26238 | D-Link DI-8100G msp_info flag parameter allows arbitrary code execution | 8.1 High | New |
| 2026-08-28 | CVE-2025-26237 | D-Link DI-7001 msp_info flag parameter allows arbitrary command execution | 8.1 High | New |
| 2026-08-27 | CVE-2026-79057 | Chrome for Android Start Race Condition Allows a Co-Installed App to Execute Arbitrary Code Outside the Sandbox via Social Engineering | 8.1 High | New |
| 2026-08-27 | CVE-2026-76321 | Splunk Enterprise Nearby-Event Search Accepts Unauthenticated SPL Injection via Unescaped Caller Values and a Missing Authorization Check | 7.3 High | Updated |
| 2026-08-27 | CVE-2026-76319 | Splunk Enterprise Federated Search Bundle Selection Lacks Capability Enforcement, Granting Low-Privilege Users a Path to Remote Code Execution | 8.8 High | Updated |
| 2026-08-27 | CVE-2026-76317 | Splunk Enterprise Lookup Configuration Endpoint Accepts Unsanitized Source Paths, Letting Low-Privilege Users Move Arbitrary Files into Their Own Lookups | 8.8 High | Updated |
| 2026-08-27 | CVE-2026-76316 | Splunk Enterprise Inserts Unescaped Deployment Server Client Identifiers into Dispatched Searches, Giving Unauthenticated Attackers an SPL Injection Path That Executes with Admin Privileges | 8.8 High | Updated |
| 2026-08-27 | CVE-2026-76315 | Splunk Enterprise Web Manager Configuration REST Endpoint Missing Capability Check Allows Low-Privilege Users to Execute Arbitrary Code | 8.8 High | Updated |
| 2026-08-27 | CVE-2026-76314 | Splunk Enterprise Evaluates Web Manager Configuration XML Without Sufficient Input Restrictions, Enabling Low-Privilege Users to Execute Arbitrary Code | 8.8 High | Updated |
| 2026-08-27 | CVE-2026-76313 | Splunk Enterprise Knowledge Bundle Upload Endpoint Lacks the edit_dist_peer Capability Check, Allowing Low-Privilege Users to Achieve Remote Code Execution via Distributed Search | 8.8 High | Updated |
| 2026-08-27 | CVE-2026-76312 | Splunk Enterprise Below 10.4.1 Exposes Session Material in the HTML Source of Pages Embedding Reports, Letting Unauthenticated Users Who Can Read That Source Access All Report Data and Affect System Integrity | 9.4 Critical | Updated |
| 2026-08-27 | CVE-2026-76311 | Splunk Enterprise Below 10.4.2 Lets an Unauthenticated User with an Embedded Report Token Download the Search Job Dispatch Archive and Recover Session Material for Full Report Data Access | 9.4 Critical | Updated |
| 2026-08-27 | CVE-2026-76310 | Splunk Enterprise Below 10.4.2 Lets an Unauthenticated User with an Embedded Report Token Download the Dispatch Archive and Recover Session Tokens That Grant Access to All Data Available to the Report Owner | 9.4 Critical | Updated |
| 2026-08-27 | CVE-2026-76259 | Splunk Enterprise for Windows Allows a Local User to Pre-Bind the Management Port and Intercept Child-Process Authentication Tokens | 8.8 High | Updated |
| 2026-08-27 | CVE-2026-76254 | Splunk Enterprise Dataset Explorer Builds SPL Searches from Unescaped Dataset Names, Letting an Unauthenticated Attacker Trick a Victim into Dispatching Arbitrary Pipelines | 7.5 High | Updated |
| 2026-08-27 | CVE-2026-76253 | Splunk Enterprise schedule_search Capability Allows Alert Action Configuration to Run SPL at Highest System Privilege and Read the Full Credential Store | 8.8 High | Updated |
| 2026-08-27 | CVE-2026-73122 | Compromised RHACM Managed Cluster Agent Can Read All Channel Namespace Secrets and ConfigMaps on the Hub, Exposing Other Tenants' Repository Credentials | 7.7 High | New |
| 2026-08-27 | CVE-2026-72508 | Red Hat Advanced Cluster Management Multicloud Subscription Component Lets a Namespace-Admin Tenant Abuse a Privileged ServiceAccount via Subscription CRs, Enabling a Confused-Deputy Attack Against Other Cluster Namespaces | 9.9 Critical | New |
| 2026-08-27 | CVE-2026-70398 | Red Hat Advanced Cluster Management GitOpsCluster Controller Lets an Authenticated Tenant Redirect Spoke Cluster Bearer Tokens to an Attacker-Controlled Endpoint, Enabling a Confused-Deputy Attack | 9.6 Critical | New |
| 2026-08-27 | CVE-2026-66793 | Red Hat ACM governance-policy-addon-controller Lets Any User with ManagedClusterAddOn Annotation Permission Override the Container Image and Gain Cluster-Admin Access on Managed Clusters | 8.8 High | New |
| 2026-08-27 | CVE-2026-64561 | Linux KVM x86 Shadow MMU Checks for an Invalid Root Before Making Shadow Pages Available, Creating Invalid Child Pages When Reclaim Zaps an In-Use Root | 8.8 High | New |
| 2026-08-27 | CVE-2026-61272 | Oracle JD Edwards EnterpriseOne Tools Web Runtime SEC Component Allows Unauthenticated HTTP Attackers to Compromise the Application, Enabling Full Takeover of the EnterpriseOne Tools Instance | 9.8 Critical | Updated |
| 2026-08-27 | CVE-2026-61270 | Low-Privileged Network Attacker Can Modify and Read Critical Data in JD Edwards EnterpriseOne Orchestrator via HTTP | 8.1 High | Updated |
| 2026-08-27 | CVE-2026-61265 | Unauthenticated Network Attacker Can Take Over JD Edwards EnterpriseOne Orchestrator via TLS Despite High Attack Complexity | 8.1 High | Updated |
| 2026-08-27 | CVE-2026-15218 | Red Hat OpenShift AI maas-api ServiceAccount over-permissioned access enables attacker to gain full cluster administrator privileges | 7.9 High | New |
| 2026-08-27 | CVE-2026-13717 | Red Hat OpenShift AI MaaS Gateway misconfiguration lets low-privilege user intercept and alter all model traffic and access keys | 8.8 High | New |
| 2026-08-26 | CVE-2026-76325 | Splunk Enterprise Power-Role User Can Store a Malicious Auto-Tour Object That Executes Arbitrary JavaScript in Other Authenticated Users' Browsers | 7.3 High | Updated |
| 2026-08-26 | CVE-2026-76262 | Splunk Enterprise Edge Processor SPL2 Sidecar Exposes Prometheus Metrics to Unauthenticated Callers | 7.5 High | Updated |
| 2026-08-26 | CVE-2026-76251 | Splunk Enterprise Observability Cloud App REST Handlers Omit the read_o11y_content Capability Check, Exposing the App's Access Token to Low-Privilege Users | 7.1 High | Updated |
| 2026-08-26 | CVE-2026-73669 | Philips Hue Bridge Pro Embedded MQTT Broker Binds on All Interfaces Without Authentication, Exposing Light Control and Real-Time Data to Any Network-Reachable Client | 7.3 High | New |
| 2026-08-26 | CVE-2026-68586 | SiYuan Publish-Mode Content Endpoints Bypass Document-Level Access Filters, Exposing Publish-Forbidden Documents to Anonymous Readers | 8.6 High | New |
| 2026-08-26 | CVE-2026-6374 | Zyxel WAH7601 Hardcoded Credentials Allow an Attacker to Read Sensitive Constants in Firmware Through July 2026 | 7.3 High | New |
| 2026-08-26 | CVE-2026-14237 | vitepos WordPress plugin Outlet Manager role can reset any user's password including administrator accounts before version 3.6.0 | 7.2 High | New |
| 2026-08-26 | CVE-2026-13206 | Zyxel WAH7601 Through July 2026 Firmware OS Command Injection Allows Attackers to Execute Arbitrary OS Commands on Affected Devices | 9.8 Critical | New |
| 2026-08-26 | CVE-2026-12984 | Zyxel WAH7601 insufficiently protected credentials allow attacker to retrieve embedded sensitive data through firmware 20072026 | 8.2 High | New |
| 2026-08-25 | CVE-2026-74688 | Linux Kernel SCTP Heartbeat ACK Chunk Caches a Transport Without Taking a Reference, Enabling Use-After-Free When That Transport Is Concurrently Removed | 9.8 Critical | New |
| 2026-08-25 | CVE-2026-74635 | Linux Kernel fbdev bit_cursor Does Not Clamp Glyph Index to Font charcount, Enabling Out-of-Bounds Read via Stale Screen Buffer Entries or vcs_write | 7.8 High | New |
| 2026-08-25 | CVE-2026-74588 | Linux Kernel SCTP Retransmit Path Moves a Gap-Acked Chunk to a New Transport Without Updating the Chunk's Cached Transport Pointer, Enabling Use-After-Free | 9.8 Critical | New |
| 2026-08-25 | CVE-2026-74587 | Linux Kernel SCTP Teardown Path Frees the Cached Outbound ASCONF Chunk Without Clearing the Cache Pointer, Exposing a Use-After-Free | 9.8 Critical | New |
| 2026-08-25 | CVE-2026-74586 | Linux Kernel SCTP Fails to Clear new_transport After DEL-IP Peer Removal, Leaving a Dangling Pointer That Subsequent ASCONF Processing Reads | 9.8 Critical | New |
| 2026-08-23 | CVE-2026-72242 | Linux Kernel SELinux SCTP Hook Dereferences sk_socket Without a Non-NULL Guarantee, Reachable from the ASCONF Softirq Path | 7.5 High | New |
| 2026-08-23 | CVE-2026-68136 | Linux Kernel GRO Path Performs Double Aggregation of flush-Marked Skbs Because skb_gro_receive_list Lacks the Flush Check Added to skb_gro_receive | 9.8 Critical | New |
| 2026-08-23 | CVE-2026-64583 | Linux Kernel BDC UDC Driver Tears Down Endpoint Objects Before Releasing Its Interrupt Handler, Creating a Use-After-Free Window on Disconnect | 7.8 High | New |
| 2026-08-22 | CVE-2026-74677 | Linux Kernel ipheth USB Ethernet Driver Re-Arms carrier_work on Any Non-Zero URB Status After Disconnect Begins, Causing a Use-After-Free When the Work Item Runs After the Device Structure Is Freed | — | New |
| 2026-08-21 | CVE-2026-76362 | Splunk SOAR CyberArk REST Client Skips Server Certificate Verification by Default, Exposing Credentials to a Network-Path Attacker | 7.4 High | Updated |
| 2026-08-21 | CVE-2026-16526 | PCP linux_sockets module unsecured internal connection allows local code execution attacker to escalate to root | 8.8 High | New |
| 2026-08-21 | CVE-2026-16524 | PCP linux_sockets PMDA command injection via network.persocket.filter metric allows arbitrary command execution as PMDA user | 7.8 High | New |
| 2026-08-20 | CVE-2026-47871 | VMware Avi Load Balancer File Path Validation Flaw Allows Authenticated Network Users to Traverse Directories | 8.8 High | Updated |
| 2026-08-20 | CVE-2026-47870 | VMware Avi Load Balancer Privilege Escalation Flaw Allows an Authenticated Network User to Execute Code Remotely | 7.1 High | Updated |
