Critical Infrastructure Vulnerability Intelligence

Advisories for Industrial Defenders

Compiled, structured vulnerability reports for operational technology and industrial control system security teams.

114
KEV Listed
117
Exploited
4
EPSS-Imminent
699
Total Advisories
Filter by Sector
ChemicalCommercialCommunicationsManufacturingDamsDefense IndustrialEmergency SvcsEnergyFinancial SvcsFood & AgGovernmentHealthcareInfo TechnologyNuclearTransportationWater
Filter by Status
FromToShow
UpdatedAdvisory IDTitleCVSSStatus
2026-10-03CVE-2026-86060MikroTik RouterOS's Argument Injection in a Command-Processing Component Allows Unauthenticated Attackers to Execute Arbitrary Commands on the Router; CISA's September 13th KEV Deadline Has Passed9.8 CriticalKEV
2026-10-03CVE-2026-85102Check Point Firewall Certificate Validation Bypass Across Site-to-Site and Remote Access VPN Carries a Lapsed September 25th CISA KEV Requirement for Covered Entities9.8 CriticalKEV
2026-10-03CVE-2026-82078PaperCut NG/MF's Unsafe Reflection Allows Remote Attackers to Manipulate Class Loading and Execute Arbitrary Code on the Print Management Server; CISA's September 14th KEV Deadline Has Passed9.1 CriticalKEV
2026-10-03CVE-2026-67276CVE-2026-672768.1 HighEPSS-Imminent
2026-10-03CVE-2026-20181CVE-2026-201819.1 CriticalEPSS-Imminent
2026-10-03CVE-2026-98154Linux Kernel nvme-rdma: Failure to Fix -EIO cleanup order in queue_rq7.0 HighUpdated
2026-10-03CVE-2026-98130Linux Kernel sctp: Failure to Fix a TOCTOU race in SCTP_CMD_TIMER_START, Reachable from the Network Without Credentials (CVSS 8.1)8.1 HighUpdated
2026-10-03CVE-2026-98122Linux Kernel vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()7.8 HighUpdated
2026-10-03CVE-2026-98116Linux Kernel ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF7.8 HighUpdated
2026-10-03CVE-2026-98108Linux Kernel Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan7.5 HighUpdated
2026-10-03CVE-2026-98096Linux Kernel ipv6: sr: restore network header before routing and forwarding, Reachable from the Network Without Credentials (CVSS 7.4)7.4 HighUpdated
2026-10-03CVE-2026-98083Linux Kernel btrfs: Failure to Fix transaction use-after-free in raid stripe insertion7.0 HighUpdated
2026-10-03CVE-2026-98070Linux Kernel net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks(), Reachable from the Network Without Credentials (CVSS 8.1)8.1 HighUpdated
2026-10-03CVE-2026-98069Linux Kernel net/rds: acquire the fastpath locks in rds_conn_shutdown(), Reachable from the Network Without Credentials (CVSS 8.1)8.1 HighUpdated
2026-10-03CVE-2026-98052Linux Kernel net: bcmasp: clear txcb->last before writing each descriptor7.8 HighUpdated
2026-10-03CVE-2026-98030Linux Kernel net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size7.0 HighUpdated
2026-10-03CVE-2026-98027Linux Kernel net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size7.0 HighUpdated
2026-10-03CVE-2026-98023Linux Kernel vxlan: reject dynamic fdb entries that reference a nexthop id7.8 HighUpdated
2026-10-03CVE-2026-98017Linux Kernel net/sched: defer qdisc freeing after failed creation7.8 HighUpdated
2026-10-03CVE-2026-97991Linux Kernel vdpa_sim_blk: reject out-of-range sector starts7.8 HighUpdated
2026-10-03CVE-2026-97990Linux Kernel vdpa_sim_net: Failure to Check TX pull result before RX copy7.5 HighUpdated
2026-10-03CVE-2026-97957Linux Kernel net: hinic: fix mailbox segment buffer overflow8.8 HighUpdated
2026-10-03CVE-2026-97509Linux Kernel thunderbolt: Keep XDomain reference during the lifetime of a service8.8 HighUpdated
2026-10-03CVE-2026-97508Linux Kernel thunderbolt: Set tb->root_switch to NULL when domain is stopped7.5 HighUpdated
2026-10-03CVE-2026-97497Linux Kernel drm/amdkfd: Failure to Check bounds for allocate_sdma_queue restore_sdma_id7.8 HighUpdated
