Critical Infrastructure Vulnerability Intelligence

Advisories for Industrial Defenders

Compiled, structured vulnerability reports for operational technology and industrial control system security teams.

114
KEV Listed
117
Exploited
4
EPSS-Imminent
689
Total Advisories
Filter by Sector
ChemicalCommercialCommunicationsManufacturingDamsDefense IndustrialEmergency SvcsEnergyFinancial SvcsFood & AgGovernmentHealthcareInfo TechnologyNuclearTransportationWater
Filter by Status
FromToShow
UpdatedAdvisory IDTitleCVSSStatus
2026-10-03CVE-2026-86060MikroTik RouterOS's Argument Injection in a Command-Processing Component Allows Unauthenticated Attackers to Execute Arbitrary Commands on the Router; CISA's September 13th KEV Deadline Has Passed9.8 CriticalKEV
2026-10-03CVE-2026-85102Check Point Firewall Certificate Validation Bypass Across Site-to-Site and Remote Access VPN Carries a Lapsed September 25th CISA KEV Requirement for Covered Entities9.8 CriticalKEV
2026-10-03CVE-2026-82078PaperCut NG/MF's Unsafe Reflection Allows Remote Attackers to Manipulate Class Loading and Execute Arbitrary Code on the Print Management Server; CISA's September 14th KEV Deadline Has Passed9.1 CriticalKEV
2026-10-03CVE-2026-67276CVE-2026-672768.1 HighEPSS-Imminent
2026-10-03CVE-2026-20181CVE-2026-201819.1 CriticalEPSS-Imminent
2026-10-03CVE-2026-98154CVE-2026-981547.0 HighUpdated
2026-10-03CVE-2026-98130CVE-2026-981308.1 HighUpdated
2026-10-03CVE-2026-98122CVE-2026-981227.8 HighUpdated
2026-10-03CVE-2026-98116CVE-2026-981167.8 HighUpdated
2026-10-03CVE-2026-98108CVE-2026-981087.5 HighUpdated
2026-10-03CVE-2026-98096CVE-2026-980967.4 HighUpdated
2026-10-03CVE-2026-98083CVE-2026-980837.0 HighUpdated
2026-10-03CVE-2026-98070CVE-2026-980708.1 HighUpdated
2026-10-03CVE-2026-98069CVE-2026-980698.1 HighUpdated
2026-10-03CVE-2026-98052CVE-2026-980527.8 HighUpdated
2026-10-03CVE-2026-98030CVE-2026-980307.0 HighUpdated
2026-10-03CVE-2026-98027CVE-2026-980277.0 HighUpdated
2026-10-03CVE-2026-98023CVE-2026-980237.8 HighUpdated
2026-10-03CVE-2026-98017CVE-2026-980177.8 HighUpdated
2026-10-03CVE-2026-97991CVE-2026-979917.8 HighUpdated
2026-10-03CVE-2026-97990CVE-2026-979907.5 HighUpdated
2026-10-03CVE-2026-97957CVE-2026-979578.8 HighUpdated
2026-10-03CVE-2026-97509CVE-2026-975098.8 HighUpdated
2026-10-03CVE-2026-97508CVE-2026-975087.5 HighUpdated
2026-10-03CVE-2026-97497CVE-2026-974977.8 HighUpdated
2026-10-03CVE-2026-97496CVE-2026-974967.1 HighUpdated
2026-10-03CVE-2026-97455CVE-2026-974558.4 HighUpdated
2026-10-03CVE-2026-97454CVE-2026-974547.7 HighUpdated
2026-10-03CVE-2026-97452CVE-2026-974528.4 HighUpdated
2026-10-03CVE-2026-97451CVE-2026-974518.4 HighUpdated
2026-10-03CVE-2026-97450CVE-2026-974508.4 HighUpdated
2026-10-03CVE-2026-97448CVE-2026-974487.7 HighUpdated
2026-10-03CVE-2026-93196CVE-2026-931968.4 HighUpdated
2026-10-03CVE-2026-90030CVE-2026-900307.8 HighUpdated
2026-10-03CVE-2026-90016CVE-2026-900167.1 HighUpdated
2026-10-03CVE-2026-90013CVE-2026-900137.8 HighUpdated
2026-10-03CVE-2026-90002CVE-2026-900027.8 HighUpdated
2026-10-03CVE-2026-89972CVE-2026-899729.8 CriticalUpdated
2026-10-03CVE-2026-89971CVE-2026-899717.5 HighUpdated
2026-10-03CVE-2026-89840CVE-2026-898407.1 HighUpdated
2026-10-03CVE-2026-89838CVE-2026-898387.1 HighUpdated
2026-10-03CVE-2026-89832CVE-2026-898327.8 HighUpdated
2026-10-03CVE-2026-89806CVE-2026-898068.4 HighUpdated
2026-10-03CVE-2026-89795CVE-2026-897958.4 HighUpdated
2026-10-03CVE-2026-89792CVE-2026-897927.1 HighUpdated
2026-10-03CVE-2026-89560CVE-2026-895608.4 HighUpdated
2026-10-03CVE-2026-89520CVE-2026-895207.8 HighUpdated
2026-10-03CVE-2026-89503CVE-2026-895037.8 HighUpdated
2026-10-03CVE-2026-89500CVE-2026-895007.8 HighUpdated
2026-10-03CVE-2026-89452CVE-2026-894528.4 HighUpdated
2026-10-03CVE-2026-89445CVE-2026-894458.8 HighUpdated
2026-10-03CVE-2026-89441CVE-2026-894417.8 HighUpdated
2026-10-03CVE-2026-81016CVE-2026-810167.7 HighUpdated
2026-10-03CVE-2026-81015CVE-2026-810157.8 HighUpdated
2026-10-03CVE-2026-80980CVE-2026-809809.8 CriticalUpdated
2026-10-03CVE-2026-80937CVE-2026-809378.8 HighUpdated
2026-10-03CVE-2026-80935CVE-2026-809358.8 HighUpdated
2026-10-03CVE-2026-80926CVE-2026-809269.8 CriticalUpdated
2026-10-03CVE-2026-80726CVE-2026-807269.3 CriticalUpdated
2026-10-03CVE-2026-80521CVE-2026-805217.8 HighUpdated
2026-10-03CVE-2026-76504CVE-2026-76504: Cisco Catalyst SD-WAN Manager9.8 CriticalKEV
2026-10-03CVE-2026-74743CVE-2026-747439.8 CriticalUpdated
2026-10-03CVE-2026-74521CVE-2026-745219.1 CriticalUpdated
2026-10-03CVE-2026-74496CVE-2026-744967.8 HighUpdated
2026-10-03CVE-2026-74347CVE-2026-743477.8 HighUpdated
2026-10-03CVE-2026-74294CVE-2026-742947.3 HighUpdated
2026-10-03CVE-2026-74289CVE-2026-742897.8 HighUpdated
2026-10-03CVE-2026-74258CVE-2026-742587.8 HighUpdated
2026-10-03CVE-2026-72496CVE-2026-724969.2 CriticalUpdated
2026-10-03CVE-2026-72485CVE-2026-724857.8 HighUpdated
2026-10-03CVE-2026-72334CVE-2026-723348.8 HighUpdated
2026-10-03CVE-2026-68391CVE-2026-683917.8 HighUpdated
2026-10-03CVE-2026-68287CVE-2026-682877.5 HighUpdated
2026-10-03CVE-2026-68236CVE-2026-682367.8 HighUpdated
2026-10-03CVE-2026-68161CVE-2026-681619.8 CriticalUpdated
2026-10-03CVE-2026-68155CVE-2026-681557.5 HighUpdated
2026-10-03CVE-2026-68097CVE-2026-680978.8 HighUpdated
2026-10-03CVE-2026-53359CVE-2026-533598.8 HighUpdated
2026-10-03CVE-2026-53005Linux Kernel AF_UNIX SOCKMAP Redirect Hides Inflight File Descriptors from the Garbage Collector, Leaking Inflight Sockets Indefinitely7.8 HighUpdated
2026-10-03CVE-2026-52988CVE-2026-529887.1 HighUpdated
2026-10-03CVE-2026-46242CVE-2026-462427.8 HighUpdated
2026-10-03CVE-2026-46113CVE-2026-461138.8 HighUpdated
2026-10-03CVE-2026-20273Cisco IOS XE's Improper Input Validation Allows a Remote Attacker to Trigger a Device Crash or Disruption via a Specially Crafted Input8.6 HighUpdated
2026-10-03CVE-2026-20272Cisco IOS XE's Injection Flaw Allows Remote Attackers to Execute Arbitrary Commands via a Specially Crafted Input Reaching a Downstream Component9.8 CriticalUpdated
2026-10-03CVE-2026-20271Cisco IOS XE's Insufficient Control Flow Management Allows a Remote Attacker to Disrupt Device Operation via a Crafted Packet8.6 HighUpdated
2026-10-03CVE-2026-20270Cisco IOS XE's Incorrect Calculation Vulnerability Allows a Remote Attacker to Cause an Unrecoverable Device Condition via a Specially Crafted Input8.6 HighUpdated
2026-10-03CVE-2026-20269Cisco IOS XE's Improper Resource Lifetime Management Allows Remote Attackers to Exhaust Device Resources and Cause a Denial of Service8.6 HighUpdated
2026-10-03CVE-2026-20268Cisco IOS XE's Improper Restriction of Memory Buffer Operations Allows Remote Attackers to Potentially Execute Code or Crash the Device via a Malformed Packet8.6 HighUpdated
2026-10-03CVE-2026-20267Cisco IOS XE's Improper Access Control Allows Network-Based Attackers to Access Protected Functions or Data Without Proper Authorization9.0 CriticalUpdated
2026-10-02CVE-2026-98163CVE-2026-981637.0 HighUpdated
2026-10-02CVE-2026-98115CVE-2026-981158.8 HighUpdated
2026-10-02CVE-2026-97415CVE-2026-974157.8 HighUpdated
2026-10-02CVE-2026-86326CVE-2026-863268.6 HighUpdated
2026-10-02CVE-2026-86325CVE-2026-863259.4 CriticalUpdated
2026-10-02CVE-2026-84411CVE-2026-844119.8 CriticalUpdated
2026-10-02CVE-2026-75937CVE-2026-759379.4 CriticalUpdated
2026-10-02CVE-2026-71452CVE-2026-714527.2 HighUpdated
2026-10-02CVE-2026-71449CVE-2026-714499.3 CriticalUpdated
2026-10-02CVE-2026-64893CVE-2026-648937.3 HighUpdated
2026-10-02CVE-2026-64008CVE-2026-640087.8 HighUpdated
2026-10-02CVE-2026-64001CVE-2026-640017.8 HighUpdated
2026-10-02CVE-2026-63996CVE-2026-639967.8 HighUpdated
2026-10-02CVE-2026-63993CVE-2026-639939.8 CriticalUpdated
2026-10-02CVE-2026-63975CVE-2026-639758.8 HighUpdated
2026-10-02CVE-2026-63972CVE-2026-639727.5 HighUpdated
2026-10-02CVE-2026-63971CVE-2026-639717.8 HighUpdated
2026-10-02CVE-2026-63970CVE-2026-639707.8 HighUpdated
2026-10-02CVE-2026-58016CVE-2026-580167.5 HighUpdated
2026-10-02CVE-2026-58014CVE-2026-580147.3 HighUpdated
2026-10-02CVE-2026-55396CVE-2026-553968.5 HighUpdated
2026-10-02CVE-2026-55395CVE-2026-553959.4 CriticalUpdated
2026-10-02CVE-2026-55393CVE-2026-5539310.0 CriticalUpdated
2026-10-02CVE-2026-48864CVE-2026-488647.8 HighUpdated
2026-10-02CVE-2026-42010CVE-2026-420107.1 HighUpdated
2026-10-02CVE-2026-42009CVE-2026-420097.5 HighUpdated
2026-10-02CVE-2026-34494CVE-2026-344947.2 HighUpdated