| 2026-08-20 | CVE-2026-47869 | VMware Avi Load Balancer Remote Code Execution Flaw Allows an Authenticated Network User to Inject and Run Arbitrary Code | 8.7 High | Updated |
| 2026-08-20 | CVE-2026-47868 | VMware Avi Load Balancer Local Privilege Escalation Flaw Allows a Locally Authenticated User to Gain Root Access | 7.8 High | Updated |
| 2026-08-20 | CVE-2026-47867 | Unauthenticated Network Attacker Can Access the VMware Avi Load Balancer Control Plane and Execute Code Remotely | 8.7 High | Updated |
| 2026-08-20 | CVE-2026-47866 | VMware Avi Load Balancer Authorization Bypass Allows a Network Attacker to Access a Subset of the Control Plane Without Credentials | 8.3 High | Updated |
| 2026-08-20 | CVE-2026-47865 | VMware Avi Load Balancer 31.x Through 31.2.2 and 30.x Through 30.2.6 Authentication Bypass Lets Network-Accessible Attackers Reach the Avi Control Plane Without Valid Credentials | 9.8 Critical | Updated |
| 2026-08-20 | CVE-2026-24185 | NVIDIA NVOS SSH PKA-only mode misconfiguration enables unauthorized access when default password remains unchanged | 7.1 High | New |
| 2026-08-20 | CVE-2026-20231 | Cisco Secure Workload Improper Neutralization of Special Elements Vulnerabilities Allow Authenticated Attackers to Inject Directives into Application Commands, Scoring CVSS 9.9 | 9.9 Critical | New |
| 2026-08-20 | CVE-2026-20030 | Cisco Crosswork Multiple Internally Discovered SQL Injection Vulnerabilities Allow Authenticated Attackers to Execute Arbitrary SQL Against the Underlying Database, Scoring CVSS 10.0 | 10.0 Critical | New |
| 2026-08-19 | CVE-2026-74468 | Linux Kernel PCH GPIO Driver Acquires a Regular Spinlock in irq_set_type Which Can Be Called From a Non-IRQ Context, Leading to a Deadlock When Interrupts Are Disabled | — | New |
| 2026-08-19 | CVE-2026-74465 | Linux Kernel Open vSwitch Meter Attach Makes the Meter Visible Before All Checks Succeed, Creating a Use-After-Free on Plain kfree Failure | 7.8 High | New |
| 2026-08-19 | CVE-2026-72392 | Linux Kernel IPv6 FIB6 Walk Reuses a Stale Position Index Across Hash Chain Batches During a Multi-Batch Netlink Dump, Triggering a NULL Dereference in fib6_walk_continue | — | New |
| 2026-08-19 | CVE-2026-72124 | Linux Kernel CAN ISO-TP TX State Machine Mixes a Lock-Free Claim in sendmsg with Locked Timer Cancellation, Corrupting Concurrent Transfers | 8.8 High | New |
| 2026-08-19 | CVE-2026-68369 | Linux Kernel USB Gadget Printer Driver printer_read Uses the Same Variable for Requested Copy Size and Bytes Copied, Looping Indefinitely When copy_to_user Fails to Copy Anything | — | New |
| 2026-08-19 | CVE-2026-68160 | Linux Kernel Ceph Cap Handler Reads snap_trace_len from the Wire and Uses It Without Bounds Checking, Enabling a Network-Controlled Out-of-Bounds Read Before Authentication | 9.8 Critical | New |
| 2026-08-19 | CVE-2026-68148 | Linux Kernel fscrypt Direct Key Cache Omits Super_Block Comparison, Allowing a Key's Lifetime to Outlast Its Filesystem and Causing Use-After-Free | 7.8 High | New |
| 2026-08-19 | CVE-2026-68141 | Linux Kernel AF_IUCV Calls iucv_sock_kill on a NULL Pointer When Child Socket Allocation Fails, Crashing the Kernel on a Crafted Inbound Connection | 7.5 High | New |
| 2026-08-19 | CVE-2026-68137 | Linux Kernel X.25 Drops the x25_list_lock Before Calling sock_hold During Neighbour Teardown, Allowing a Concurrent Free to Race and Produce a Use-After-Free | 9.8 Critical | New |
| 2026-08-19 | CVE-2026-68127 | Linux Kernel ILA Caches the IPv6 Header Pointer Before pskb_may_pull, Which Can Reallocate the Header on a Non-Linear skb, Producing a Stale Pointer in Checksum Adjust | 9.8 Critical | New |
| 2026-08-19 | CVE-2026-68117 | Linux Kernel TIPC Socket Creation Error Path Frees the sk While Leaving sock->sk Pointing at the Freed Object, Enabling a Use-After-Free on Subsequent Socket Operations | 9.8 Critical | New |
| 2026-08-19 | CVE-2026-64565 | Linux Kernel Input ims-pcu Driver ims_pcu_process_data Processes Incoming URB Data Without Checking Whether read_pos Exceeds IMS_PCU_BUF_SIZE, Enabling Heap Buffer Overflow via a Crafted USB Device | — | New |
| 2026-08-19 | CVE-2026-64564 | Linux Kernel SCTP DEL-IP Processing Frees the Transport Cached on the ASCONF Chunk Itself, Triggering Use-After-Free on the Chunk's Own Transport Pointer | 9.8 Critical | New |
| 2026-08-19 | CVE-2026-64563 | Linux Kernel rhashtable Walk Restart Leaves a Stale Pointer After a Resize, Causing Use-After-Free in Multi-Fragment Walks | 7.8 High | New |
| 2026-08-19 | CVE-2026-64562 | Linux KVM nVMX Frees Shadow VMCS Before Clearing the vmcs01 Pointer, Racing with Migration-Triggered VMCLEAR | 8.8 High | New |
| 2026-08-19 | CVE-2026-21059 | Samsung Contacts improper component export allows local attacker to delete files using app privilege | 7.1 High | Updated |
| 2026-08-19 | CVE-2026-21058 | Samsung Contacts input validation flaw allows local attacker to delete files using app privilege | 7.1 High | Updated |
| 2026-08-18 | CVE-2026-72585 | CVE-2026-72585 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review | — | New |
| 2026-08-18 | CVE-2026-40144 | BeyondTrust Endpoint Privilege Management Kernel-Mode Component Fails to Validate Input Bounds, Allowing Out-of-Bounds Memory Access | 7.3 High | New |
| 2026-08-17 | CVE-2026-74287 | Linux Kernel SCTP ASCONF Chunk Processing Skips Length Validation of Embedded Address Parameters, Allowing Network-Controlled Data to Trigger Out-of-Bounds Reads | 9.1 Critical | New |
| 2026-08-17 | CVE-2026-72568 | CVE-2026-72568 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review | — | New |
| 2026-08-17 | CVE-2026-72540 | CVE-2026-72540 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review | — | New |
| 2026-08-17 | CVE-2026-72397 | Linux Kernel PMBus Voltage Output Setter Uses Hardcoded VR11 VID Encoding Regardless of Driver Configuration, Sending Wrong Voltage Codes to the Hardware | 7.1 High | New |
| 2026-08-17 | CVE-2026-72328 | Linux Kernel amdxdna GPU Memory Mapper Obtains References to Objects Already Being Released, Creating a Use-After-Free in aie2_populate_range | 7.8 High | New |
| 2026-08-17 | CVE-2026-72293 | Linux Kernel KVM s390 VSIE Shadow Fault Handler Missing radix_tree_preload Call Can Block Forward Progress Under Memory Pressure During Fault Handling | — | New |
| 2026-08-17 | CVE-2026-72265 | Linux Kernel nvidiafb Driver nvidiafb_probe Error Path Leaks the modelist Memory Allocated by nvidia_set_fbinfo When Subsequent Initialization Steps Fail | — | New |
| 2026-08-17 | CVE-2026-72029 | Linux Kernel WWAN iosm MUX Downlink Decoder Trusts Modem-Supplied Offsets and Lengths Without Validation, Enabling Out-of-Bounds Read and an Infinite Loop from a Malicious Modem | 8.8 High | New |
| 2026-08-17 | CVE-2026-71245 | CVE-2026-71245 Rejected by Red Hat CNA-LR as Not a Valid Security Vulnerability Following Internal Review | — | New |
| 2026-08-17 | CVE-2026-68260 | Linux Kernel PowerVR GPU VM Map Operation Skips the vm_ctx Lock, Racing with Find Operations and Causing NULL Pointer Dereference | 7.8 High | New |
| 2026-08-17 | CVE-2026-68170 | Linux Kernel MPTCP Cleans Up Subflow backlog References Outside the Lock That Guards the Backlog List, Leaving a Stale skb->sk Pointer After Subflow Close | 9.8 Critical | New |
| 2026-08-17 | CVE-2026-68122 | Linux Kernel OpenVPN Driver Peer Reference Count Leaks in the TCP Error Path When defer_del_work Is Already Pending, Preventing Timely Peer Cleanup | — | New |
| 2026-08-17 | CVE-2026-68092 | Linux Kernel Uses the jiffies Clocksource Before It Is Registered With the Clocksource Framework, Causing XEN HVM Guests to Experience Long Boot Delays Due to Negative Motion Reporting | — | New |
| 2026-08-17 | CVE-2026-68090 | Linux Kernel debugobjects OOM Disable Path Races Against a Concurrent hrtimer_fixup_assert_init Call, Producing a Spurious stub_timer Callback Warning | — | New |
| 2026-08-17 | CVE-2026-64603 | Linux Kernel Intel HID ACPI Notify Handler Can Run Concurrently on Multiple CPU Cores Since commit e2ffcda16290, Causing Race Conditions in the Hot-Plug Notification Handler | — | New |
| 2026-08-17 | CVE-2026-64593 | Linux Kernel btrfs Trim Path Calls blkdev_issue_discard on a Device Marked Read-Only During Degraded Mount, Dereferencing a NULL Device Pointer and Panicking | — | New |
| 2026-08-17 | CVE-2026-64588 | Linux Kernel fuse-uring Weak-Ordering Data Race on ring->ready Allows Stale fiq->ops Dispatch on Weakly-Ordered Architectures | 7.8 High | New |
| 2026-08-17 | CVE-2026-28323 | SolarWinds Web Help Desk SAML 2.0 Authentication Bypass Lets Attackers Authenticate Without Valid Credentials When SAML Is Enabled | 9.8 Critical | Updated |
| 2026-08-14 | CVE-2026-20313 | Cisco Catalyst SD-WAN hardening release addresses improper link resolution before file access | 7.7 High | New |
| 2026-08-14 | CVE-2026-20312 | Cisco Catalyst SD-WAN hardening release addresses cleartext storage of sensitive information | 8.8 High | New |
| 2026-08-14 | CVE-2026-20310 | Cisco Catalyst SD-WAN Addresses Multiple Internally Discovered Improper Link Resolution Vulnerabilities That Could Allow Local Privilege Escalation via Symlink Following | 9.1 Critical | New |
| 2026-08-14 | CVE-2026-20304 | Cisco Catalyst SD-WAN Improper Access Control Vulnerabilities Allow Attackers to Perform Unauthorized Actions on Affected Systems, Scoring CVSS 9.9 | 9.9 Critical | New |
| 2026-08-14 | CVE-2026-20303 | Cisco Catalyst SD-WAN Improper Input Validation Vulnerabilities Enable Attackers to Cause Unintended System Behavior on Affected Deployments, Scoring CVSS 9.9 | 9.9 Critical | New |
| 2026-08-13 | CVE-2026-64125 | Linux Kernel bcmgenet Driver Enabling RBUF EEE and PM Bits Stops RX Traffic When MAC EEE Activates, Causing a Denial-of-Service Condition on Broadcom GENET Hardware | 9.8 Critical | Updated |