2026-10-03CVE-2026-97496Linux Kernel drm/amdkfd: Failure to Fix OOB memory exposure in get_wave_state()7.1 HighUpdated
2026-10-03CVE-2026-97455Linux Kernel ACPICA: Failure to Fix use-after-free in acpi_ds_terminate_control_method()8.4 HighUpdated
2026-10-03CVE-2026-97454Linux Kernel ACPICA: Failure to Add boundary checks in acpi_ps_get_next_field()7.7 HighUpdated
2026-10-03CVE-2026-97452Linux Kernel ACPICA: Failure to Prevent adding invalid references8.4 HighUpdated
2026-10-03CVE-2026-97451Linux Kernel ACPICA: Failure to Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)8.4 HighUpdated
2026-10-03CVE-2026-97450Linux Kernel ACPICA: Failure to Validate handler object type in two places8.4 HighUpdated
2026-10-03CVE-2026-97448Linux Kernel ACPICA: Failure to Add validation for node in acpi_ns_build_normalized_path()7.7 HighUpdated
2026-10-03CVE-2026-93196Linux Kernel nvdimm: virtio_pmem: refcount requests for token lifetime8.4 HighUpdated
2026-10-03CVE-2026-90030Linux Kernel usb: dwc3: clear forceRM when issuing EndTransfer7.8 HighUpdated
2026-10-03CVE-2026-90016Linux Kernel staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()7.1 HighUpdated
2026-10-03CVE-2026-90013Linux Kernel tracing: Take trace_array reference when opening options file7.8 HighUpdated
2026-10-03CVE-2026-90002Linux Kernel ftrace: Take trace_array reference before accessing its ftrace_ops7.8 HighUpdated
2026-10-03CVE-2026-89972Linux Kernel nvme: Failure to Add missing SRCU grace period in error path, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-10-03CVE-2026-89971Linux Kernel nvme: skip the zoned limits update if the zone info query failed, Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-10-03CVE-2026-89840Linux Kernel f2fs: Failure to Validate MOVE_RANGE destination size7.1 HighUpdated
2026-10-03CVE-2026-89838Linux Kernel f2fs: limit recovery filename logging to stored length7.1 HighUpdated
2026-10-03CVE-2026-89832Linux Kernel f2fs: Failure to Fix to clear dirty flag on folio in error path7.8 HighUpdated
2026-10-03CVE-2026-89806Linux Kernel drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation8.4 HighUpdated
2026-10-03CVE-2026-89795Linux Kernel PCI: Allow per function PCI slots to fix slot reset on s3908.4 HighUpdated
2026-10-03CVE-2026-89792Linux Kernel ksmbd: Failure to Prevent out-of-bounds reads in share config responses7.1 HighUpdated
2026-10-03CVE-2026-89560Linux Kernel landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation8.4 HighUpdated
2026-10-03CVE-2026-89520Linux Kernel sched/core: Make core-sched flips wait for in-flight selections7.8 HighUpdated
2026-10-03CVE-2026-89503Linux Kernel ring-buffer: Failure to Fix subbuf resize race with ring_buffer_alloc_read_page()7.8 HighUpdated
2026-10-03CVE-2026-89500Linux Kernel ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page7.8 HighUpdated
2026-10-03CVE-2026-89452Linux Kernel iommu/msm: Unwind probe state on registration failure8.4 HighUpdated
2026-10-03CVE-2026-89445Linux Kernel iommufd: Failure to Fix UAF in selftest IOPF reporting8.8 HighUpdated
2026-10-03CVE-2026-89441Linux Kernel mmc: via-sdmmc: cancel card-detect work on remove7.8 HighUpdated
2026-10-03CVE-2026-81016Linux Kernel platform/x86/amd/pmc: Propagate SMU errors and validate S2D address7.7 HighUpdated
2026-10-03CVE-2026-81015Linux Kernel platform/x86/amd/pmc: Failure to Fix LPS0 and debugfs leaks when STB init fails7.8 HighUpdated
2026-10-03CVE-2026-80980Linux Kernel net/smc: stop killed, freed and out_of_sync sharing a byte, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-10-03CVE-2026-80937Linux Kernel wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy8.8 HighUpdated
2026-10-03CVE-2026-80935Linux Kernel wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy8.8 HighUpdated