2026-10-02CVE-2026-34493CVE-2026-344937.2 HighUpdated
2026-10-02CVE-2026-33845CVE-2026-338457.5 HighUpdated
2026-10-02CVE-2026-17523CVE-2026-175237.8 HighUpdated
2026-10-02CVE-2026-14984CVE-2026-149849.4 CriticalUpdated
2026-10-02CVE-2026-14983CVE-2026-149837.1 HighUpdated
2026-10-02CVE-2026-104286CVE-2026-104286: Fortinet FortiMail Path9.8 CriticalKEV
2026-10-02CVE-2026-102490CVE-2026-102490: Zammad GmbH Zammad Improper9.8 CriticalKEV
2026-10-02CVE-2026-102489CVE-2026-102489: Zammad GmbH Zammad Session9.8 CriticalKEV
2026-10-02CVE-2026-100075CVE-2026-1000759.8 CriticalUpdated
2026-10-01CVE-2026-8037Progress LoadMaster's Command Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary OS Commands on the Load Balancer Appliance; CISA's August 10th KEV Deadline Has Passed9.6 CriticalKEV
2026-10-01CVE-2026-69594CVE-2026-695947.8 HighUpdated
2026-10-01CVE-2026-69576CVE-2026-695767.8 HighUpdated
2026-10-01CVE-2026-69549CVE-2026-695497.0 HighUpdated
2026-10-01CVE-2026-69546CVE-2026-695468.1 HighUpdated
2026-10-01CVE-2026-69541CVE-2026-695417.8 HighUpdated
2026-10-01CVE-2026-69524CVE-2026-695248.1 HighUpdated
2026-10-01CVE-2026-48710Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections6.5 MediumKEV
2026-10-01CVE-2026-42965CVE-2026-429657.7 HighUpdated
2026-10-01CVE-2026-3012CVE-2026-30128.0 HighUpdated
2026-10-01CVE-2026-1784CVE-2026-17848.8 HighUpdated
2026-10-01CVE-2025-41753CVE-2025-417539.8 CriticalUpdated
2026-09-30CVE-2026-41940WebPros cPanel and WHM's Login Flow Authentication Bypass Gives Unauthenticated Attackers Unauthorized Access to the Control Panel; CISA's May 3rd KEV Deadline Has Passed9.8 CriticalKEV
2026-09-28CVE-2026-20263Cisco IOS XE BEEP SOAP request parsing flaw causes unexpected device reload8.6 HighUpdated
2026-09-26CVE-2026-80152Lantronix SLC8000, SLC9000, EMG, and SLB Series Set Script Schedule Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root9.1 CriticalUpdated
2026-09-26CVE-2026-80151Lantronix SLC8000, SLC9000, EMG, and SLB Series Set NFS Download Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root9.1 CriticalUpdated
2026-09-26CVE-2026-80150Lantronix Serial Console Servers Allow Unauthenticated Attackers to Redirect WebTelnet Connections to Arbitrary Hosts via a Tampered rooturl Parameter7.5 HighUpdated
2026-09-26CVE-2026-80149Lantronix Serial Console Servers Allow Unauthenticated Attackers to Redirect WebSSH Connections to Arbitrary Hosts via a Tampered rooturl Parameter8.6 HighUpdated
2026-09-26CVE-2026-80148Overlong Username in Lantronix Serial Console Server WebSSH Truncates the Device IP Suffix in snprintf, Redirecting SSH Connections to Attacker-Controlled Hosts8.6 HighUpdated
2026-09-26CVE-2026-80146Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root9.9 CriticalUpdated
2026-09-26CVE-2026-67279MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 286.5 MediumKEV
2026-09-25CVE-2026-93616Path Traversal Across Check Point Management and Log Server Infrastructure Missed the September 25th CISA KEV Window; Covered Organizations Are Now Out of Compliance9.8 CriticalKEV
2026-09-25CVE-2026-85046Google Chromium V8's Type Confusion Allows Remote Attackers to Execute Arbitrary Code or Escape the Browser Sandbox via a Crafted Web Page8.8 HighKEV
2026-09-25CVE-2026-81578PaperCut NG/MF's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Perform Administrative Actions Without Logging In; CISA's September 14th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-25CVE-2026-76461Cisco Secure Email Gateway's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Compromise the Email Security Platform9.8 CriticalKEV
2026-09-25CVE-2026-76460Cisco Identity Services Engine's Incorrect Use of Privileged APIs Allows Unauthenticated Remote Attackers to Gain Full Administrative Control; CISA's September 19th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-25CVE-2026-75650Adobe Commerce and Magento's Template Engine Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Server-Side Code on the E-Commerce Platform10.0 CriticalKEV
2026-09-25CVE-2026-97941CVE-2026-979417.8 HighUpdated
2026-09-25CVE-2026-97940CVE-2026-979407.8 HighUpdated
2026-09-25CVE-2026-97937CVE-2026-979377.8 HighUpdated
2026-09-25CVE-2026-97931CVE-2026-979317.0 HighUpdated
2026-09-25CVE-2026-97926CVE-2026-979267.0 HighUpdated
2026-09-25CVE-2026-97911CVE-2026-979117.8 HighUpdated
2026-09-25CVE-2026-97910CVE-2026-979107.8 HighUpdated
2026-09-25CVE-2026-97903CVE-2026-979037.8 HighUpdated
2026-09-25CVE-2026-97612CVE-2026-976127.8 HighUpdated
2026-09-25CVE-2026-97611CVE-2026-976117.8 HighUpdated
2026-09-25CVE-2026-97609CVE-2026-976097.0 HighUpdated
2026-09-25CVE-2026-97608CVE-2026-976087.0 HighUpdated
2026-09-25CVE-2026-97602CVE-2026-976027.8 HighUpdated
2026-09-25CVE-2026-97595CVE-2026-975957.5 HighUpdated
2026-09-25CVE-2026-97594CVE-2026-975947.8 HighUpdated
2026-09-25CVE-2026-97589CVE-2026-975897.0 HighUpdated
2026-09-25CVE-2026-97584CVE-2026-975847.8 HighUpdated
2026-09-25CVE-2026-97583CVE-2026-975837.5 HighUpdated
2026-09-25CVE-2026-97580CVE-2026-975807.8 HighUpdated
2026-09-25CVE-2026-97579CVE-2026-975797.8 HighUpdated
2026-09-25CVE-2026-97578CVE-2026-975787.8 HighUpdated
2026-09-25CVE-2026-97577CVE-2026-975777.8 HighUpdated
2026-09-25CVE-2026-97576CVE-2026-975767.8 HighUpdated
2026-09-25CVE-2026-97575CVE-2026-975757.8 HighUpdated
2026-09-25CVE-2026-97573CVE-2026-975738.1 HighUpdated
2026-09-25CVE-2026-97570CVE-2026-975708.1 HighUpdated
2026-09-25CVE-2026-97562CVE-2026-975627.5 HighUpdated
2026-09-25CVE-2026-97557CVE-2026-975577.5 HighUpdated
2026-09-25CVE-2026-97555CVE-2026-975558.8 HighUpdated
2026-09-25CVE-2026-97548CVE-2026-975487.8 HighUpdated
2026-09-25CVE-2026-97536CVE-2026-975367.5 HighUpdated
2026-09-25CVE-2026-97531CVE-2026-975317.5 HighUpdated
2026-09-25CVE-2026-97528CVE-2026-975288.8 HighUpdated
2026-09-25CVE-2026-97527CVE-2026-975278.8 HighUpdated
2026-09-25CVE-2026-97525CVE-2026-975258.2 HighUpdated
2026-09-25CVE-2026-97524CVE-2026-975247.5 HighUpdated
2026-09-25CVE-2026-97523CVE-2026-975237.5 HighUpdated
2026-09-25CVE-2026-97445CVE-2026-974457.7 HighUpdated
2026-09-25CVE-2026-97444CVE-2026-974447.7 HighUpdated
2026-09-25CVE-2026-97442CVE-2026-974428.8 HighUpdated
2026-09-25CVE-2026-97438CVE-2026-974387.1 HighUpdated
2026-09-25CVE-2026-97437CVE-2026-974377.1 HighUpdated
2026-09-25CVE-2026-97433CVE-2026-974338.2 HighUpdated
2026-09-25CVE-2026-97429CVE-2026-974297.8 HighUpdated
2026-09-25CVE-2026-97428CVE-2026-974287.7 HighUpdated
2026-09-25CVE-2026-97421CVE-2026-974217.8 HighUpdated
2026-09-25CVE-2026-97417CVE-2026-974177.5 HighUpdated
2026-09-25CVE-2026-97413CVE-2026-974139.8 CriticalUpdated
2026-09-25CVE-2026-97409CVE-2026-974098.8 HighUpdated
2026-09-25CVE-2026-93830CVE-2026-938307.5 HighUpdated
2026-09-25CVE-2026-93827CVE-2026-938278.4 HighUpdated
2026-09-25CVE-2026-93826CVE-2026-938267.5 HighUpdated
2026-09-25CVE-2026-93817CVE-2026-938177.8 HighUpdated
2026-09-25CVE-2026-93816CVE-2026-938167.1 HighUpdated
2026-09-25CVE-2026-93813CVE-2026-938137.8 HighUpdated
2026-09-25CVE-2026-93810CVE-2026-938107.0 HighUpdated
2026-09-25CVE-2026-93806CVE-2026-938068.8 HighUpdated
2026-09-25CVE-2026-93801CVE-2026-938017.0 HighUpdated
2026-09-25CVE-2026-93799CVE-2026-937998.8 HighUpdated
2026-09-25CVE-2026-93798CVE-2026-937987.8 HighUpdated
2026-09-25CVE-2026-93796CVE-2026-937967.0 HighUpdated
2026-09-25CVE-2026-93793CVE-2026-937938.8 HighUpdated
2026-09-25CVE-2026-93790CVE-2026-937908.8 HighUpdated
2026-09-25CVE-2026-93787CVE-2026-937878.1 HighUpdated
2026-09-25CVE-2026-93786CVE-2026-937868.1 HighUpdated
2026-09-25CVE-2026-93782CVE-2026-937827.8 HighUpdated
2026-09-25CVE-2026-93345MikroTik RouterOS Labelled-VPN NLRI Prefix-Length Underflow Holds the BGP Plane Down Indefinitely; Fix Is Only in a Development Build7.5 HighUpdated
2026-09-25CVE-2026-93288CVE-2026-932887.8 HighUpdated
2026-09-25CVE-2026-93287CVE-2026-932877.8 HighUpdated
2026-09-25CVE-2026-93284CVE-2026-932848.8 HighUpdated
2026-09-25CVE-2026-93282CVE-2026-932828.1 HighUpdated
2026-09-25CVE-2026-93280CVE-2026-932808.8 HighUpdated
2026-09-25CVE-2026-93277CVE-2026-932777.8 HighUpdated
2026-09-25CVE-2026-93265CVE-2026-932657.7 HighUpdated
2026-09-25CVE-2026-93262CVE-2026-932627.8 HighUpdated
2026-09-25CVE-2026-93260CVE-2026-932607.4 HighUpdated
2026-09-25CVE-2026-93250CVE-2026-932507.8 HighUpdated
2026-09-25CVE-2026-93237CVE-2026-932377.8 HighUpdated
2026-09-25CVE-2026-93229CVE-2026-932297.1 HighUpdated
2026-09-25CVE-2026-93228CVE-2026-932289.1 CriticalUpdated