| 2026-08-13 | CVE-2026-18358 | RHEL gnome-remote-desktop RDP listener bypasses connection throttling allowing pre-authentication connection exhaustion | 7.5 High | New |
| 2026-08-12 | CVE-2026-3141 | FormGent WordPress Plugin Through 1.9.2 Missing Capability Check on the formgent/responses/attachments REST Endpoint Lets Any Authenticated User Delete Arbitrary Attachments | 9.1 Critical | New |
| 2026-08-11 | CVE-2026-15416 | Argo CD repo-server unauthenticated remote code execution enables manipulation of cached data to compromise managed clusters | 8.9 High | New |
| 2026-08-11 | CVE-2026-0288 | Multiple Buffer Overflows in the Palo Alto Networks PAN-OS User-ID Terminal Server Agent Allow Unauthenticated Denial of Service or Potential Code Execution | 7.5 High | New |
| 2026-08-07 | CVE-2026-67261 | Dell Virtual Storage Integrator for VMware vSphere Client IAPI Component Accepts Unauthenticated Remote Input and Passes It to the OS Shell, Enabling Arbitrary Command Execution on the Application Host | 9.8 Critical | Updated |
| 2026-08-07 | CVE-2026-56160 | Azure Red Hat OpenShift Improper Authorization Lets an Authorized Attacker Escalate Privileges Over the Network | 9.1 Critical | Updated |
| 2026-08-07 | CVE-2026-54489 | Dell Virtual Storage Integrator for VMware vSphere Client Exposes Sensitive Information to Unauthenticated Remote Attackers, Enabling Information Disclosure and Session Hijacking | 9.1 Critical | Updated |
| 2026-08-07 | CVE-2026-47623 | NVIDIA Dynamo's Deserialization of Untrusted Data Allows Remote Attackers to Execute Arbitrary Code via a Crafted Serialized Object | 8.2 High | Updated |
| 2026-08-07 | CVE-2026-47618 | NVIDIA Dynamo's Server-Side Request Forgery Flaw Lets Attackers Use the Inference Server as an HTTP Proxy to Reach Internal Services | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-47617 | NVIDIA Dynamo Server-Side Request Forgery Flaw Allows Attackers to Make the Service Issue Requests to Arbitrary Hosts, Including Internal Resources | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-47616 | NVIDIA Dynamo's SSRF Vulnerability Exposes Internal Network Infrastructure to Attackers Who Can Redirect the Server's Outbound HTTP Connections | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-47615 | NVIDIA Dynamo's Unvalidated URL Handling Lets Attackers Steer the Inference Server's HTTP Requests Toward Internal Hosts and Retrieve Their Responses | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-47614 | NVIDIA Dynamo Carries an SSRF Flaw That Enables Attackers to Probe Internal Services via the Dynamo Server's Request Mechanism | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-47613 | NVIDIA Dynamo's Server-Side Request Forgery Vulnerability Allows Attackers to Redirect the AI Inference Server's HTTP Requests Toward Internal or External Targets | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-47612 | NVIDIA Dynamo's Path Traversal Flaw Allows Attackers to Navigate Outside the Intended Directory and Read or Write Files in Restricted Locations | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-24255 | NVIDIA Dynamo's Incomplete Input Comparison Allows Attackers to Bypass a Security Check by Supplying Input the Comparison Logic Fails to Fully Evaluate | 7.5 High | Updated |
| 2026-08-07 | CVE-2026-24254 | NVIDIA Dynamo's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access the AI Inference Platform Without Valid Credentials | 9.8 Critical | Updated |
| 2026-08-07 | CVE-2026-24253 | NVIDIA Dynamo's Out-of-Bounds Write Allows Remote Attackers to Corrupt Memory and Potentially Execute Arbitrary Code via a Crafted Request | 8.2 High | Updated |
| 2026-08-06 | CVE-2026-60497 | Low-Privileged Attacker Can Take Over JD Edwards EnterpriseOne CRM Foundation via JDENET | 7.5 High | Updated |
| 2026-08-06 | CVE-2026-60496 | Low-Privileged Attacker Can Take Over JD Edwards EnterpriseOne Advanced Pricing via JDENET | 7.5 High | Updated |
| 2026-08-06 | CVE-2026-60495 | Low-Privileged Attacker Can Take Over JD Edwards EnterpriseOne Requirements Planning via JDENET | 7.5 High | Updated |
| 2026-08-06 | CVE-2026-60494 | Unauthenticated Attacker Can Crash or Modify Data in JD Edwards EnterpriseOne General Ledger via HTTP | 7.0 High | Updated |
| 2026-08-06 | CVE-2026-60493 | Low-Privileged Network Attacker Can Take Over JD Edwards EnterpriseOne Human Resources Management via HTTP | 8.8 High | Updated |
| 2026-08-06 | CVE-2026-60492 | Low-Privileged Network Attacker Can Crash or Read a Data Subset from JD Edwards EnterpriseOne HCM Foundation via HTTP | 7.1 High | Updated |
| 2026-08-06 | CVE-2026-60490 | Low-Privileged HTTP Attacker Can Achieve Full Takeover of JD Edwards EnterpriseOne CRM Foundation 9.2 | 8.8 High | Updated |
| 2026-08-06 | CVE-2026-60489 | JD Edwards EnterpriseOne CRM Foundation 9.2 Contains a Second Low-Privilege HTTP Escalation Path Leading to Full Takeover | 8.8 High | Updated |
| 2026-08-06 | CVE-2026-55733 | ueberauth Guardian Passes Attacker-Controlled Permission Scope Binaries to String.to_atom Without an Allow-List, Allowing Denial of Service via Atom Table Exhaustion | 7.5 High | Updated |
| 2026-08-06 | CVE-2026-21655 | Johnson Controls victor and CCure deserialization vulnerability allows remote code execution on Windows | 8.7 High | New |
| 2026-08-06 | CVE-2026-20263 | Cisco IOS XE BEEP SOAP request parsing flaw causes unexpected device reload | 8.6 High | New |
| 2026-08-05 | CVE-2026-6837 | Zyxel WAX650S export-cgi Script Passes Input Unsanitized to OS Commands, Allowing Authenticated Administrators to Execute Arbitrary Shell Commands | 7.2 High | New |
| 2026-08-05 | CVE-2026-60007 | Eclipse Milo OPC UA Username-Token Decryption Returns Distinguishable RSA Padding Errors, Exposing a Bleichenbacher Oracle via Unauthenticated ActivateSession Requests | 7.4 High | Updated |
| 2026-08-05 | CVE-2026-18574 | Check Point Security Management Server and Multi-Domain Management Server Authentication Bypass Lets Unauthenticated Remote Attackers Execute Arbitrary Commands via Management Service Network Access | 9.3 Critical | New |
| 2026-08-05 | CVE-2026-17566 | pgAdmin 4 Import/Export Data Tool Builds a psql \copy Command by Interpolating User-Supplied SQL into a Jinja Template Without Sufficient Escaping, Enabling Authenticated Attackers to Execute Arbitrary OS Commands | 9.9 Critical | Updated |
| 2026-08-04 | CVE-2026-17894 | Use-After-Free in Google Chrome for Linux's Views Component Allows Remote Heap Corruption via a Crafted HTML Page, Fixed in 151.0.7922.72 | 8.8 High | New |
| 2026-08-04 | CVE-2026-14818 | Zyxel ATP and USG FLEX CLI path traversal allows admin with elevated privileges to execute malicious configuration files | 7.2 High | New |
| 2026-08-04 | CVE-2026-13325 | CVE-2026-13325 Rejected by Red Hat Product Security After Concluding the CVE Record Is Not Needed | — | New |
| 2026-08-03 | CVE-2026-17877 | Chromoting's Network Traffic Handling in Google Chrome for Linux Lets a Local Attacker Escalate to OS-Level Privileges, Fixed in 151.0.7922.72 | 8.4 High | New |
| 2026-08-03 | CVE-2026-17744 | Remote Attacker Can Potentially Escape the Browser Sandbox Through Google Chrome for Linux's File Input Component Using a Crafted HTML Page, Prior to 151.0.7922.72 | 7.1 High | New |
| 2026-08-03 | CVE-2026-10079 | Red Hat ACS null deployment-config label bypasses deploy-time policy detection and enforcement | 8.5 High | New |
| 2026-07-31 | CVE-2026-58263 | Jodit Editor HTML Sanitizer Can Be Bypassed via a MathML and Style Element Combination, Allowing a Surviving Event Handler to Execute JavaScript | 7.2 High | New |
| 2026-07-31 | CVE-2026-22622 | Eaton Tripp Lite PADM session management flaw allows authenticated user to escalate to unrestricted device access | 8.8 High | New |
| 2026-07-31 | CVE-2026-22621 | Eaton Tripp Lite PADM session management flaw allows authenticated administrator to execute commands in restricted environment | 8.3 High | New |
| 2026-07-30 | CVE-2026-61892 | Weintek cMT3092X HMI Allows a Low-Privilege User to Modify Authentication Tokens and Escalate Privileges | 8.8 High | New |
| 2026-07-30 | CVE-2026-60134 | Weintek cMT3092X HMI Allows a Low-Privilege User to Elevate Privileges by Modifying Session Cookies | 8.8 High | New |
| 2026-07-30 | CVE-2026-5433 | Honeywell Control Network Module Web Interface Allows Command Delimiter Injection, Potentially Enabling Remote Code Execution via the Web Management Interface | 9.1 Critical | New |
| 2026-07-30 | CVE-2026-47876 | VMware ESX VMXNET3 Virtual Network Adapter Contains an Out-of-Bounds Write Reachable by a Local VM Admin, Potentially Enabling Code Execution on the Underlying Host | 9.3 Critical | New |
| 2026-07-30 | CVE-2026-41703 | VMware ESX, Workstation, and Fusion Out-of-Bounds Read Is Reachable by an Attacker with VM Deployment Privileges and Can Disclose Host Memory or Crash the Host Process | 7.6 High | New |
| 2026-07-30 | CVE-2026-34496 | Johnson Controls victor Web improper privilege management allows unauthorized privilege use on Windows before version 7.1 | 7.1 High | New |
| 2026-07-30 | CVE-2026-21653 | Johnson Controls CCure 9000 and victor application server SSRF vulnerability in versions 2.9 through 3.0 | 7.2 High | New |
| 2026-07-30 | CVE-2026-17192 | Arista VCO insufficient input validation allows Enterprise Standard Admin to send requests to internal services | 8.5 High | New |
| 2026-07-30 | CVE-2026-17191 | Arista EOS Orchestrator API Component Fails to Validate Input Before Building Backend Queries, Letting Authenticated Users Access Unauthorized Data and Trigger Unintended Outbound Network Connections | 9.1 Critical | New |
| 2026-07-30 | CVE-2026-16347 | MikroTik RouterOS API lacks effective rate-limiting; concurrent sessions bypass per-connection delay to enable credential brute force | 8.8 High | New |