2026-10-03CVE-2026-80926Linux Kernel ksmbd: Failure to Fix use-after-free in oplock break notification, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-10-03CVE-2026-80726Linux Kernel KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (CVSS 9.3)9.3 CriticalUpdated
2026-10-03CVE-2026-80521Linux Kernel af_unix: Unlink scc_entry in unix_del_edge()7.8 HighUpdated
2026-10-03CVE-2026-76504CVE-2026-76504: Cisco Catalyst SD-WAN Manager9.8 CriticalKEV
2026-10-03CVE-2026-74743Linux Kernel macvlan: inherit needed_headroom and needed_tailroom from lowerdev, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-10-03CVE-2026-74521Linux Kernel ksmbd: Failure to Use memcmp() to compare ClientGUIDs, Reachable Without Authentication (CVSS 9.1)9.1 CriticalUpdated
2026-10-03CVE-2026-74496Linux Kernel fou: Failure to Fix use-after-free in fou_create()7.8 HighUpdated
2026-10-03CVE-2026-74347Linux Kernel netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount7.8 HighUpdated
2026-10-03CVE-2026-74294Linux Kernel ASoC: meson: aiu: Validate written enum values7.3 HighUpdated
2026-10-03CVE-2026-74289Linux Kernel ipv4: fib: Don't dump dying fib_info in fib_leaf_notify()7.8 HighUpdated
2026-10-03CVE-2026-74258Linux Kernel bpf: Guard __get_user acesss with access_ok for uprobe_multi data7.8 HighUpdated
2026-10-03CVE-2026-72496Linux Kernel RDMA/bnxt_re: Proper rollback if the ioremap fails (CVSS 9.2)9.2 CriticalUpdated
2026-10-03CVE-2026-72485Linux Kernel coresight: platform: defer connection counter increment until alloc succeeds7.8 HighUpdated
2026-10-03CVE-2026-72334CVE-2026-723348.8 HighUpdated
2026-10-03CVE-2026-68391Linux Kernel Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds7.8 HighUpdated
2026-10-03CVE-2026-68287Linux Kernel drop_monitor: Failure to Fix size calculations for 64-bit attributes, Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-10-03CVE-2026-68236CVE-2026-682367.8 HighUpdated
2026-10-03CVE-2026-68161Linux Kernel sctp: close UDP tunnel sockets during netns teardown, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-10-03CVE-2026-68155Linux Kernel libceph: Reject monmaps advertising zero monitors, Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-10-03CVE-2026-68097CVE-2026-680978.8 HighUpdated
2026-10-03CVE-2026-53359CVE-2026-533598.8 HighUpdated
2026-10-03CVE-2026-53005Linux Kernel AF_UNIX SOCKMAP Redirect Hides Inflight File Descriptors from the Garbage Collector, Leaking Inflight Sockets Indefinitely7.8 HighUpdated
2026-10-03CVE-2026-52988CVE-2026-529887.1 HighUpdated
2026-10-03CVE-2026-46242CVE-2026-462427.8 HighUpdated
2026-10-03CVE-2026-46113Linux Kernel KVM: x86: Fix shadow paging use-after-free due to unexpected GFN8.8 HighUpdated
2026-10-03CVE-2026-20273Cisco IOS XE's Improper Input Validation Allows a Remote Attacker to Trigger a Device Crash or Disruption via a Specially Crafted Input8.6 HighUpdated
2026-10-03CVE-2026-20272Cisco IOS XE's Injection Flaw Allows Remote Attackers to Execute Arbitrary Commands via a Specially Crafted Input Reaching a Downstream Component9.8 CriticalUpdated
2026-10-03CVE-2026-20271Cisco IOS XE's Insufficient Control Flow Management Allows a Remote Attacker to Disrupt Device Operation via a Crafted Packet8.6 HighUpdated
2026-10-03CVE-2026-20270Cisco IOS XE's Incorrect Calculation Vulnerability Allows a Remote Attacker to Cause an Unrecoverable Device Condition via a Specially Crafted Input8.6 HighUpdated
2026-10-03CVE-2026-20269Cisco IOS XE's Improper Resource Lifetime Management Allows Remote Attackers to Exhaust Device Resources and Cause a Denial of Service8.6 HighUpdated
2026-10-03CVE-2026-20268Cisco IOS XE's Improper Restriction of Memory Buffer Operations Allows Remote Attackers to Potentially Execute Code or Crash the Device via a Malformed Packet8.6 HighUpdated
2026-10-03CVE-2026-20267Cisco IOS XE's Improper Access Control Allows Network-Based Attackers to Access Protected Functions or Data Without Proper Authorization9.0 CriticalUpdated