2026-09-25CVE-2026-93225CVE-2026-932257.4 HighUpdated
2026-09-25CVE-2026-93224CVE-2026-932248.1 HighUpdated
2026-09-25CVE-2026-93221CVE-2026-932218.1 HighUpdated
2026-09-25CVE-2026-93207CVE-2026-932079.8 CriticalUpdated
2026-09-25CVE-2026-72463CVE-2026-724639.8 CriticalUpdated
2026-09-25CVE-2026-72315CVE-2026-723157.8 HighUpdated
2026-09-25CVE-2026-69458CVE-2026-694588.0 HighUpdated
2026-09-25CVE-2026-69456CVE-2026-694567.8 HighUpdated
2026-09-25CVE-2026-69455CVE-2026-694557.8 HighUpdated
2026-09-25CVE-2026-69451CVE-2026-694517.1 HighUpdated
2026-09-25CVE-2026-69448CVE-2026-694487.0 HighUpdated
2026-09-25CVE-2026-69447CVE-2026-694477.8 HighUpdated
2026-09-25CVE-2026-69445CVE-2026-694457.8 HighUpdated
2026-09-25CVE-2026-69444CVE-2026-694447.8 HighUpdated
2026-09-25CVE-2026-69441CVE-2026-694417.0 HighUpdated
2026-09-25CVE-2026-69440CVE-2026-694407.0 HighUpdated
2026-09-25CVE-2026-69436CVE-2026-694367.8 HighUpdated
2026-09-25CVE-2026-69434CVE-2026-694348.8 HighUpdated
2026-09-25CVE-2026-69433CVE-2026-694337.8 HighUpdated
2026-09-25CVE-2026-69396CVE-2026-693967.1 HighUpdated
2026-09-25CVE-2026-69394CVE-2026-693947.0 HighUpdated
2026-09-25CVE-2026-69392CVE-2026-693927.8 HighUpdated
2026-09-25CVE-2026-69391CVE-2026-693917.8 HighUpdated
2026-09-25CVE-2026-69389CVE-2026-693897.8 HighUpdated
2026-09-25CVE-2026-67281CVE-2026-672817.5 HighUpdated
2026-09-25CVE-2026-67278MikroTik RouterOS Accepts Malformed RSA/PKCS#1 v1.5 Signatures Across TLS and SSH, and Its Trust Store Includes an e=3 Root CA, Letting a Network Attacker Forge Valid Signatures Without the Private Key9.1 CriticalUpdated
2026-09-25CVE-2026-5430WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 2710.0 CriticalKEV
2026-09-25CVE-2026-33824Microsoft Windows IKE Service Extensions' Double Free Enables Unauthenticated Remote Attackers to Execute Arbitrary Code; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-25CVE-2026-32157CVE-2026-321578.8 HighUpdated
2026-09-25CVE-2026-26174CVE-2026-261747.0 HighUpdated
2026-09-25CVE-2026-20190CVE-2026-201907.5 HighUpdated
2026-09-25CVE-2026-20147Critical Cisco ISE and ISE-PIC Command Injection Scores 9.99.9 CriticalEPSS-Imminent
2026-09-24CVE-2026-71474Red Hat insights-client logs a long-lived OpenShift pull-secret token that local pod-log access can expose7.1 HighUpdated
2026-09-24CVE-2026-54100Red Hat's Windows Machine Config Operator skips SSH host-key checks, letting adjacent attackers capture node bootstrap credentials8.3 HighUpdated
2026-09-24CVE-2026-54099A compromised Windows node can forge a cluster-administrator certificate through WMCO's CSR auto-approver, CVSS 8.88.8 HighUpdated
2026-09-24CVE-2026-4740Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation8.2 HighUpdated
2026-09-24CVE-2026-40141A critical query-injection flaw in BeyondTrust Remote Support lets low-privileged users reach unauthorized resources, CVSS 9.99.9 CriticalUpdated
2026-09-24CVE-2026-40140Unauthenticated attackers can crash BeyondTrust Remote Support appliances via a network-communication flaw7.5 HighUpdated
2026-09-24CVE-2026-40139Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access9.8 CriticalUpdated
2026-09-24CVE-2026-40138BeyondTrust Privileged Remote Access Shares Pre-Authentication Bypass Flaw with Remote Support8.1 HighUpdated
2026-09-24CVE-2026-33105Critical Authorization Bypass in Microsoft Azure Kubernetes Service Allows Network Privilege Escalation10.0 CriticalUpdated
2026-09-24CVE-2026-32590Unsafe Deserialization in Red Hat Quay Resumable Upload Handling7.1 HighUpdated
2026-09-24CVE-2026-32153Use-After-Free in Windows Speech Component Allows Local Privilege Escalation7.8 HighUpdated
2026-09-24CVE-2026-32091Race Condition in Microsoft Brokering File System Allows Unauthorized Privilege Escalation8.4 HighUpdated
2026-09-24CVE-2026-27914Improper Access Control in Microsoft Management Console Allows Local Privilege Escalation7.8 HighUpdated
2026-09-24CVE-2026-27909Use-After-Free in Windows Search Component Allows Authorized Attacker to Escalate Privileges7.8 HighUpdated
2026-09-24CVE-2026-26181Use-After-Free in Microsoft Brokering File System Lets Authorized User Escalate Privileges7.8 HighUpdated
2026-09-24CVE-2026-26170Input Validation Flaw in Microsoft PowerShell Allows Local Privilege Escalation7.8 HighUpdated
2026-09-24CVE-2026-23429Linux Kernel IOMMU SVA Use-After-Free in Unbind Path Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23428Critical Linux Kernel ksmbd Use-After-Free in Compound Request Handling Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-23427Critical Linux Kernel ksmbd Use-After-Free in Durable Handle Replay Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-23425Linux Kernel KVM arm64 ID Register Initialization Flaw Scores 8.88.8 HighUpdated
2026-09-24CVE-2026-23424Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.17.1 HighUpdated
2026-09-24CVE-2026-23422Linux Kernel dpaa2-switch Out-of-Bounds Write from Malformed Interrupt Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23415Linux Kernel Futex Use-After-Free between Key Lookup and VMA Policy Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23414Linux Kernel TLS Memory Leak in Async Decrypt Wait Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-23413Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23412Linux Kernel Netfilter BPF Use-After-Free in Hook Memory Release Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23411Linux Kernel AppArmor Race Condition Frees i_private Data Early Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23410Linux Kernel AppArmor Race on Rawdata Dereference Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23408Linux Kernel AppArmor Double Free of Namespace Name Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23407Linux Kernel AppArmor Out-of-Bounds Read in DFA Verification Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-22619Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-21662Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-20160Critical Cisco Smart Software Manager On-Prem Resource Exposure Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-20155Cisco Evolved Programmable Network Manager Missing Authorization Scores 8.08.0 HighUpdated
2026-09-24CVE-2026-20151Cisco Smart Software Manager On-Prem Leaks Sensitive Data in Transmitted Requests7.3 HighUpdated
2026-09-24CVE-2026-20094Cisco UCS Command Injection Scores 8.88.8 HighUpdated
2026-09-24CVE-2026-16443Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.47.4 HighUpdated
2026-09-24CVE-2026-0265Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.18.1 HighUpdated
2026-09-24CVE-2026-0264Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-0262Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE18087.5 HighUpdated
2026-09-24CVE-2026-0261Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.27.2 HighUpdated
2026-09-24CVE-2026-0258Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.19.1 CriticalUpdated
2026-09-24CVE-2026-89028MikroTik RouterOS SMB1 SessionSetupAndX Handler Integer Underflow in uniPwdLen Corrupts Adjacent Heap Memory7.5 HighUpdated
2026-09-24CVE-2026-85880Microsoft Windows' Heap-Based Buffer Overflow Allows Local Attackers to Escalate Privileges by Corrupting Heap Memory; CISA's September 22nd KEV Deadline Has Passed7.8 HighKEV
2026-09-24CVE-2026-80156Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Strips Backslash Characters but Not Forward Slashes During Path Validation, Letting Authenticated Attackers Write Files to Arbitrary Filesystem Locations9.1 CriticalUpdated
2026-09-24CVE-2026-80155Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Requires No Authentication, Allowing Unauthenticated Attackers to Read Configuration Files and Upload to Arbitrary Filesystem Locations, Scoring CVSS 10.010.0 CriticalUpdated
2026-09-24CVE-2026-80154Lantronix SLC8000, SLC9000, EMG, and SLB Series Web Portal Derives Session Tokens Deterministically from Device Model and Current Second, Letting Unauthenticated Attackers Predict and Forge Valid Sessions on All Firmware Versions9.6 CriticalUpdated
2026-09-24CVE-2026-80147Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root9.9 CriticalUpdated
2026-09-24CVE-2026-80145Lantronix SLC8000/SLC9000 and EMG Series Set CIFS Password Command Passes User Input Unsanitized to system(), Enabling Authenticated Users with Services Permission to Run Commands as Root9.1 CriticalUpdated