| 2026-07-30 | CVE-2026-15929 | LG SmartShare SQL injection on Windows 10 and earlier through version 2.3.1712.1202 | 7.1 High | New |
| 2026-07-30 | CVE-2022-4994 | Linux Kernel KVM x86 Fast IN Path Calls emulator_pio_in When __emulator_pio_in Could Be Used Directly, Causing Unnecessary Indirection in the PIO Emulation Path | — | New |
| 2026-07-28 | CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem Management Plane Executes Injected OS Commands; CISA's July 30th KEV Deadline Has Passed for Covered Entities | 10.0 Critical | KEV |
| 2026-07-28 | CVE-2025-59172 | Ericsson Packet Core Controller command injection executes arbitrary code as root before version 1.38 | 8.5 High | New |
| 2026-07-27 | CVE-2026-63880 | Linux Kernel amdgpu GEM Op IOCTL Leaks a drm_exec Lock Held at the Time of a kvcalloc Failure in AMDGPU_GEM_OP_GET_MAPPING_INFO, Causing a Lock Imbalance | — | New |
| 2026-07-27 | CVE-2026-10517 | CVE-2026-10517 Retracted by Red Hat Product Security and Upstream Clair/Claircore Maintainer After Confirming the Described PSK Authentication Behavior Is Intentional and Implemented in a Separate Package | — | New |
| 2026-07-25 | CVE-2026-33019 | libsixel integer overflow in crop handling causes overflow in bounds guard and triggers heap out-of-bounds read | 7.1 High | Updated |
| 2026-07-25 | CVE-2026-1460 | Zyxel DX3301-T0 and EX3301-T0 DHCP DomainName parameter command injection allows admin to execute OS commands | 7.2 High | Updated |
| 2026-07-25 | CVE-2025-52222 | D-Link DI-series radius_asp buffer overflow via crafted RADIUS parameters causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50670 | D-Link DI-8003 buffer overflow in xwgl_bwr.asp name/qq/time parameters causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50669 | D-Link DI-8003 buffer overflow in wan_ping.asp wan_ping parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50668 | D-Link DI-8003 buffer overflow in web_list_opt.asp s parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50667 | D-Link DI-8003 buffer overflow in wan_line_detection.asp iface parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50666 | D-Link DI-8003 buffer overflow in web_post.asp via multiple parameters causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50665 | D-Link DI-8003 buffer overflow in web_keyword.asp via multiple parameters causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50664 | D-Link DI-8003 buffer overflow in user_group.asp name/mem/pri/attr parameters causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50663 | D-Link DI-8003 buffer overflow in usb_paswd.asp name parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50662 | D-Link DI-8003 buffer overflow in url_group.asp name parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50661 | D-Link DI-8003 buffer overflow in url_rule.asp via multiple URL policy parameters causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50660 | D-Link DI-8003 buffer overflow in url_member.asp name parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50659 | D-Link DI-8003 buffer overflow in user.asp custom_error parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50657 | D-Link DI-8003 buffer overflow in trace.asp pid parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50655 | D-Link DI-8003 buffer overflow in thd_group.asp name parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50654 | D-Link DI-8003 buffer overflow in thd_member.asp id parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50653 | D-Link DI-8003 buffer overflow in time_group.asp name and mem parameters causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50652 | D-Link DI-8003 improper id parameter handling in saveparm_usb.asp causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50650 | D-Link DI-8003 buffer overflow in router.asp routes_static parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50649 | D-Link DI-8003 buffer overflow in shut_set.asp vlan_name parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50648 | D-Link DI-8003 buffer overflow in tggl.asp causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50647 | D-Link DI-8003 buffer overflow in qos.asp wans parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50646 | D-Link DI-8003 buffer overflow in qos_type_asp.asp name parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50645 | D-Link DI-8003 buffer overflow in pppoe_list_opt.asp s parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-50644 | D-Link DI-8003 buffer overflow in qj.asp causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-45059 | D-Link DI-8300 buffer overflow in tgfile_htm fn parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-45058 | D-Link DI-8300 buffer overflow in jingx_asp fx parameter causes denial of service | 7.5 High | Updated |
| 2026-07-25 | CVE-2025-45057 | D-Link DI-8300 buffer overflow in ip_position_asp ip parameter causes denial of service | 7.5 High | Updated |
| 2026-07-24 | CVE-2026-7865 | Crestron Hidden Console Command Passes Control Characters to popen, Letting Authenticated SSH Users Inject Underlying OS Commands | 7.4 High | New |
| 2026-07-24 | CVE-2026-5709 | AWS Research and Engineering Studio FileBrowser API Passes Unsanitized Input to OS Commands, Allowing an Authenticated Remote User to Execute Arbitrary Code on the Cluster Manager | 8.8 High | Updated |
| 2026-07-24 | CVE-2026-5708 | AWS Research and Engineering Studio Session Creation Accepts Attacker-Controlled Attributes, Letting an Authenticated User Assume the Virtual Desktop Host Instance Profile | 8.8 High | Updated |
| 2026-07-24 | CVE-2026-5707 | AWS Research and Engineering Studio Session Name Passes Unsanitized Input to OS Commands, Allowing an Authenticated Remote User to Execute Arbitrary Commands as Root | 8.8 High | Updated |
| 2026-07-24 | CVE-2026-53005 | Linux Kernel AF_UNIX SOCKMAP Redirect Hides Inflight File Descriptors from the Garbage Collector, Leaking Inflight Sockets Indefinitely | 7.8 High | Updated |
| 2026-07-24 | CVE-2026-4483 | Moxa MxGeneralIo Utility Exposes Privileged IOCTL Methods Without Adequate Access Control, Enabling Privilege Escalation on Windows 7 and System Crashes on Windows 10 and 11 | 7.0 High | New |
| 2026-07-24 | CVE-2026-4272 | Honeywell Handheld Scanner Base Station Exposes Critical System Functions Without Authentication, Allowing a Bluetooth-Range Attacker to Execute Commands on the Connected Host | 8.1 High | New |
| 2026-07-24 | CVE-2026-35187 | pyLoad parse_urls API server-side request forgery allows authenticated user to reach internal network resources and read local files | 7.7 High | Updated |
| 2026-07-24 | CVE-2026-31405 | Linux Kernel DVB-net ULE Extension Handler Uses a Network-Controlled Index into a 255-Entry Table Without Bounds Checking, Enabling Out-of-Bounds Reads and Writes | 9.8 Critical | Updated |
| 2026-07-24 | CVE-2026-28390 | OpenSSL NULL pointer dereference in RSA-OAEP CMS EnvelopedData processing causes denial of service before authentication | 7.5 High | Updated |
| 2026-07-24 | CVE-2026-28389 | OpenSSL NULL pointer dereference in KeyAgreeRecipientInfo CMS EnvelopedData processing causes denial of service | 7.5 High | Updated |
| 2026-07-24 | CVE-2026-28388 | OpenSSL NULL pointer dereference in delta CRL Number extension processing causes denial of service | 7.5 High | Updated |
| 2026-07-24 | CVE-2026-28321 | SolarWinds Serv-U Broken Access Control Allows a Domain Administrator to Read and Write Arbitrary Files, Then Escalate Privileges and Execute Code as Root | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28317 | SolarWinds Serv-U IDOR Vulnerability Lets a Domain Administrator Reference Objects Outside Their Authorized Scope to Escalate Privileges | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28316 | SolarWinds Serv-U IDOR Vulnerability Lets a Domain Account With Administrator Access Escalate to System Administrator and Execute Commands as Root | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28314 | SolarWinds Serv-U IDOR Vulnerability Allows Authenticated Users to Reference Objects Outside Their Authorized Scope, Leading to Account Takeover | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28313 | SolarWinds Serv-U IDOR Vulnerability Enables SMTP Configuration Hijacking, Allowing an Authenticated User to Take Over Arbitrary Accounts | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28312 | SolarWinds Serv-U Privilege Escalation Lets a Group's Access Be Elevated to System Administrator, Enabling Code Execution as Root | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28310 | SolarWinds Serv-U Privilege Escalation Allows a Domain Administrator to Elevate Their User Type to System Administrator | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28309 | SolarWinds Serv-U Broken Access Control Lets a Domain Administrator Create System Administrator Accounts Without Proper Authorization | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28308 | SolarWinds Serv-U IDOR Vulnerability Allows a Domain Administrator to Reference Objects Outside Authorized Scope, Leading to Remote Code Execution | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28307 | SolarWinds Serv-U Privilege Escalation Allows a Domain User Group to Be Elevated to Administrator Access Without Authorization | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28306 | SolarWinds Serv-U Privilege Escalation Allows a Domain Administrator to Elevate Their Privileges to System Administrator Level | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28305 | SolarWinds Serv-U IDOR Vulnerability Allows a Domain Administrator with Home Directory Access to Reference Out-of-Scope Objects, Enabling Remote Code Execution as Root | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28304 | SolarWinds Serv-U Remote Code Execution Vulnerability Allows Arbitrary Code to Run as Root on Affected Linux Installations | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-28302 | SolarWinds Serv-U IDOR Vulnerability Lets Group Administrators Reference Out-of-Scope Objects to Escalate Privileges and Execute Code as Root | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2026-25112 | Genetec RabbitMQ deployment misconfiguration allows privilege escalation attack | 7.8 High | New |