2026-09-24CVE-2026-80144Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution9.9 CriticalUpdated
2026-09-24CVE-2026-80143Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution9.9 CriticalUpdated
2026-09-24CVE-2026-69571CVE-2026-695717.8 HighUpdated
2026-09-24CVE-2026-69567CVE-2026-695677.0 HighUpdated
2026-09-24CVE-2026-69564CVE-2026-695647.0 HighUpdated
2026-09-24CVE-2026-69563CVE-2026-695637.0 HighUpdated
2026-09-24CVE-2026-69561CVE-2026-695617.8 HighUpdated
2026-09-24CVE-2026-69560CVE-2026-695607.0 HighUpdated
2026-09-24CVE-2026-69553CVE-2026-695537.1 HighUpdated
2026-09-24CVE-2026-69551CVE-2026-695518.8 HighUpdated
2026-09-24CVE-2026-69547CVE-2026-695478.8 HighUpdated
2026-09-24CVE-2026-69544CVE-2026-695447.8 HighUpdated
2026-09-24CVE-2026-69542CVE-2026-695427.8 HighUpdated
2026-09-24CVE-2026-69540CVE-2026-695407.0 HighUpdated
2026-09-24CVE-2026-69539CVE-2026-695397.5 HighUpdated
2026-09-24CVE-2026-69538CVE-2026-695387.8 HighUpdated
2026-09-24CVE-2026-69535CVE-2026-695357.8 HighUpdated
2026-09-24CVE-2026-69534CVE-2026-695347.8 HighUpdated
2026-09-24CVE-2026-69532CVE-2026-695327.8 HighUpdated
2026-09-24CVE-2026-69525CVE-2026-695259.8 CriticalUpdated
2026-09-24CVE-2026-69518CVE-2026-695188.8 HighUpdated
2026-09-24CVE-2026-69514CVE-2026-695147.5 HighUpdated
2026-09-24CVE-2026-69511CVE-2026-695118.8 HighUpdated
2026-09-24CVE-2026-69510CVE-2026-695108.1 HighUpdated
2026-09-24CVE-2026-69509CVE-2026-695097.8 HighUpdated
2026-09-24CVE-2026-69505CVE-2026-695058.0 HighUpdated
2026-09-24CVE-2026-69500CVE-2026-695007.0 HighUpdated
2026-09-24CVE-2026-69496CVE-2026-694969.8 CriticalUpdated
2026-09-24CVE-2026-69491CVE-2026-694919.8 CriticalUpdated
2026-09-24CVE-2026-69479CVE-2026-694798.4 HighUpdated
2026-09-24CVE-2026-69475CVE-2026-694757.8 HighUpdated
2026-09-24CVE-2026-69473CVE-2026-694737.0 HighUpdated
2026-09-24CVE-2026-69466CVE-2026-694667.0 HighUpdated
2026-09-24CVE-2026-69463CVE-2026-694639.8 CriticalUpdated
2026-09-24CVE-2026-69461CVE-2026-694618.8 HighUpdated
2026-09-24CVE-2026-69450CVE-2026-694507.8 HighUpdated
2026-09-24CVE-2026-69430CVE-2026-694307.0 HighUpdated
2026-09-24CVE-2026-69429CVE-2026-694297.5 HighUpdated
2026-09-24CVE-2026-69428CVE-2026-694287.5 HighUpdated
2026-09-24CVE-2026-69427CVE-2026-694278.0 HighUpdated
2026-09-24CVE-2026-69426CVE-2026-694267.8 HighUpdated
2026-09-24CVE-2026-69424CVE-2026-694247.8 HighUpdated
2026-09-24CVE-2026-69423CVE-2026-694238.0 HighUpdated
2026-09-24CVE-2026-69421CVE-2026-694217.8 HighUpdated
2026-09-24CVE-2026-69420CVE-2026-694207.8 HighUpdated
2026-09-24CVE-2026-69413CVE-2026-694137.0 HighUpdated
2026-09-24CVE-2026-69412CVE-2026-694128.0 HighUpdated
2026-09-24CVE-2026-69410CVE-2026-694107.0 HighUpdated
2026-09-24CVE-2026-69408CVE-2026-694089.8 CriticalUpdated
2026-09-24CVE-2026-69404CVE-2026-694047.0 HighUpdated
2026-09-24CVE-2026-69398CVE-2026-693987.0 HighUpdated
2026-09-24CVE-2026-69397CVE-2026-693977.5 HighUpdated
2026-09-24CVE-2026-69388CVE-2026-693887.0 HighUpdated
2026-09-24CVE-2026-69386CVE-2026-693868.8 HighUpdated
2026-09-24CVE-2026-69385CVE-2026-693857.0 HighUpdated
2026-09-24CVE-2026-69383CVE-2026-693837.0 HighUpdated
2026-09-24CVE-2026-69377CVE-2026-693777.8 HighUpdated
2026-09-24CVE-2026-69371CVE-2026-693718.0 HighUpdated
2026-09-24CVE-2026-69368CVE-2026-693687.8 HighUpdated
2026-09-24CVE-2026-69366CVE-2026-693667.1 HighUpdated
2026-09-24CVE-2026-69364CVE-2026-693647.1 HighUpdated
2026-09-24CVE-2026-69362CVE-2026-693627.0 HighUpdated
2026-09-24CVE-2026-69357CVE-2026-693577.1 HighUpdated
2026-09-24CVE-2026-69347CVE-2026-693477.4 HighUpdated
2026-09-24CVE-2026-69346CVE-2026-693468.0 HighUpdated
2026-09-24CVE-2026-69342CVE-2026-693427.5 HighUpdated
2026-09-24CVE-2026-69341CVE-2026-693417.0 HighUpdated
2026-09-24CVE-2026-69340CVE-2026-693407.1 HighUpdated
2026-09-24CVE-2026-69337CVE-2026-693377.1 HighUpdated
2026-09-24CVE-2026-69335CVE-2026-693357.0 HighUpdated
2026-09-24CVE-2026-69334CVE-2026-693348.8 HighUpdated
2026-09-24CVE-2026-69332CVE-2026-693328.0 HighUpdated
2026-09-24CVE-2026-69331CVE-2026-693317.0 HighUpdated
2026-09-24CVE-2026-69328CVE-2026-693287.8 HighUpdated
2026-09-24CVE-2026-69324CVE-2026-693247.8 HighUpdated
2026-09-24CVE-2026-69322CVE-2026-693228.0 HighUpdated
2026-09-24CVE-2026-69319CVE-2026-693197.0 HighUpdated
2026-09-24CVE-2026-69312CVE-2026-693127.8 HighUpdated
2026-09-24CVE-2026-69311CVE-2026-693117.0 HighUpdated
2026-09-24CVE-2026-69310CVE-2026-693107.0 HighUpdated
2026-09-24CVE-2026-69309CVE-2026-693097.0 HighUpdated
2026-09-24CVE-2026-69307CVE-2026-693077.8 HighUpdated
2026-09-24CVE-2026-69305CVE-2026-693057.1 HighUpdated
2026-09-24CVE-2026-69301CVE-2026-693018.0 HighUpdated
2026-09-24CVE-2026-69300CVE-2026-693007.0 HighUpdated
2026-09-24CVE-2026-69299CVE-2026-692997.0 HighUpdated
2026-09-24CVE-2026-69296CVE-2026-692967.1 HighUpdated
2026-09-24CVE-2026-69295CVE-2026-692957.8 HighUpdated
2026-09-24CVE-2026-69291CVE-2026-692918.8 HighUpdated
2026-09-24CVE-2026-69290CVE-2026-692907.8 HighUpdated
2026-09-24CVE-2026-69289CVE-2026-692897.8 HighUpdated
2026-09-24CVE-2026-69287CVE-2026-692877.0 HighUpdated
2026-09-24CVE-2026-69284CVE-2026-692847.8 HighUpdated
2026-09-24CVE-2026-69283CVE-2026-692837.8 HighUpdated
2026-09-24CVE-2026-69281CVE-2026-692817.0 HighUpdated
2026-09-24CVE-2026-69280CVE-2026-692807.0 HighUpdated
2026-09-24CVE-2026-69279CVE-2026-692797.0 HighUpdated
2026-09-24CVE-2026-69274CVE-2026-692747.1 HighUpdated
2026-09-24CVE-2026-69270CVE-2026-692707.8 HighUpdated
2026-09-24CVE-2026-69266CVE-2026-692668.8 HighUpdated
2026-09-24CVE-2026-69265CVE-2026-692657.8 HighUpdated
2026-09-24CVE-2026-68896CVE-2026-688967.8 HighUpdated
2026-09-24CVE-2026-68894CVE-2026-688948.0 HighUpdated
2026-09-24CVE-2026-68893CVE-2026-688937.1 HighUpdated
2026-09-24CVE-2026-68887CVE-2026-688877.5 HighUpdated
2026-09-24CVE-2026-68880CVE-2026-688808.0 HighUpdated
2026-09-24CVE-2026-68878CVE-2026-688788.0 HighUpdated
2026-09-24CVE-2026-68877CVE-2026-688777.8 HighUpdated
2026-09-24CVE-2026-68876CVE-2026-688768.0 HighUpdated
2026-09-24CVE-2026-68875CVE-2026-688757.8 HighUpdated
2026-09-24CVE-2026-68848CVE-2026-688487.8 HighUpdated
2026-09-24CVE-2026-68846CVE-2026-688467.1 HighUpdated
2026-09-24CVE-2026-68845CVE-2026-688457.8 HighUpdated
2026-09-24CVE-2026-68844CVE-2026-688447.8 HighUpdated
2026-09-24CVE-2026-68841CVE-2026-688417.8 HighUpdated
2026-09-24CVE-2026-68840CVE-2026-688407.0 HighUpdated
2026-09-24CVE-2026-68839CVE-2026-688399.8 CriticalUpdated
2026-09-24CVE-2026-68838CVE-2026-688388.0 HighUpdated
2026-09-24CVE-2026-68835CVE-2026-688357.1 HighUpdated
2026-09-24CVE-2026-68834CVE-2026-688348.0 HighUpdated
2026-09-24CVE-2026-68832CVE-2026-688327.8 HighUpdated
2026-09-24CVE-2026-68827CVE-2026-688278.0 HighUpdated
2026-09-24CVE-2026-62759CVE-2026-627597.5 HighUpdated
2026-09-24CVE-2026-62706CVE-2026-627068.8 HighUpdated
2026-09-24CVE-2026-62694CVE-2026-626947.0 HighUpdated
2026-09-24CVE-2026-50349CVE-2026-503497.0 HighUpdated
2026-09-24CVE-2026-19654CVE-2026-196547.5 HighUpdated
2026-09-24CVE-2026-13249Honeywell PD45 Industrial Printer F10.19.010040 Web Management Interface Allows Unauthenticated File Upload of Attacker-Controlled Files, Enabling Remote Code Execution Without Credentials9.8 CriticalUpdated
2026-09-24CVE-2026-13248Honeywell PD45 Industrial Printer Fingerprint command interface allows authenticated admin to write arbitrary files and execute code8.8 HighUpdated
2026-09-23CVE-2026-20180Critical Cisco ISE Path Traversal Enables Remote Code Execution, Scores 9.99.9 CriticalEPSS-Imminent
2026-09-23CVE-2026-94127CISA's September 25th Remediation Deadline for F5 BIG-IP APM's OAuth Profile Heap Overflow Has Passed; Covered Entities Running Affected Virtual Servers Are Out of Compliance9.8 CriticalKEV
2026-09-23CVE-2026-93952Arista VeloCloud Orchestrator Input Validation Gap Lets Remote Attackers Reach Privileged APIs; CISA's September 25th KEV Deadline for Covered Entities Has Now Passed10.0 CriticalKEV
2026-09-23CVE-2026-83998CVE-2026-839988.8 HighUpdated
2026-09-23CVE-2026-73176Advantech EKI-1242IEIMS Web Management Interface Passes Request Parameters to OS Commands Without Sanitization, Enabling Root Execution for Authenticated Administrators8.6 HighUpdated
2026-09-23CVE-2026-73175Adjacent Unauthenticated Attacker Can Exhaust the Advantech EKI-1242EIMS OPC UA Session Pool by Opening Multiple Anonymous Connections7.1 HighUpdated
2026-09-23CVE-2026-73174Advantech EKI-1242EIMS edgserver Management Protocol Transmits Device Identity and Network Metadata in Cleartext, Recoverable by a Network-Adjacent Passive Observer8.7 HighUpdated
2026-09-23CVE-2026-73173Advantech EKI-1242EIMS edgserver on TCP Port 5058 Requires No Authentication, Allowing Remote Attackers to Reconfigure the Network, Reboot, Reset, or Replace Firmware8.8 HighUpdated
2026-09-23CVE-2026-73172Advantech EKI-1242EIMS Firmware V1.06.01 edgserver Management Service Passes Unsanitized Input to the OS Shell, Enabling Unauthenticated Remote Attackers to Execute Arbitrary Commands9.3 CriticalUpdated
2026-09-23CVE-2026-73171Advantech EKI-1242EIMS Backup-Restore Workflow Accepts Crafted Archives That Overwrite Arbitrary Files on the Device Filesystem8.6 HighUpdated
2026-09-23CVE-2026-73170Advantech EKI-1242EIMS Modbus CSV Import Evaluates Crafted File Content as Lua, Allowing Authenticated Administrators to Execute Arbitrary Code8.6 HighUpdated
2026-09-23CVE-2026-73167Authenticated Administrator Can Inject OS Commands as Root via Crafted Request Parameters in the Advantech EKI-1242IEIMS Web Management Interface8.6 HighUpdated
2026-09-23CVE-2026-73166Advantech EKI-1242IEIMS Web Management Interface Evaluates Code from Request Parameters, Giving Authenticated Administrators Root-Level Code Execution8.6 HighUpdated
2026-09-23CVE-2026-73165Advantech EKI-1242IEIMS Web Management Endpoint Executes Attacker-Supplied OS Commands as Root When Request Parameters Are Not Sanitized8.6 HighUpdated
2026-09-23CVE-2026-73164Crafted HTTP Request Parameters Reach Root-Level OS Execution in Advantech EKI-1242IEIMS Due to Unsanitized Web Interface Input8.6 HighUpdated
2026-09-23CVE-2026-73163Advantech EKI-1242IEIMS Web Interface OS Command Injection Grants Root Access to Authenticated Administrators8.6 HighUpdated
2026-09-23CVE-2026-73014CVE-2026-730147.8 HighUpdated
2026-09-23CVE-2026-70584CVE-2026-705847.8 HighUpdated
2026-09-23CVE-2026-69528CVE-2026-695287.8 HighUpdated
2026-09-23CVE-2026-69517CVE-2026-695177.0 HighUpdated
2026-09-23CVE-2026-69512CVE-2026-695128.0 HighUpdated
2026-09-23CVE-2026-69508CVE-2026-695087.8 HighUpdated
2026-09-23CVE-2026-69443CVE-2026-694437.5 HighUpdated
2026-09-23CVE-2026-19535Advantech EKI-1242IEIMS LuCI admin interface CSRF allows unauthenticated attacker to trigger privileged management actions8.6 HighUpdated
2026-09-23CVE-2026-19438CVE-2026-194387.5 HighUpdated
2026-09-23CVE-2026-12974Forcepoint NGFW security policy bypass affects versions across 7.1, 7.3, 7.4, and 7.5 branches7.9 HighUpdated
2026-09-22CVE-2026-9586Sangoma Switchvox's SQL Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Database Queries and Compromise the Telephony Platform9.8 CriticalKEV
2026-09-22CVE-2026-9198IBM Langflow's Code Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the AI Workflow Platform; CISA's August 7th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-9082Drupal Core's SQL Injection via Specially Crafted Database Abstraction API Requests Enables Privilege Escalation and Remote Code Execution; CISA's May 27th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-86218N-able N-central's Static Code Injection Flaw Allows Remote Attackers to Inject and Execute Arbitrary Code on the RMM Platform Without Prior Authentication9.8 CriticalKEV
2026-09-22CVE-2026-85706GitLab Community and Enterprise Edition's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Read Arbitrary Files on the Server and Fully Compromise the GitLab Instance10.0 CriticalKEV
2026-09-22CVE-2026-83549SonicWall SMA1000 Appliances' OS Command Injection Allows Authenticated Local Attackers to Execute Arbitrary Commands with Root Privileges; CISA's September 5th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-83548SonicWall SMA1000 Appliances' Server-Side Request Forgery Allows Unauthenticated Remote Attackers to Reach Internal Services and Compromise the Secure Mobile Access Gateway; CISA's September 5th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-82329JFrog Artifactory Carries a 9.8 Critical Improper Authentication Flaw That Lets Unauthenticated Attackers Bypass Login Controls on the Artifact Repository9.8 CriticalKEV
2026-09-22CVE-2026-73570Zimbra Collaboration Suite's OS Command Injection Allows Authenticated Attackers to Execute Arbitrary Commands on the Email Server with Elevated Privileges; CISA's August 24th KEV Deadline Has Passed8.9 HighKEV
2026-09-22CVE-2026-72898Metabase's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Achieve Full Platform Compromise; CISA's August 14th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-6973Ivanti Endpoint Manager Mobile's Improper Input Validation Allows a Remotely Authenticated Administrator to Execute Code Remotely; CISA's May 10th KEV Deadline Has Passed7.2 HighKEV
2026-09-22CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock's Use-After-Free Allows a Local Attacker to Gain Elevated Privileges via a Freed Memory Reference; CISA's August 25th KEV Deadline Has Passed7.0 HighKEV
2026-09-22CVE-2026-65400Apple macOS's Improper Authentication Flaw Allows a Network Attacker to Bypass Login Controls and Gain Unauthorized Access to the Operating System; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-64849MLflow's Server-Side Request Forgery Flaw Allows Remote Attackers to Use the ML Platform Server as a Proxy to Access Internal Services and Steal Credentials; CISA's September 2nd KEV Deadline Has Passed9.3 CriticalKEV
2026-09-22CVE-2026-63077JetBrains TeamCity's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the CI/CD Server; CISA's August 8th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-63030WordPress Core Input Interpretation Conflict Exploited in the Wild Carries a Lapsed July 24th CISA KEV Mandate for Covered Entities9.8 CriticalKEV
2026-09-22CVE-2026-60137WordPress Core SQL Injection Enabling Database Access Joins CISA's Known Exploited Vulnerabilities Catalog; Covered Entities Past the August 4th Remediation Deadline5.9 MediumKEV
2026-09-22CVE-2026-60004Gitea's Code Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Repository Platform; CISA's August 28th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-59310Broadcom VMware vCenter's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Access Files Outside the Web Root and Potentially Compromise the Virtualization Platform; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-56291Balbooa Forms Unrestricted File Upload Requiring No Authentication Has Missed CISA's July 13th KEV Remediation Deadline; Covered Entities Are Now Out of Compliance9.8 CriticalKEV
2026-09-22CVE-2026-56290Joomlack Page Builder Lets Unauthenticated Users Upload Arbitrary Files, Enabling Remote Code Execution; CISA's July 10th KEV Mandate Has Lapsed9.8 CriticalKEV
2026-09-22CVE-2026-55040Microsoft SharePoint's Weak Authentication Allows Attackers to Bypass Login Controls and Gain Unauthorized Access to SharePoint Sites and Data; CISA's August 21st KEV Deadline Has Passed9.1 CriticalKEV
2026-09-22CVE-2026-50751Check Point Security Gateway's IKEv1 Key Exchange Flaw Lets Unauthenticated Attackers Establish Remote Access VPN Tunnels Without a Valid Password; CISA's June 11th KEV Deadline Has Passed9.3 CriticalKEV
2026-09-22CVE-2026-48939iCagenda Joomla Event Calendar Extension Accepts Unrestricted File Uploads Without Authentication, Enabling Remote Code Execution; CISA's July 13th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-48908JoomShaper SP Page Builder Accepts Arbitrary File Uploads from Unauthenticated Users; CISA's July 10th KEV Deadline for Covered Entities Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-48907Joomla Content Editor Plugin Exposes Privileged Functions Without Proper Authorization; CISA's June 19th KEV Deadline for Covered Entities Has Lapsed9.8 CriticalKEV
2026-09-22CVE-2026-48558SimpleHelp Accepts Unverified Cryptographic Signatures, Letting Remote Attackers Bypass Authentication; CISA's July 2nd KEV Deadline for Covered Entities Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-48172Any cPanel User Can Escalate Privileges Through LiteSpeed's Plugin; CISA's May 29th KEV Remediation Requirement for Covered Entities Has Expired9.8 CriticalKEV
2026-09-22CVE-2026-46817Oracle E-Business Suite's Improper Privilege Management in Oracle Payments Allows an Unauthenticated Network Attacker to Take Over the Payments Module via HTTP; CISA's July 18th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-45498Microsoft Defender's Unspecified Vulnerability Allows for Denial of Service; CISA's June 3rd KEV Deadline Has Passed4.0 MediumKEV