| 2026-07-24 | CVE-2026-23458 | Linux kernel ctnetlink multi-round dump dereferences freed conntrack pointer in second callback invocation | 7.8 High | Updated |
| 2026-07-24 | CVE-2026-23450 | Linux Kernel SMC-over-TCP SYN Receive Path Calls sock_hold Then Schedules a tcp_close Work Item Without Synchronizing Against Concurrent Stack Cleanup, Enabling Use-After-Free and Null Dereference | 9.8 Critical | Updated |
| 2026-07-24 | CVE-2026-23419 | Linux kernel rds_tcp_tune circular locking dependency causes deadlock via sk_net_refcnt_upgrade | 7.5 High | Updated |
| 2026-07-24 | CVE-2026-20297 | Splunk app installation path traversal allows privileged user to write files outside the intended app directory | 7.2 High | Updated |
| 2026-07-24 | CVE-2026-20296 | Splunk Deployment Server XSS tricks users into executing SPL searches as splunk-system-user exposing stored credentials | 8.3 High | Updated |
| 2026-07-24 | CVE-2025-58349 | Samsung Exynos L2 Layer Incorrect Handling of LTE MAC Packets Containing Many MAC Control Elements Leads to Uncontrolled Resource Consumption, Affecting Processors from Exynos 980 Through W1000 | 9.1 Critical | Updated |
| 2026-07-24 | CVE-2025-54602 | Samsung Exynos Wi-Fi driver concurrent ioctl race triggers use-after-free condition | 7.0 High | Updated |
| 2026-07-24 | CVE-2025-54601 | Samsung Exynos Wi-Fi driver concurrent ioctl race triggers double-free condition | 7.0 High | Updated |
| 2026-07-24 | CVE-2025-54328 | Samsung Exynos Modem SMS Processing Stack-Based Buffer Overflow, Scoring CVSS 10.0 and Affecting Processors from Exynos 980 Through Exynos 2500 and Multiple Modem Generations | 10.0 Critical | Updated |
| 2026-07-24 | CVE-2025-14859 | Semtech LR11xx LoRa secure boot second-preimage weakness enables unauthorized firmware installation via physical access | 7.0 High | New |
| 2026-07-24 | CVE-2025-14816 | Mitsubishi Electric GENESIS64 and ICONICS Suite 10.97.3 and Prior Store Sensitive Information in Cleartext in the GUI, Potentially Allowing Local Attackers to Recover Credentials From Screen Captures or Memory | 9.3 Critical | New |
| 2026-07-24 | CVE-2025-14815 | Mitsubishi Electric GENESIS64 and ICONICS Suite 10.97.3 and Prior Store Sensitive Information in Cleartext in Persistent Storage, Potentially Allowing Local Attackers to Recover Credentials From Disk | 9.3 Critical | New |
| 2026-07-24 | CVE-2019-25671 | VA MAX changeip.php mtu_eth0 parameter shell injection allows authenticated attacker to execute commands as apache user | 8.8 High | New |
| 2026-07-23 | CVE-2026-8992 | Ivanti Secure Access Client Certificate Validation Flaw Lets an Unauthenticated Remote Attacker Execute Arbitrary Code | 8.8 High | Updated |
| 2026-07-23 | CVE-2026-8370 | Broadcom Automic Automation Unix Agent Runs Target Programs with Excessive Privileges, Enabling Local Escalation on Affected Linux Platforms | 8.5 High | New |
| 2026-07-23 | CVE-2026-6952 | Zyxel AX7501-B1 Syslog LogServer Field Passes Input Unsanitized to the Shell, Allowing Authenticated Administrators to Execute OS Commands | 7.2 High | New |
| 2026-07-23 | CVE-2026-54420 | LiteSpeed's cPanel Plugin Follows Symlinks Across Security Boundaries to Escalate Privileges; CISA's June 18th KEV Remediation Window Has Closed for Covered Entities | 8.5 High | KEV |
| 2026-07-23 | CVE-2026-39834 | SSH Channel Write Path Overflows a Size Counter on Payloads Larger Than 4GB, Causing the Write Loop to Spin Indefinitely Sending Empty Packets Without Making Progress | 9.1 Critical | Updated |
| 2026-07-23 | CVE-2026-20239 | Splunk low-privilege users with _internal index access can read session cookies and sensitive response data | 7.5 High | Updated |
| 2026-07-23 | CVE-2026-10727 | Ivanti EPMM authenticated remote OS command injection executes arbitrary commands as root | 7.2 High | New |
| 2026-07-23 | CVE-2026-10523 | Ivanti Sentry Before R10.5.2 / R10.6.2 / R10.7.1 Authentication Bypass Lets Unauthenticated Remote Attackers Create Arbitrary Administrative Accounts and Obtain Full Administrative Access | 9.9 Critical | Updated |
| 2026-07-23 | CVE-2026-0273 | Authenticated PAN-OS Administrators Can Bypass CLI and Web UI Restrictions to Run Arbitrary Commands as Root via Command Injection | 7.2 High | New |
| 2026-07-23 | CVE-2026-0272 | PAN-OS CLI Access Lets an Authenticated Administrator Perform Actions with Root Privileges via a Privilege Management Bypass | 7.2 High | New |
| 2026-07-23 | CVE-2026-0271 | Local Users on Linux Devices Running Palo Alto Networks Prisma Access Agent Can Execute Code with Elevated Privileges via a Permission Misconfiguration | 7.8 High | New |
| 2026-07-23 | CVE-2025-71217 | Trend Micro Apex One for Mac self-protection origin validation flaw allows local privilege escalation | 7.8 High | Updated |
| 2026-07-23 | CVE-2025-71216 | Trend Micro Apex One for Mac agent cache time-of-check flaw allows local privilege escalation | 7.8 High | Updated |
| 2026-07-23 | CVE-2025-71215 | Trend Micro Apex One for Mac iCore service TOCTOU flaw allows local privilege escalation | 7.0 High | Updated |
| 2026-07-23 | CVE-2025-71214 | Trend Micro Apex One for Mac iCore service origin validation error allows local privilege escalation | 7.8 High | Updated |
| 2026-07-23 | CVE-2025-71213 | Trend Micro Apex One origin validation error allows local privilege escalation | 7.8 High | Updated |
| 2026-07-23 | CVE-2025-71212 | Trend Micro Apex One scan engine link-following flaw allows local privilege escalation | 7.8 High | Updated |
| 2026-07-23 | CVE-2025-71211 | Trend Micro Apex One Management Console Path Traversal in a Second Executable Allows Remote Attackers to Upload Malicious Code and Execute Commands on Affected Installations | 9.8 Critical | Updated |
| 2026-07-23 | CVE-2025-71210 | Trend Micro Apex One Management Console Path Traversal Allows Remote Attackers to Upload Malicious Code and Execute Commands on Affected Installations | 9.8 Critical | Updated |
| 2026-07-23 | CVE-2024-58330 | Bosch CPP13 and CPP14 IP cameras expose video analytics event data without authentication | 7.5 High | New |
| 2026-07-23 | CVE-2024-58023 | Bosch Configuration Manager 7.72.0106 information disclosure allows attacker to access sensitive data | 8.4 High | New |
| 2026-07-22 | CVE-2026-9614 | Authenticated Remote Attacker Can Gain Administrative Access to Ivanti Neurons for ITSM via Improper Access Control | 8.8 High | New |
| 2026-07-22 | CVE-2026-50033 | Acronis DeviceLock DLP for Windows DLL Hijacking Flaw Allows a Local Attacker to Escalate Privileges | 7.3 High | New |
| 2026-07-22 | CVE-2026-44682 | Acronis DeviceLock DLP for Windows Contains a DLL Hijacking Path That Allows Local Privilege Escalation | 7.3 High | New |
| 2026-07-22 | CVE-2026-44609 | Acronis DeviceLock DLP for Windows EXE Hijacking Flaw Allows a Local Attacker to Escalate Privileges | 7.3 High | New |
| 2026-07-22 | CVE-2026-42061 | Acronis DeviceLock DLP for Windows Child Processes Receive Excessive Permissions, Enabling Local Privilege Escalation | 7.3 High | New |
| 2026-07-22 | CVE-2026-40619 | Genetec Security Center Specific Installation Package Builds Allow a Local Attacker to Read Server Admin Credentials from the Main Server | 7.8 High | New |
| 2026-07-22 | CVE-2026-28299 | SolarWinds Web Help Desk denial of service crashes the server via insufficient memory handling | 8.2 High | Updated |
| 2026-07-22 | CVE-2025-8873 | Arista EOS crafted IPsec packet halts dataplane processing and traffic may not resume after reset | 7.5 High | New |
| 2026-07-22 | CVE-2025-48595 | Android Framework's Integer Overflow Enables Code Execution and Local Privilege Escalation; CISA's June 5th KEV Deadline Has Passed | 8.4 High | KEV |
| 2026-07-22 | CVE-2024-27892 | Arista EOS with OpenConfig Configured Fails to Reject Certain gNMI Set Requests That Should Not Execute, Potentially Allowing Unauthorized Configuration Changes on Affected Switches | 9.6 Critical | New |
| 2026-07-22 | CVE-2024-27890 | Arista EOS with OpenConfig Configured Fails to Reject a Second Class of gNMI Set Requests That Should Not Execute, Potentially Allowing Unauthorized Configuration Changes on Affected Switches | 9.6 Critical | New |
| 2026-07-22 | CVE-2024-14036 | Dräger Core and M540 malformed SDC discovery packets exhaust CPU and block further SDC message processing | 7.5 High | New |
| 2026-07-22 | CVE-2022-4992 | Dräger Infinity Acute Care System network message handling allows remote manipulation of alarm settings and denial of service | 8.6 High | New |
| 2026-07-22 | CVE-2021-4481 | Dräger Protector Software insecure file permissions allow local attacker to replace binaries and execute code as SYSTEM | 8.2 High | New |
| 2026-07-22 | CVE-2021-4480 | Dräger Protector Software insecure permissions provide a second local path to SYSTEM code execution via module replacement | 8.2 High | New |
| 2026-07-22 | CVE-2021-4478 | Dräger CC-Vision crafted .gdt file triggers buffer overflow during parsing and allows crash or code execution | 8.2 High | New |
| 2026-07-22 | CVE-2019-25722 | Dräger SC Monitoring devices contain hard-coded credentials and denial-of-service vulnerability across all software versions | 7.6 High | New |