2026-09-22CVE-2026-45247Mirasvit Full Page Cache Warmer's Deserialization Flaw Lets Unauthenticated Attackers Reach Remote Code Execution via a Crafted PHP Object in the CacheWarmer Cookie; CISA's June 6th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-42897Microsoft Exchange Server's Outlook Web Access Cross-Site Scripting Flaw Executes Arbitrary JavaScript When Interaction Conditions Are Met; CISA's May 29th KEV Deadline Has Passed8.1 HighKEV
2026-09-22CVE-2026-42018JFrog Artifactory's Improper Authentication Allows Network-Based Attackers to Bypass Login Controls and Gain Unauthorized Access to the Artifact Repository7.5 HighKEV
2026-09-22CVE-2026-42016JFrog Artifactory's Incorrect Authorization Allows Authenticated Users to Access Artifacts and Repositories Outside Their Permitted Scope8.1 HighKEV
2026-09-22CVE-2026-41091Microsoft Defender's Link Following Flaw Enables an Authorized Attacker to Elevate Privileges Locally; CISA's June 3rd KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-39987Marimo's Pre-Authentication Flaw Gives Unauthenticated Attackers Shell Access and Arbitrary Command Execution; CISA's May 7th KEV Remediation Requirement for Covered Entities Has Long Lapsed9.8 CriticalKEV
2026-09-22CVE-2026-39808Fortinet FortiSandbox's OS Command Injection Gives Unauthenticated Attackers Remote Code Execution via Crafted HTTP Requests; CISA's July 19th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-35616Fortinet FortiClient EMS Access Control Bypass Entered CISA's Known Exploited Vulnerabilities Catalog with an April 9th Federal Deadline That Has Long Passed9.8 CriticalKEV
2026-09-22CVE-2026-35273Oracle PeopleSoft Enterprise PeopleTools' Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Take Over the Platform; CISA's June 15th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-34926Pre-Authenticated Local Attackers Can Use Relative Path Traversal in Trend Micro Apex One to Modify Key Configuration Data; CISA's June 4th KEV Mandate for Covered Entities Has Lapsed6.7 MediumKEV
2026-09-22CVE-2026-34910Network-Adjacent Attackers Can Inject Commands into Ubiquiti UniFi OS Through an Input Validation Flaw; CISA's June 26th KEV Remediation Window Has Closed for Covered Entities10.0 CriticalKEV
2026-09-22CVE-2026-34909Ubiquiti UniFi OS's Path Traversal Lets a Network-Adjacent Attacker Access Files on the Underlying System and Manipulate an Underlying Account; CISA's June 26th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-34908Ubiquiti UniFi OS's Improper Access Control Lets a Network-Adjacent Attacker Make Unauthorized Changes to the System; CISA's June 26th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-34486Apache Tomcat's Missing Encryption of Sensitive Session Data Exposes Credentials and Tokens to Network Interception; CISA's August 7th KEV Deadline Has Passed7.5 HighKEV
2026-09-22CVE-2026-34197Apache ActiveMQ's Improper Input Validation Enables Code Injection Affecting Both ActiveMQ and Broker Deployments; CISA's April 30th KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2026-33825Microsoft Defender's Insufficient Access Control Allows an Authorized Attacker to Escalate Privileges Locally; CISA's May 6th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-32202Microsoft Windows Shell's Protection Mechanism Failure Allows an Unauthorized Attacker to Perform Spoofing Over the Network; CISA's May 12th KEV Deadline Has Passed4.3 MediumKEV
2026-09-22CVE-2026-31431Linux Kernel Resource Mishandling That Allows Privilege Escalation Carries a Lapsed May 15th CISA KEV Mandate; Covered Entities on Unpatched Kernels Remain Out of Compliance7.8 HighKEV
2026-09-22CVE-2026-28318SolarWinds Serv-U File Transfer Server Resource Exhaustion Exploited in the Wild Carries a Lapsed June 19th CISA KEV Federal Deadline7.5 HighKEV
2026-09-22CVE-2026-25089Fortinet FortiSandbox's Unauthenticated OS Command Injection via Crafted HTTP Requests Covers Cloud and PaaS Deployments; CISA's July 19th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-21962Oracle HTTP Server and WebLogic Server Proxy Plug-in's Improper Access Control Allows Unauthenticated Network Attackers to Fully Compromise the Middleware Platform; CISA's August 27th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-21643Fortinet FortiClient EMS's SQL Injection Allows Unauthenticated Attackers to Execute Unauthorized Code via Crafted HTTP Requests; CISA's April 16th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-20316Cisco Secure Firewall Management Center Hard-Coded Password Lets Attackers Bypass Authentication; CISA's August 1st KEV Deadline for Covered Entities Has Passed5.3 MediumKEV
2026-09-22CVE-2026-20262Authenticated Path Traversal in Cisco Catalyst SD-WAN Manager Lets Remote Attackers Write Files Outside Allowed Directories; CISA's June 29th KEV Deadline Has Passed6.5 MediumKEV
2026-09-22CVE-2026-20253Splunk Enterprise's Missing Authentication on a PostgreSQL Sidecar Service Endpoint Lets Unauthenticated Users Create or Truncate Arbitrary Files; CISA's June 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-20245Cisco Catalyst SD-WAN Manager's Improper Encoding Allows an Authenticated Local Attacker to Execute Arbitrary Commands as Root via a Crafted File; CISA's June 23rd KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-20230Cisco Unified Communications Manager SSRF Flaw Routes Attacker Requests to Internal Resources; CISA's June 28th KEV Deadline for Covered Entities Has Lapsed8.6 HighKEV
2026-09-22CVE-2026-20200Cisco Unified Computing System's Argument Delimiter Injection Allows an Authenticated Attacker to Execute Arbitrary Commands on the Management Controller8.8 HighExploited
2026-09-22CVE-2026-20182Cisco Catalyst SD-WAN Controller and Manager's Authentication Bypass Gives Unauthenticated Remote Attackers Administrative Privileges; CISA's May 17th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-20133Cisco Catalyst SD-WAN Manager Leaks Sensitive Configuration Data to Unauthorized Users; CISA's April 23rd KEV Remediation Requirement Has Expired for Covered Entities6.5 MediumKEV
2026-09-22CVE-2026-20128Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed7.5 HighKEV
2026-09-22CVE-2026-20122Cisco Catalyst SD-WAN Manager Exposes Privileged API Functions to Unauthorized Callers; CISA's April 23rd KEV Remediation Deadline for Covered Entities Has Long Passed5.4 MediumKEV
2026-09-22CVE-2026-20079Cisco Firewall Management Center's Authentication Bypass via an Alternate Path Grants Unauthenticated Remote Attackers Full Administrative Control; CISA's September 12th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-19490Citrix NetScaler's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access Protected Resources Without Valid Credentials9.8 CriticalKEV
2026-09-22CVE-2026-16232Check Point SmartConsole's Improper Authentication Allows Unauthenticated Remote Attackers to Obtain a Login Token and Authenticate with Full Administrative Privileges; CISA's July 25th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-15410SonicWall SMA1000's Code Injection Allows a Remote Authenticated Administrator to Execute Arbitrary OS Commands Under Specific Conditions; CISA's July 17th KEV Deadline Has Passed7.2 HighKEV
2026-09-22CVE-2026-15409SonicWall SMA1000 Secure Access Appliances Accept Forged Server-Side Requests, Enabling Internal Network Pivoting; CISA's July 17th KEV Remediation Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-1340Ivanti Endpoint Manager Mobile's Code Injection Vulnerability Allows Attackers to Achieve Unauthenticated Remote Code Execution; CISA's April 11th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-12569PTC Windchill and FlexPLM's Improper Input Validation Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via Malicious Network Requests; CISA's June 28th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-10520Ivanti Sentry's OS Command Injection Gives Remote Unauthenticated Attackers Root-Level Remote Code Execution; CISA's June 14th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-0300PAN-OS Out-of-Bounds Write Enabling Code Execution Affects Both Palo Alto Networks Firewalls and Siemens RUGGEDCOM APE1808 Industrial Appliances; CISA's May 9th KEV Window Has Closed9.8 CriticalKEV