| 2026-07-22 | CVE-2019-25719 | Dräger Infinity Acute Care and M540 network message vulnerabilities allow alarm setting changes and denial of service | 8.6 High | New |
| 2026-07-22 | CVE-2019-25718 | Dräger Infinity Explorer C700 kiosk escape allows OS control and causes device to display incorrect patient monitor data | 8.4 High | Updated |
| 2026-07-21 | CVE-2026-9509 | Unauthenticated HTTP POST to Suprema BioStar 2 Migration Endpoint Triggers Unhandled Exception That Halts Access Control Readers | 8.7 High | New |
| 2026-07-21 | CVE-2026-9508 | Suprema BioStar 2 Exposes Backup ZIP Files Without Authentication When Administrator Places the Backup Path Inside the NGINX Webroot, Allowing Database Download and Server Impersonation | 10.0 Critical | New |
| 2026-07-21 | CVE-2026-50131 | Fedify IPv4 Public Address Validation Leaves Some Private Address Ranges Unblocked, Allowing SSRF to Internal Services via Incomplete IPv4 Checks | 8.6 High | New |
| 2026-07-21 | CVE-2026-48695 | FastNetMon MikroTik Router Integration Plugin Concatenates Attack Data Directly into Shell Commands, Enabling Command Injection from Argv-Controlled Input | 8.1 High | Updated |
| 2026-07-20 | CVE-2025-57834 | Samsung Exynos missing input validation causes denial of service across multiple processor models | 7.5 High | Updated |
| 2026-07-20 | CVE-2025-54324 | Samsung Exynos NAS DL NAS Transport packet mishandling causes denial of service in multiple processor models | 7.5 High | Updated |
| 2026-07-17 | CVE-2024-32386 | Kerlink Wirnet iStation SNMP update directory traversal exposes sensitive files to remote attacker | 7.3 High | New |
| 2026-07-16 | CVE-2023-4346 | KNX Protocol Connection Authorization Option 1's Overly Restrictive Lockout Mechanism Lets Attackers Purge Devices and Lock Out Authorized Users with a BCU Key; CISA's July 29th KEV Deadline Has Passed | 7.5 High | KEV |
| 2026-07-15 | CVE-2026-56155 | Microsoft Active Directory Federation Services Insufficient Access Control Allows an Authorized Attacker to Elevate Privileges Locally; CISA's July 28th KEV Deadline Has Passed | 7.8 High | KEV |
| 2026-07-15 | CVE-2026-39042 | MikroTik RouterOS unflatten() Function in libumsg.so Is Reachable by a Remote Attacker and Can Cause Denial of Service | 7.5 High | New |
| 2026-07-15 | CVE-2026-11774 | 389 Directory Server SASL integer overflow bypasses size limit and triggers heap buffer overflow | 7.6 High | New |
| 2026-07-14 | CVE-2026-31446 | Linux kernel ext4 use-after-free in update_super_work races with unmount after sysfs unregistration | 7.8 High | Updated |
| 2026-07-14 | CVE-2026-11917 | Rockwell ThinManager API path traversal allows authenticated attacker to write arbitrary files to restricted system directories | 7.2 High | New |
| 2026-07-14 | CVE-2026-0263 | Unauthenticated IKEv2 Buffer Overflow in Palo Alto Networks PAN-OS Allows Remote Code Execution with Elevated Privileges on PA-Series Firewalls | 9.8 Critical | New |
| 2026-07-14 | CVE-2026-0259 | Authenticated Users on Palo Alto Networks WildFire WF-500 Appliances Can Read Sensitive Files and Delete Arbitrary Files via an External Path Control Flaw | 8.8 High | New |
| 2026-07-14 | CVE-2026-0251 | GlobalProtect App's Untrusted Search Path Flaws Let a Local User Escalate to NT AUTHORITY\SYSTEM on Windows or Root on macOS and Linux | 7.8 High | New |
| 2026-07-14 | CVE-2026-0250 | A Man-in-the-Middle Attacker Can Overflow Palo Alto Networks GlobalProtect's Portal-Gateway Communication and Potentially Execute Code with SYSTEM Privileges | 8.1 High | New |
| 2026-07-14 | CVE-2026-0246 | A Privilege Management Flaw in Palo Alto Networks Prisma Access Agent Lets Non-Administrative Local Users Reach Root on macOS and Linux or SYSTEM on Windows | 7.8 High | New |
| 2026-07-13 | CVE-2026-4769 | WAGO System I/O Field Series Activates an Undocumented Diagnostic Interface Without Authentication During Early Boot, Granting Unauthenticated Network Access for a Brief Window at Each Power Cycle | 9.8 Critical | New |
| 2026-07-09 | CVE-2026-14265 | AWS Advanced JDBC Wrapper RemoteQueryCachePlugin deserializes cached Redis objects enabling code execution on application servers | 7.5 High | Updated |
| 2026-07-08 | CVE-2026-46592 | Apache Camel CXF SOAP Producer Allows Incoming HTTP Requests to Override the Target SOAP Operation via Unfiltered Exchange Headers | 7.5 High | Updated |
| 2026-07-08 | CVE-2026-46279 | Linux Kernel Page Extension Initialization Leaves Codetag Uninitialized for Pages Allocated Before page_ext Is Ready | 7.8 High | Updated |
| 2026-07-08 | CVE-2026-11610 | 389 Directory Server SASL UNBIND oversized packet overflows heap buffer after authenticated bind | 8.8 High | New |
| 2026-07-07 | CVE-2026-55727 | Genetec Security Center Video Stream Authentication Flaw Allows an Unauthenticated Attacker to Access Live Video Streams | 7.5 High | New |
| 2026-07-07 | CVE-2026-45169 | CyberArk Privileged Access Manager Self-Hosted Vault Validation Flaw Can Cause Unexpected Service Termination When Processing Crafted Input | 8.6 High | Updated |
| 2026-07-07 | CVE-2026-0234 | Cortex XSOAR and XSIAM Microsoft Teams Integration Fails to Verify Cryptographic Signatures, Letting Unauthenticated Users Access and Modify Protected Resources | 9.1 Critical | Updated |
| 2026-07-06 | CVE-2026-6901 | B&R APROL Untrusted Search Path Allows a Local Attacker to Load Malicious Libraries and Achieve Code Execution | 7.7 High | New |
| 2026-07-06 | CVE-2026-6900 | B&R APROL Improper Certificate Validation Exposes Encrypted Communications to Network Interception and Modification | 7.4 High | New |
| 2026-07-03 | CVE-2026-50238 | CVE-2026-50238 Rejected by Red Hat Product Security as Not Required; Underlying Issue Reclassified as a Regular Bug to Be Fixed Through Standard Bug-Fixing Process | — | New |
| 2026-07-02 | CVE-2026-53225 | Linux Kernel SCTP ASCONF Lookup Reads Past the Validated Header Boundary, Exposing Uninitialized Memory to Downstream Address Parameter Processing | 9.1 Critical | Updated |
| 2026-06-30 | CVE-2026-14162 | Advantech Hospital Queuing Management System Exposes API Documentation to Unauthenticated Remote Attackers via a Specific URL, Facilitating Unauthorized Access to Internal API Details | 9.8 Critical | New |
| 2026-06-30 | CVE-2026-14161 | Advantech Hospital Queuing Management exposes API documentation to unauthenticated remote attackers | 7.5 High | New |
| 2026-06-30 | CVE-2026-12819 | Delta Electronics DVP12SE PLC Modbus TCP Service Runs Without Authentication or Access Control, Granting Unauthenticated Network Access to Security-Sensitive PLC Functions | 9.3 Critical | New |
| 2026-06-30 | CVE-2026-12818 | Delta Electronics DVP12SE PLC Modbus TCP Service Has No Resource Allocation Limits, Making the PLC Susceptible to Denial-of-Service via Request Flooding | 9.3 Critical | New |
| 2026-06-26 | CVE-2026-46893 | Oracle JD Edwards EnterpriseOne General Ledger E1 Foundation Component Allows Low-Privileged SMB Attackers to Compromise the Application, With Attacks Potentially Spreading to Additional Oracle Products | 9.9 Critical | Updated |
| 2026-06-26 | CVE-2026-46892 | Oracle JD Edwards EnterpriseOne Human Resources Management Component Allows Unauthenticated HTTP Attackers to Read and Modify Data, Affecting Confidentiality and Integrity | 9.1 Critical | Updated |
| 2026-06-26 | CVE-2026-46891 | Low-Privileged Network Attacker Can Modify or Exfiltrate All JD Edwards EnterpriseOne Accounts Payable Data via HTTP | 8.1 High | Updated |
| 2026-06-23 | CVE-2026-45172 | CyberArk Privileged Session Manager for SSH Incomplete Input Validation Allows an Authenticated Low-Privilege User to Execute Arbitrary Commands on the PSMP Host | 8.8 High | Updated |
| 2026-06-23 | CVE-2026-45171 | CyberArk Privileged Session Manager Incomplete Input Validation and Misconfigured Folder Permissions Allow an Authenticated Low-Privilege User to Execute Arbitrary Code | 8.8 High | Updated |
| 2026-06-23 | CVE-2026-45170 | CyberArk Vendor PAM Self-Hosted Connector May Skip TLS Certificate Validation Under Specific Configurations, Exposing Connections to Interception | 8.8 High | Updated |
| 2026-06-22 | CVE-2026-8806 | Packet Flood Prevents Mitsubishi MELSEC FX5-ENET/IP Internal Anomaly Detection from Running, Taking the Communication Function Offline | 8.7 High | New |
| 2026-06-22 | CVE-2026-8805 | Rapidly Established TCP Connections Trigger an Integer Overflow in Mitsubishi MELSEC FX5-EIP Connection Management, Causing Denial of Service | 8.7 High | New |
| 2026-06-22 | CVE-2026-45178 | CyberArk Secrets Manager Internal Cluster Endpoint Access Control Flaw Allows an Authenticated Node-Level Attacker to Retrieve Unauthorized Secrets or Cause Denial of Service | 8.1 High | Updated |
| 2026-06-22 | CVE-2026-45177 | Idira Secrets Manager SaaS Edge Before 1.8 Improper Access Control in Internal Authentication Components Lets Unauthenticated Remote Attackers Access Protected Resources Under Specific Conditions | 9.1 Critical | Updated |
| 2026-06-22 | CVE-2026-45176 | CyberArk Endpoint Privilege Manager Agent Improper Access Control Lets a Local Low-Privilege Attacker Execute Unauthorized Actions with Elevated Privileges | 7.8 High | Updated |
| 2026-06-22 | CVE-2026-45175 | CyberArk Endpoint Privilege Manager Agent Internal Validation Flaw Allows a Local Attacker to Bypass Agent Self-Defense Mechanisms | 7.8 High | Updated |
| 2026-06-22 | CVE-2026-45174 | CyberArk Endpoint Privilege Manager Linux Agent Initialization Flaw Allows a Local Attacker to Compromise the Agent Daemon | 7.8 High | Updated |
| 2026-06-22 | CVE-2026-39962 | MISP Before 2.5.36 ApacheAuthenticate Module Passes Unsanitized Username Values Into an LDAP Query, Enabling LDAP Injection by Unauthenticated Users When ApacheAuthenticate Is Enabled | 9.6 Critical | Updated |