2026-09-22CVE-2026-0257PAN-OS Authentication Bypass Enabling Unauthorized VPN Tunnels Affects Palo Alto Networks Prisma Access and Siemens RUGGEDCOM APE1808; Now Listed in CISA's Known Exploited Vulnerabilities Catalog9.1 CriticalKEV
2026-09-22CVE-2026-95675CVE-2026-956759.8 CriticalUpdated
2026-09-22CVE-2026-94089CVE-2026-9408910.0 CriticalUpdated
2026-09-22CVE-2026-72946CVE-2026-729467.8 HighUpdated
2026-09-22CVE-2026-72940CVE-2026-729408.8 HighUpdated
2026-09-22CVE-2026-72936CVE-2026-729368.1 HighUpdated
2026-09-22CVE-2026-72929CVE-2026-729297.8 HighUpdated
2026-09-22CVE-2026-72926CVE-2026-729267.0 HighUpdated
2026-09-22CVE-2026-7273Zyxel GS1900 Series Switches' CGI Program Stack-Based Buffer Overflow Allows a LAN-Side Unauthenticated Attacker to Execute OS Commands via Crafted HTTP Requests; CISA's September 24th KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2026-71221CVE-2026-712217.0 HighUpdated
2026-09-22CVE-2026-71220CVE-2026-712207.0 HighUpdated
2026-09-22CVE-2026-69791CVE-2026-697917.0 HighUpdated
2026-09-22CVE-2026-69790CVE-2026-697907.8 HighUpdated
2026-09-22CVE-2026-69784CVE-2026-697848.8 HighUpdated
2026-09-22CVE-2026-69775CVE-2026-697757.1 HighUpdated
2026-09-22CVE-2026-69762CVE-2026-697628.0 HighUpdated
2026-09-22CVE-2026-69760CVE-2026-697607.5 HighUpdated
2026-09-22CVE-2026-69757CVE-2026-697577.1 HighUpdated
2026-09-22CVE-2026-69744CVE-2026-697447.5 HighUpdated
2026-09-22CVE-2026-69740CVE-2026-697408.8 HighUpdated
2026-09-22CVE-2026-69735CVE-2026-697357.0 HighUpdated
2026-09-22CVE-2026-69729CVE-2026-697298.8 HighUpdated
2026-09-22CVE-2026-69725CVE-2026-697257.8 HighUpdated
2026-09-22CVE-2026-69720CVE-2026-697207.8 HighUpdated
2026-09-22CVE-2026-69711CVE-2026-697117.0 HighUpdated
2026-09-22CVE-2026-69710CVE-2026-697107.5 HighUpdated
2026-09-22CVE-2026-69708CVE-2026-697087.0 HighUpdated
2026-09-22CVE-2026-69694CVE-2026-696947.0 HighUpdated
2026-09-22CVE-2026-69693CVE-2026-696937.0 HighUpdated
2026-09-22CVE-2026-69689CVE-2026-696898.0 HighUpdated
2026-09-22CVE-2026-69682CVE-2026-696827.0 HighUpdated
2026-09-22CVE-2026-69654CVE-2026-696547.0 HighUpdated
2026-09-22CVE-2026-69652CVE-2026-696527.0 HighUpdated
2026-09-21CVE-2026-94036CVE-2026-940368.8 HighUpdated
2026-09-21CVE-2026-93958CVE-2026-939589.1 CriticalUpdated
2026-09-21CVE-2026-90042CVE-2026-900429.8 CriticalUpdated
2026-09-21CVE-2026-90041CVE-2026-900418.8 HighUpdated
2026-09-21CVE-2026-90037CVE-2026-900379.8 CriticalUpdated
2026-09-21CVE-2026-90036CVE-2026-900369.8 CriticalUpdated
2026-09-21CVE-2026-89815CVE-2026-898157.8 HighUpdated
2026-09-21CVE-2026-89799CVE-2026-897997.8 HighUpdated
2026-09-21CVE-2026-89763CVE-2026-897637.8 HighUpdated
2026-09-21CVE-2026-89755CVE-2026-897557.8 HighUpdated
2026-09-21CVE-2026-89731CVE-2026-897317.1 HighUpdated
2026-09-21CVE-2026-89708CVE-2026-897089.8 CriticalUpdated
2026-09-21CVE-2026-89685CVE-2026-896857.5 HighUpdated
2026-09-21CVE-2026-89676CVE-2026-896769.8 CriticalUpdated
2026-09-21CVE-2026-89667CVE-2026-896678.1 HighUpdated
2026-09-21CVE-2026-89660CVE-2026-896609.8 CriticalUpdated
2026-09-21CVE-2026-89659CVE-2026-896599.8 CriticalUpdated
2026-09-21CVE-2026-89624CVE-2026-896247.8 HighUpdated
2026-09-21CVE-2026-89622CVE-2026-896227.8 HighUpdated
2026-09-21CVE-2026-89602CVE-2026-896027.8 HighUpdated
2026-09-21CVE-2026-89564CVE-2026-895647.8 HighUpdated
2026-09-21CVE-2026-89561CVE-2026-895617.5 HighUpdated
2026-09-21CVE-2026-89545CVE-2026-895457.8 HighUpdated
2026-09-21CVE-2026-89544CVE-2026-895447.5 HighUpdated
2026-09-21CVE-2026-89535CVE-2026-895358.1 HighUpdated
2026-09-21CVE-2026-89492CVE-2026-894929.8 CriticalUpdated
2026-09-21CVE-2026-80945CVE-2026-809459.1 CriticalUpdated
2026-09-21CVE-2026-80734CVE-2026-807348.8 HighUpdated
2026-09-21CVE-2026-80685CVE-2026-806857.1 HighUpdated
2026-09-21CVE-2026-74407CVE-2026-744078.8 HighUpdated
2026-09-21CVE-2026-74269CVE-2026-742699.8 CriticalUpdated
2026-09-21CVE-2026-72989CVE-2026-729897.5 HighUpdated
2026-09-21CVE-2026-72962CVE-2026-729628.2 HighUpdated
2026-09-21CVE-2026-72961CVE-2026-729618.2 HighUpdated
2026-09-21CVE-2026-72960CVE-2026-729608.8 HighUpdated
2026-09-21CVE-2026-72958CVE-2026-729588.2 HighUpdated
2026-09-21CVE-2026-72953CVE-2026-729537.8 HighUpdated
2026-09-21CVE-2026-72952CVE-2026-729527.0 HighUpdated
2026-09-21CVE-2026-72949CVE-2026-729497.5 HighUpdated
2026-09-21CVE-2026-72494CVE-2026-724949.8 CriticalUpdated
2026-09-21CVE-2026-72438CVE-2026-724387.5 HighUpdated
2026-09-21CVE-2026-72355CVE-2026-723559.8 CriticalUpdated
2026-09-21CVE-2026-71226CVE-2026-712267.3 HighUpdated
2026-09-21CVE-2026-69648CVE-2026-696487.0 HighUpdated
2026-09-21CVE-2026-69625CVE-2026-696258.0 HighUpdated
2026-09-21CVE-2026-69617CVE-2026-696177.0 HighUpdated
2026-09-21CVE-2026-69606CVE-2026-696067.0 HighUpdated
2026-09-21CVE-2026-69602CVE-2026-696027.1 HighUpdated
2026-09-21CVE-2026-69597CVE-2026-695977.1 HighUpdated
2026-09-21CVE-2026-69586CVE-2026-695869.8 CriticalUpdated
2026-09-21CVE-2026-69575CVE-2026-695757.0 HighUpdated
2026-09-21CVE-2026-54230CVE-2026-542307.0 HighUpdated
2026-09-20CVE-2026-87886Acronis Backup's Incorrect Default Permissions Allow a Local Attacker to Access Backup Files and Configurations Not Intended for Their Account; CISA's September 19th KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-84869ConnectWise ScreenConnect's Improper Privilege Management and Missing Authorization Allow Unauthenticated Attackers to Gain Administrative Control of the Remote Support Platform; CISA's September 14th KEV Deadline Has Passed9.9 CriticalKEV
2026-09-20CVE-2026-81963Microsoft Windows' Improper Link Resolution Before File Access Allows a Local Attacker to Follow Symbolic Links to Privileged Files and Gain Elevated Access; CISA's September 22nd KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-67277MikroTik RouterOS's Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Access and Modify Router Configuration; CISA's September 13th KEV Deadline Has Passed8.2 HighKEV
2026-09-20CVE-2026-53362Linux Kernel's Unspecified Flaw Allows Local Attackers to Gain Elevated Privileges on Affected Systems; CISA's August 30th KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-53266Linux Kernel's Out-of-Bounds Write Vulnerability Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 21st KEV Deadline Has Passed8.8 HighKEV
2026-09-20CVE-2026-50516Microsoft Azure Kubernetes Service's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Interact with Privileged Cluster Management Endpoints9.4 CriticalUpdated
2026-09-20CVE-2026-20349Cisco Secure Firewall ASA and FTD's Heap Inspection Vulnerability Allows Remote Attackers to Extract Sensitive Memory Contents from the Firewall Device; CISA's August 14th KEV Deadline Has Passed8.6 HighKEV
2026-09-20CVE-2026-20301Cisco IOS XE's Unchecked Loop Condition Input Allows Network-Accessible Devices to Be Crashed via a Specially Crafted Packet8.6 HighExploited
2026-09-20CVE-2026-20124Cisco IOS XE's Memory Resource Leak Allows Remote Attackers to Exhaust Device Memory and Cause a Denial of Service via Repeated Packet Transmission7.7 HighExploited
2026-09-20CVE-2026-72530TrueConf Server's Code Injection Vulnerability Allows Remote Attackers to Execute Arbitrary Code on the Video Conferencing Platform; CISA's September 3rd KEV Deadline Has Passed9.0 CriticalKEV
2026-09-20CVE-2026-72529TrueConf Server's Missing Authentication on a Critical Function Allows Unauthenticated Remote Attackers to Access Administrative Capabilities; CISA's August 23rd KEV Deadline Has Passed9.8 CriticalKEV
2026-09-18CVE-2026-87491Google Chromium V8's Out-of-Bounds Write Allows Remote Attackers to Corrupt the JavaScript Engine's Heap and Execute Arbitrary Code via a Crafted Web Page8.8 HighKEV
2026-09-18CVE-2026-59822BerriAI LiteLLM's Improper Authentication Allows Unauthenticated Attackers to Access the AI Model Gateway and Interact with Configured LLM Endpoints Without Credentials8.2 HighKEV
2026-09-18CVE-2026-58704Google Pixel's Improper Authorization Flaw Allows an Attacker with Physical or Local Access to Bypass Permission Controls and Access Protected Device Functions8.8 HighKEV
2026-09-18CVE-2026-49869Kestra OSS's OS Command Injection Flaw Lets Unauthenticated Remote Attackers Execute Arbitrary Commands on the Workflow Orchestration Server with Full System Privileges10.0 CriticalKEV
2026-09-18CVE-2026-27563Crafted GET Request to the Datastorage API Lets Admin Credentials Trigger Root Command Execution on Pepperl+Fuchs ICE-Series IO-Link Masters7.2 HighUpdated