| 2026-06-22 | CVE-2026-20266 | Splunk AI Toolkit Below 5.7.4 Constructs OS Command Strings from Dynamic btool Configuration Parameters Without Sanitization, Letting Admin-Role Users Execute Arbitrary OS Commands on the Host | 9.1 Critical | Updated |
| 2026-06-18 | CVE-2026-53855 | OpenClaw Execution Allowlist Can Be Weakened by Authenticated Operators Using Shell Positional Parameters to Smuggle Inline Eval Content Past Allowlist Checks | 8.1 High | Updated |
| 2026-06-18 | CVE-2026-46913 | Oracle JD Edwards EnterpriseOne Tools Installation Security Component Allows Unauthenticated Local Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products | 9.3 Critical | Updated |
| 2026-06-18 | CVE-2026-46911 | Oracle JD Edwards EnterpriseOne Project Costing Job Costing Component Allows Low-Privileged JDENET Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products | 9.6 Critical | Updated |
| 2026-06-18 | CVE-2026-46909 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated HTTP Attackers Full Takeover of the EnterpriseOne Tools Instance, Scoring CVSS 9.8 | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46908 | Oracle JD Edwards EnterpriseOne Accounts Payable Component Allows Low-Privileged HTTP Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products | 9.9 Critical | Updated |
| 2026-06-18 | CVE-2026-46907 | Oracle JD Edwards EnterpriseOne Order Promising Integration Component Allows Low-Privileged HTTP Attackers to Compromise the Application, With Attacks Potentially Spreading to Additional Oracle Products | 9.9 Critical | Updated |
| 2026-06-18 | CVE-2026-46906 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Low-Privileged HTTP Attackers to Compromise the Application, With Attacks Potentially Impacting Additional Oracle Products | 9.6 Critical | Updated |
| 2026-06-18 | CVE-2026-46905 | Oracle JD Edwards EnterpriseOne Tools Web Runtime Security Component Allows Unauthenticated HTTP Attackers Full Takeover of the EnterpriseOne Tools Instance, Scoring CVSS 9.8 | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46904 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the EnterpriseOne Tools Instance, Scoring CVSS 9.8 | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46903 | Low-Privileged Network Attacker Can Achieve Full Takeover of JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2 via HTTP Business Logic Security Flaw | 8.8 High | Updated |
| 2026-06-18 | CVE-2026-46883 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance in Versions 9.2.0.0 Through 9.2.26.2, One of Six Related CVEs | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46882 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance in Versions 9.2.0.0 Through 9.2.26.2, One of Six Related CVEs | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46881 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Third in a Set of Six JDENET-Reachable Takeover Vulnerabilities | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46880 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Fourth in a Set of Six JDENET-Reachable Takeover Vulnerabilities | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46879 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Fifth in a Set of Six JDENET-Reachable Takeover Vulnerabilities | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-46878 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated JDENET Attackers Full Takeover of the Tools Instance, Sixth in a Set of Six JDENET-Reachable Takeover Vulnerabilities | 9.8 Critical | Updated |
| 2026-06-18 | CVE-2026-0063 | Android CarrierConfigLoader logic error lets local app disable carrier restrictions without additional privileges | 7.8 High | New |
| 2026-06-18 | CVE-2025-48617 | Android CarrierConfigLoader UID check bypass enables local privilege escalation without user interaction | 7.8 High | New |
| 2026-06-17 | CVE-2026-9266 | Moxa's TPM2 Parameter Encryption Countermeasure for CVE-2026-0714 Provides No Effective Protection Due to an Omission in the Authorization Session Configuration | 7.0 High | New |
| 2026-06-17 | CVE-2026-8398 | Daemon Tools Lite Contains Embedded Malicious Code; CISA Added It to KEV with a May 30th Deadline That Has Since Passed for Covered Entities | 9.8 Critical | KEV |
| 2026-06-17 | CVE-2026-8111 | Ivanti Endpoint Manager Web Console SQL Injection Allows an Authenticated Remote Attacker to Execute Code on the Server | 8.8 High | Updated |
| 2026-06-17 | CVE-2026-8051 | Ivanti Virtual Traffic Manager OS Command Injection Requires Authenticated Admin Access to Reach Remote Code Execution | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-8043 | Ivanti Xtraction Before 2026.2 Lets Authenticated Remote Attackers Supply Arbitrary File Paths to Read Sensitive Files or Write HTML Files into a Web-Accessible Directory | 9.6 Critical | Updated |
| 2026-06-17 | CVE-2026-7821 | Ivanti EPMM Certificate Validation Flaw Allows an Unauthenticated Remote Attacker to Enroll Restricted Devices and Expose Appliance Information | 7.4 High | Updated |
| 2026-06-17 | CVE-2026-7668 | MikroTik RouterOS SCEP Endpoint Reads Out of Bounds When Processing a Crafted transactionID or messageType; Vendor Recommends Upgrading | 7.3 High | New |
| 2026-06-17 | CVE-2026-7473 | Arista Extensible Operating System Validation Bypass Added to CISA's Known Exploited Vulnerabilities List; Federal Remediation Window for Covered Entities Closed June 23rd | 5.8 Medium | KEV |
| 2026-06-17 | CVE-2026-7432 | Race Condition in Ivanti Secure Access Client Lets a Locally Authenticated User Escalate to SYSTEM | 7.8 High | Updated |
| 2026-06-17 | CVE-2026-7287 | Zyxel NWA1100-N Is Unsupported and Contains a Buffer Overflow in Its Web Functions That Can Be Triggered Remotely to Cause Denial of Service | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-7256 | Zyxel WRE6505 v2 Is Unsupported and Contains a CGI Command Injection Exploitable Without Credentials from the Local Network | 8.8 High | Updated |
| 2026-06-17 | CVE-2026-5788 | Unauthenticated Remote Attacker Can Invoke Arbitrary Methods on Ivanti EPMM via Improper Access Control | 7.0 High | Updated |
| 2026-06-17 | CVE-2026-5787 | Ivanti EPMM Certificate Validation Flaw Lets an Unauthenticated Attacker Impersonate Registered Sentry Hosts and Obtain CA-Signed Client Certificates | 8.9 High | Updated |
| 2026-06-17 | CVE-2026-5786 | Authenticated Remote Attacker Can Gain Administrative Access to Ivanti EPMM via Improper Access Control | 8.8 High | Updated |
| 2026-06-17 | CVE-2026-5667 | Mitsubishi Electric Air Conditioning and Related Products Contain Hardcoded Credentials Across Multiple Device Families | 7.2 High | New |
| 2026-06-17 | CVE-2026-53473 | Red Hat Migration Planner UI Reflects Unsanitized JavaScript from Malicious Discovery Agent Credential URLs, Compromising SSO Sessions on User Click | 7.3 High | Updated |
| 2026-06-17 | CVE-2026-48027 | Nx Console Developer Tooling Published Packages Contain Embedded Malicious Code; CISA's June 10th KEV Mandate for Covered Entities Has Passed | 9.8 Critical | KEV |
| 2026-06-17 | CVE-2026-46912 | Oracle JD Edwards EnterpriseOne Tools Web Runtime Security Component Allows Unauthenticated HTTP Attackers to Compromise the Application, With High Impact on Confidentiality, Integrity, and Availability | 9.3 Critical | Updated |
| 2026-06-17 | CVE-2026-46910 | Oracle JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security Allows Unauthenticated HTTP Attackers to Read and Write Data in a Way That Affects Confidentiality and Integrity | 9.1 Critical | Updated |
| 2026-06-17 | CVE-2026-45321 | TanStack JavaScript Library Suite Added to CISA's Known Exploited Vulnerabilities Catalog; Federal Remediation Deadline for Covered Entities Was June 10th | 9.6 Critical | KEV |
| 2026-06-17 | CVE-2026-43296 | Linux Kernel octeontx2-af NIC SQ Manager Sticky Mode Causes Stalls and Potential PSE Deadlock When Multiple Queues Share an SMQ | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-41952 | Acronis DeviceLock DLP and Cyber Protect Cloud Agent for Windows Fail to Validate Input in a Privileged Component, Allowing a Local User to Escalate Privileges | 7.8 High | New |
| 2026-06-17 | CVE-2026-41512 | ai-scanner 1.0.0 Through 1.4.0 Remote Code Execution via JavaScript Injection in BrowserAutomation PlaywrightService, Reachable Without Authentication | 9.9 Critical | Updated |
| 2026-06-17 | CVE-2026-41380 | OpenClaw Execution Approval Mechanism Trusts Carrier Wrapper Executables Rather Than Invoked Targets, Allowing Broader Allowlist Entries Than Intended | 7.3 High | Updated |
| 2026-06-17 | CVE-2026-41323 | Kyverno ClusterPolicy apiCall Attaches the Admission Controller Service Account Token to Outbound HTTP Requests Without Validating the Destination URL | 8.1 High | Updated |
| 2026-06-17 | CVE-2026-41220 | A Separate Input Validation Gap in Acronis DeviceLock DLP and Cyber Protect Cloud Agent for Windows Lets a Local User Gain Elevated Privileges | 7.8 High | New |
| 2026-06-17 | CVE-2026-4116 | SonicWall SMA1000 Mishandles Unicode Encoding in TOTP Validation, Allowing an Authenticated SSLVPN User to Bypass Two-Factor Authentication | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-41135 | free5GC PCF Registers a New CORS Middleware on Every Incoming OAM Request, Causing Progressive Memory Exhaustion Reachable by Unauthenticated Attackers | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-4113 | SonicWall SMA1000 Distinguishable Authentication Error Responses Allow a Remote Attacker to Enumerate SSL VPN User Accounts | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-4112 | SonicWall SMA1000 SQL Injection in the SSLVPN Component Allows a Read-Only Administrator to Escalate to Primary Administrator | 7.2 High | Updated |