2026-09-18CVE-2026-27558Operator Access to the IODD File Removal Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Allows Root Command Injection8.8 HighUpdated
2026-09-18CVE-2026-27548Command Injection in the IODD Port Info Endpoint Grants Root Access on Pepperl+Fuchs ICE-Series IO-Link Masters to Any User or Operator Account8.8 HighUpdated
2026-09-16CVE-2026-27565Unauthenticated IODD File Upload on Pepperl+Fuchs ICE-Series IO-Link Masters Executes a Root Shell Script That Persists Across Reboots9.8 CriticalUpdated
2026-09-16CVE-2026-27564Pepperl+Fuchs ICE-Series IO-Link Masters Run Injected Root Commands When Admin Credentials Submit a Crafted PUT Request to the Datastorage API7.2 HighUpdated
2026-09-16CVE-2026-27562Admin-Level PUT Requests to the IODD Configuration API Execute Injected Commands as Root on Pepperl+Fuchs ICE-Series IO-Link Masters7.2 HighUpdated
2026-09-16CVE-2026-27561Admin Credentials Enable Root Command Injection via the IODD Config GET API on Pepperl+Fuchs ICE-Series IO-Link Masters7.2 HighUpdated
2026-09-16CVE-2026-27560Admin-Credentialed DELETE Requests to Pepperl+Fuchs ICE-Series IO-Link Masters' Status API Carry Injected Commands Executed at Root7.2 HighUpdated
2026-09-16CVE-2026-27559User Credentials Are Enough to Inject Root-Level Commands via the Status Data API on Pepperl+Fuchs ICE-Series IO-Link Masters8.8 HighUpdated
2026-09-16CVE-2026-27557Unauthenticated Path Traversal in Pepperl+Fuchs ICE-Series IO-Link Masters Exposes the Device's SSH Server Private Keys7.5 HighUpdated
2026-09-16CVE-2026-27556Operator Cookie Enables Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Parameter Save Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27555A Valid User Cookie Triggers Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Port Info Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27554IODD Parameter Save Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Accepts Injected Commands from Operator-Level Accounts, Yielding Root Access8.8 HighUpdated
2026-09-16CVE-2026-27552Pepperl+Fuchs ICE-Series IO-Link Masters Allow Low-Privileged Users to Upload Arbitrary IODD Files via a Missing Authorization Check, Enabling Device Manipulation or Crashes8.1 HighUpdated
2026-09-16CVE-2026-27551User-Level Credentials Give Root Shell on Pepperl+Fuchs ICE-Series IO-Link Masters via the Parameter Management Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27550Operator Credentials Can Inject Root-Level OS Commands via the Field_Shadow_Password Handler on Pepperl+Fuchs ICE-Series IO-Link Masters8.8 HighUpdated
2026-09-16CVE-2026-27549Operator-Level Credentials Suffice to Run Root Commands on Pepperl+Fuchs ICE-Series IO-Link Masters via the IODD Upload Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27547IODD Menu Info Request on Pepperl+Fuchs ICE-Series IO-Link Masters Passes Unvalidated Parameters to Root-Level Commands, Reachable with User-Level Credentials8.8 HighUpdated
2026-09-16CVE-2026-27546The _account_log Function in Pepperl+Fuchs ICE-Series IO-Link Masters Lets Unauthenticated Attackers Log In as Admin Regardless of Account Configuration9.8 CriticalUpdated
2026-09-11CVE-2026-63298LXD NVIDIA Instance Configuration Handler Accepts Newline Characters in nvidia.driver.capabilities and nvidia.require.* Values, Letting Authenticated Attackers Inject Arbitrary Directives into the GPU Configuration9.9 CriticalUpdated
2026-09-10CVE-2026-32589Red Hat Quay authenticated push access enables interference with other users' in-progress image uploads across repositories7.4 HighUpdated
2026-08-13CVE-2026-64125Linux Kernel bcmgenet Driver Enabling RBUF EEE and PM Bits Stops RX Traffic When MAC EEE Activates, Causing a Denial-of-Service Condition on Broadcom GENET Hardware9.8 CriticalUpdated
2026-07-28CVE-2026-16812Arista VeloCloud Orchestrator On-Prem Management Plane Executes Injected OS Commands; CISA's July 30th KEV Deadline Has Passed for Covered Entities10.0 CriticalKEV
2026-07-24CVE-2026-31405Linux Kernel DVB-net ULE Extension Handler Uses a Network-Controlled Index into a 255-Entry Table Without Bounds Checking, Enabling Out-of-Bounds Reads and Writes9.8 CriticalUpdated
2026-07-24CVE-2026-23458Linux kernel ctnetlink multi-round dump dereferences freed conntrack pointer in second callback invocation7.8 HighUpdated
2026-07-24CVE-2026-23450Linux Kernel SMC-over-TCP SYN Receive Path Calls sock_hold Then Schedules a tcp_close Work Item Without Synchronizing Against Concurrent Stack Cleanup, Enabling Use-After-Free and Null Dereference9.8 CriticalUpdated
2026-07-24CVE-2026-23419Linux kernel rds_tcp_tune circular locking dependency causes deadlock via sk_net_refcnt_upgrade7.5 HighUpdated
2026-07-23CVE-2026-54420LiteSpeed's cPanel Plugin Follows Symlinks Across Security Boundaries to Escalate Privileges; CISA's June 18th KEV Remediation Window Has Closed for Covered Entities8.5 HighKEV
2026-07-23CVE-2026-42542CVE-2026-425427.5 HighUpdated
2026-07-15CVE-2026-56155Microsoft Active Directory Federation Services Insufficient Access Control Allows an Authorized Attacker to Elevate Privileges Locally; CISA's July 28th KEV Deadline Has Passed7.8 HighKEV
2026-07-14CVE-2026-31446Linux kernel ext4 use-after-free in update_super_work races with unmount after sysfs unregistration7.8 HighUpdated
2026-07-08CVE-2026-46279Linux Kernel Page Extension Initialization Leaves Codetag Uninitialized for Pages Allocated Before page_ext Is Ready7.8 HighUpdated
2026-07-02CVE-2026-53225Linux Kernel SCTP ASCONF Lookup Reads Past the Validated Header Boundary, Exposing Uninitialized Memory to Downstream Address Parameter Processing9.1 CriticalUpdated
2026-06-17CVE-2026-8398Daemon Tools Lite Contains Embedded Malicious Code; CISA Added It to KEV with a May 30th Deadline That Has Since Passed for Covered Entities9.8 CriticalKEV
2026-06-17CVE-2026-7473Arista Extensible Operating System Validation Bypass Added to CISA's Known Exploited Vulnerabilities List; Federal Remediation Window for Covered Entities Closed June 23rd5.8 MediumKEV
2026-06-17CVE-2026-48027Nx Console Developer Tooling Published Packages Contain Embedded Malicious Code; CISA's June 10th KEV Mandate for Covered Entities Has Passed9.8 CriticalKEV
2026-06-17CVE-2026-45321TanStack JavaScript Library Suite Added to CISA's Known Exploited Vulnerabilities Catalog; Federal Remediation Deadline for Covered Entities Was June 10th9.6 CriticalKEV
2026-06-17CVE-2026-43296Linux Kernel octeontx2-af NIC SQ Manager Sticky Mode Causes Stalls and Potential PSE Deadlock When Multiple Queues Share an SMQ7.5 HighUpdated
2026-06-17CVE-2026-4116SonicWall SMA1000 Mishandles Unicode Encoding in TOTP Validation, Allowing an Authenticated SSLVPN User to Bypass Two-Factor Authentication7.2 HighUpdated
2026-06-17CVE-2026-4113SonicWall SMA1000 Distinguishable Authentication Error Responses Allow a Remote Attacker to Enumerate SSL VPN User Accounts7.2 HighUpdated
2026-06-17CVE-2026-4112SonicWall SMA1000 SQL Injection in the SSLVPN Component Allows a Read-Only Administrator to Escalate to Primary Administrator7.2 HighUpdated
2026-06-17CVE-2026-31693Linux kernel CIFS replay path missing variable reinitializations causes undefined behavior on request retry7.8 HighUpdated
2026-06-17CVE-2026-31568Linux kernel s390/mm missing secure storage access fixups for donated pages causes kernel context exceptions7.1 HighUpdated
2026-06-17CVE-2026-31426Linux kernel ACPI EC address space handler persists after probe failure leaves dangling pointer7.0 HighUpdated
2026-06-17CVE-2026-23406Linux kernel AppArmor match_char macro evaluates pointer multiple times and skips input characters during DFA traversal7.8 HighUpdated
2026-06-17CVE-2026-1952Delta Electronics AS320T Denial of Service via Undocumented Subfunction Call, Exploitable Remotely Without Authentication9.8 CriticalUpdated
2026-06-17CVE-2026-1951Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing Directory Name Length Check, Enabling Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-06-17CVE-2026-1950Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing File Name Length Check, Enabling Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-06-17CVE-2026-1949Delta Electronics AS320T GET/PUT Request Handler Incorrectly Calculates Stack Buffer Size, Enabling Unauthenticated Remote Code Execution via the Web Service9.8 CriticalUpdated

No advisories match this filter.