| 2026-06-17 | CVE-2026-41085 | Thermo Fisher Scientific Torrent Suite Dx Allows an Authenticated Limited-Access User to Gain Unauthorized Administrator Privileges via Specific System Interfaces | 8.8 High | New |
| 2026-06-17 | CVE-2026-40881 | Zebra Zcash Node Allocates a Full Over-Limit addr/addrv2 Vector Before Enforcing the 1,000-Message Cap, Allowing Memory Exhaustion via a Small Number of Large Messages | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-40613 | Coturn Misaligned Pointer Cast in STUN Attribute Parsing Causes a SIGBUS Crash on ARM64, Triggerable by a Single Unauthenticated STUN Message | 7.5 High | Updated |
| 2026-06-17 | CVE-2026-40586 | blueprintUE Login Endpoint Applies No Rate Limiting or Account Lockout, Allowing Unlimited Credential Guessing | 7.5 High | New |
| 2026-06-17 | CVE-2026-40193 | maddy Mail Server LDAP Auth Module Interpolates Usernames into LDAP Filters Without Escaping, Allowing SMTP or IMAP Clients to Inject Arbitrary LDAP Expressions | 8.2 High | Updated |
| 2026-06-17 | CVE-2026-40046 | Apache ActiveMQ 6.x Did Not Receive the MQTT Remaining-Length Integer Overflow Fix Applied to 5.19.x, Leaving Versions 6.0.0 Through 6.2.3 Vulnerable | 7.5 High | New |
| 2026-06-17 | CVE-2026-39974 | n8n-MCP Authenticated SSRF Allows a Valid Token Holder to Cause the Server to Fetch Arbitrary URLs and Receive Their Contents, Including Cloud Instance Metadata | 8.5 High | Updated |
| 2026-06-17 | CVE-2026-39973 | Apktool 3.0.0 and 3.0.1 Removed the Path Traversal Guard from Resource File Decoding, Allowing a Crafted APK to Write Arbitrary Files to the Filesystem | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-3868 | Moxa Secure Router HTTPS management interface buffer overflow causes web service denial of service | 8.7 High | New |
| 2026-06-17 | CVE-2026-3643 | WordPress Accessibly plugin unauthenticated REST API endpoint allows stored cross-site scripting | 7.2 High | New |
| 2026-06-17 | CVE-2026-3614 | WordPress AcyMailing unauthenticated AJAX handler lets subscriber-level users access admin configuration controls | 8.8 High | New |
| 2026-06-17 | CVE-2026-35573 | ChurchCRM Before 6.5.3 Backup Restore Functionality Allows Authenticated Administrators to Upload Files to Arbitrary Paths via Path Traversal, Enabling Remote Code Execution | 9.1 Critical | Updated |
| 2026-06-17 | CVE-2026-35227 | CODESYS Modbus TCP Server race condition in connection handling exhausts TCP connections and blocks legitimate clients | 8.2 High | New |
| 2026-06-17 | CVE-2026-35225 | CODESYS EtherNet/IP adapter TCP connection exhaustion blocks legitimate clients without authentication | 8.7 High | New |
| 2026-06-17 | CVE-2026-33702 | Chamilo LMS learning path progress endpoint accepts attacker-supplied user ID and overwrites other users' scores | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-33092 | Acronis True Image macOS improper environment variable handling allows local privilege escalation before build 42902 | 7.8 High | New |
| 2026-06-17 | CVE-2026-31693 | Linux kernel CIFS replay path missing variable reinitializations causes undefined behavior on request retry | 7.8 High | Updated |
| 2026-06-17 | CVE-2026-31568 | Linux kernel s390/mm missing secure storage access fixups for donated pages causes kernel context exceptions | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-31426 | Linux kernel ACPI EC address space handler persists after probe failure leaves dangling pointer | 7.0 High | Updated |
| 2026-06-17 | CVE-2026-25208 | Samsung Escargot JavaScript engine integer overflow allows buffer overflow at affected commit | 8.1 High | Updated |
| 2026-06-17 | CVE-2026-25207 | Samsung Escargot JavaScript engine out-of-bounds write allows buffer overflow at affected commit | 7.4 High | Updated |
| 2026-06-17 | CVE-2026-25205 | Samsung Escargot JavaScript engine heap-based buffer overflow allows out-of-bounds write at affected commit | 7.4 High | Updated |
| 2026-06-17 | CVE-2026-25203 | Samsung MagicINFO 9 Server incorrect default permissions allow local privilege escalation before version 21.1091.1 | 7.8 High | New |
| 2026-06-17 | CVE-2026-24189 | NVIDIA CUDA-Q unauthenticated out-of-bounds read via malicious request causes denial of service and information disclosure | 8.2 High | New |
| 2026-06-17 | CVE-2026-24177 | NVIDIA KAI Scheduler unauthenticated API endpoint access leads to information disclosure | 7.7 High | New |
| 2026-06-17 | CVE-2026-23406 | Linux kernel AppArmor match_char macro evaluates pointer multiple times and skips input characters during DFA traversal | 7.8 High | Updated |
| 2026-06-17 | CVE-2026-20879 | Intel Data Center Graphics Driver for VMware ESXi Ring 1 out-of-bounds write allows denial of service before version 2.0.2 | 8.3 High | New |
| 2026-06-17 | CVE-2026-20794 | Intel Data Center Graphics Driver for VMware ESXi Before 2.0.2 Ring 1 Device Driver Buffer Overflow Allows a Privileged System Software Adversary to Escalate Privileges and Execute Code Locally | 9.3 Critical | New |
| 2026-06-17 | CVE-2026-20751 | Intel Data Center Graphics Driver for VMware ESXi Ring 1 out-of-bounds read allows denial of service before version 2.0.2 | 8.3 High | New |
| 2026-06-17 | CVE-2026-20258 | Splunk low-privilege user can store malicious script in dashboard HTML panel for execution in other users' browsers | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-20252 | Splunk Dashboard Studio PDF export SSRF bypass via prefix match sends requests to internal destinations | 7.6 High | Updated |
| 2026-06-17 | CVE-2026-20251 | Splunk Secure Gateway KV store deserialization allows low-privilege user to achieve remote code execution | 8.8 High | Updated |
| 2026-06-17 | CVE-2026-20205 | Splunk MCP Server stores session and authorization tokens in cleartext within the _internal index | 7.2 High | New |
| 2026-06-17 | CVE-2026-20204 | Splunk low-privilege user can achieve remote code execution via malicious file upload to temporary directory | 7.1 High | Updated |
| 2026-06-17 | CVE-2026-20184 | Cisco Webex SSO Integration with Control Hub Performed Improper Certificate Validation, Allowing Unauthenticated Attackers to Impersonate Any User Within the Service Prior to Patching | 9.8 Critical | New |
| 2026-06-17 | CVE-2026-20093 | Cisco Integrated Management Controller Change Password Handler Incorrectly Processes Password Change Requests, Letting Unauthenticated Remote Attackers Bypass Authentication and Gain Admin Access | 9.8 Critical | New |
| 2026-06-17 | CVE-2026-1952 | Delta Electronics AS320T Denial of Service via Undocumented Subfunction Call, Exploitable Remotely Without Authentication | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1951 | Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing Directory Name Length Check, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1950 | Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing File Name Length Check, Enabling Unauthenticated Remote Code Execution | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1949 | Delta Electronics AS320T GET/PUT Request Handler Incorrectly Calculates Stack Buffer Size, Enabling Unauthenticated Remote Code Execution via the Web Service | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2026-1078 | Pega Browser Extension arbitrary file write in Chrome and Edge automations via malicious website visit | 7.2 High | New |
| 2026-06-17 | CVE-2025-62818 | Samsung Exynos Modem SMS Processing Out-of-Bounds Write Due to TP-UDHI Header Mismatch, Affecting Processors from Exynos 980 Through Exynos 2500 and Multiple Modem Generations | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2025-62627 | VMware ESXi ionic cloud driver untrusted pointer dereference exposes kernel memory and co-located guest VM memory | 7.2 High | New |
| 2026-06-17 | CVE-2025-62624 | VMware ESXi ionic cloud driver heap overflow enables privilege escalation and arbitrary code execution | 8.8 High | New |
| 2026-06-17 | CVE-2025-62623 | VMware ESXi ionic cloud driver heap overflow provides a second path to privilege escalation and code execution | 8.8 High | New |
| 2026-06-17 | CVE-2025-59440 | Samsung Exynos USIM improper SIM proactive command handling causes denial of service | 7.5 High | Updated |
| 2026-06-17 | CVE-2025-57835 | Samsung Exynos RRC memory initialization flaw crashes modem via malformed RRCReconfiguration message | 7.5 High | Updated |
| 2026-06-17 | CVE-2025-52909 | Samsung Exynos Wi-Fi Driver NL80211 Vendor Command Handler Overflows a Buffer via a Crafted Packet, Affecting Exynos 980 Through W1000 Mobile and Wearable Processors | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2025-52908 | Samsung Exynos Wi-Fi Driver NL80211 Vendor Command Handler Contains a Second Buffer Overflow Path via a Crafted Packet, Affecting Exynos 980 Through W1000 Mobile and Wearable Processors | 9.8 Critical | Updated |
| 2026-06-17 | CVE-2025-32975 | Quest KACE Systems Management Appliance's Improper Authentication Allows Attackers to Impersonate Legitimate Users Without Valid Credentials; CISA's May 4th KEV Deadline Has Passed | 10.0 Critical | KEV |
| 2026-06-17 | CVE-2025-12659 | Siemens Simcenter Femap memory corruption during crafted IPT file parsing allows code execution | 7.8 High | New |
| 2026-06-17 | CVE-2024-33618 | Bosch VMS Central Server uncontrolled disk consumption via network interface exhausts storage | 7.5 High | New |
| 2026-06-17 | CVE-2024-27686 | MikroTik RouterOS SMB service crash via crafted packet on TCP port 445 across versions 6.40.5 through 6.49.10 | 7.5 High | New |
| 2026-06-17 | CVE-2024-1490 | WAGO PLC authenticated admin can execute arbitrary shell commands via OpenVPN web management interface | 7.2 High | New |
| 2026-06-17 | CVE-2023-3634 | Festo MSE6 undocumented test mode reachable by low-privileged authenticated user enables full system compromise | 8.8 High | New |