2026-10-02CVE-2026-98163CVE-2026-981637.0 HighUpdated
2026-10-02CVE-2026-98115CVE-2026-981158.8 HighUpdated
2026-10-02CVE-2026-97415CVE-2026-974157.8 HighUpdated
2026-10-02CVE-2026-86326CVE-2026-863268.6 HighUpdated
2026-10-02CVE-2026-86325CVE-2026-863259.4 CriticalUpdated
2026-10-02CVE-2026-84411CVE-2026-844119.8 CriticalUpdated
2026-10-02CVE-2026-75937CVE-2026-759379.4 CriticalUpdated
2026-10-02CVE-2026-71452CVE-2026-714527.2 HighUpdated
2026-10-02CVE-2026-71449CVE-2026-714499.3 CriticalUpdated
2026-10-02CVE-2026-64893CVE-2026-648937.3 HighUpdated
2026-10-02CVE-2026-64008CVE-2026-640087.8 HighUpdated
2026-10-02CVE-2026-64001CVE-2026-640017.8 HighUpdated
2026-10-02CVE-2026-63996CVE-2026-639967.8 HighUpdated
2026-10-02CVE-2026-63993CVE-2026-639939.8 CriticalUpdated
2026-10-02CVE-2026-63975CVE-2026-639758.8 HighUpdated
2026-10-02CVE-2026-63972CVE-2026-639727.5 HighUpdated
2026-10-02CVE-2026-63971CVE-2026-639717.8 HighUpdated
2026-10-02CVE-2026-63970CVE-2026-639707.8 HighUpdated
2026-10-02CVE-2026-58016CVE-2026-580167.5 HighUpdated
2026-10-02CVE-2026-58014CVE-2026-580147.3 HighUpdated
2026-10-02CVE-2026-55396CVE-2026-553968.5 HighUpdated
2026-10-02CVE-2026-55395CVE-2026-553959.4 CriticalUpdated
2026-10-02CVE-2026-55393CVE-2026-5539310.0 CriticalUpdated
2026-10-02CVE-2026-48864CVE-2026-488647.8 HighUpdated
2026-10-02CVE-2026-42010CVE-2026-420107.1 HighUpdated
2026-10-02CVE-2026-42009CVE-2026-420097.5 HighUpdated
2026-10-02CVE-2026-34494CVE-2026-344947.2 HighUpdated
2026-10-02CVE-2026-34493CVE-2026-344937.2 HighUpdated
2026-10-02CVE-2026-33845CVE-2026-338457.5 HighUpdated
2026-10-02CVE-2026-17523CVE-2026-175237.8 HighUpdated
2026-10-02CVE-2026-14984CVE-2026-149849.4 CriticalUpdated
2026-10-02CVE-2026-14983CVE-2026-149837.1 HighUpdated
2026-10-02CVE-2026-104286CVE-2026-104286: Fortinet FortiMail Path9.8 CriticalKEV
2026-10-02CVE-2026-102490CVE-2026-102490: Zammad GmbH Zammad Improper9.8 CriticalKEV
2026-10-02CVE-2026-102489CVE-2026-102489: Zammad GmbH Zammad Session9.8 CriticalKEV
2026-10-02CVE-2026-100075CVE-2026-1000759.8 CriticalUpdated
2026-10-01CVE-2026-8037Progress LoadMaster's Command Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary OS Commands on the Load Balancer Appliance; CISA's August 10th KEV Deadline Has Passed9.6 CriticalKEV
2026-10-01CVE-2026-69594CVE-2026-695947.8 HighUpdated
2026-10-01CVE-2026-69576CVE-2026-695767.8 HighUpdated
2026-10-01CVE-2026-69549CVE-2026-695497.0 HighUpdated
2026-10-01CVE-2026-69546CVE-2026-695468.1 HighUpdated
2026-10-01CVE-2026-69541CVE-2026-695417.8 HighUpdated
2026-10-01CVE-2026-69524CVE-2026-695248.1 HighUpdated
2026-10-01CVE-2026-48710Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections6.5 MediumKEV
2026-10-01CVE-2026-42965CVE-2026-429657.7 HighUpdated
2026-10-01CVE-2026-3012CVE-2026-30128.0 HighUpdated
2026-10-01CVE-2026-1784CVE-2026-17848.8 HighUpdated
2026-10-01CVE-2025-41753CVE-2025-417539.8 CriticalUpdated
2026-09-30CVE-2026-41940WebPros cPanel and WHM's Login Flow Authentication Bypass Gives Unauthenticated Attackers Unauthorized Access to the Control Panel; CISA's May 3rd KEV Deadline Has Passed9.8 CriticalKEV
2026-09-28CVE-2026-20263Cisco IOS XE BEEP SOAP request parsing flaw causes unexpected device reload8.6 HighUpdated
2026-09-26CVE-2026-80152Lantronix SLC8000, SLC9000, EMG, and SLB Series Set Script Schedule Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root9.1 CriticalUpdated
2026-09-26CVE-2026-80151Lantronix SLC8000, SLC9000, EMG, and SLB Series Set NFS Download Command Passes Unsanitized Input to system(), Enabling Authenticated Users with Services Permission to Run Arbitrary Commands as Root9.1 CriticalUpdated
2026-09-26CVE-2026-80150Lantronix Serial Console Servers Allow Unauthenticated Attackers to Redirect WebTelnet Connections to Arbitrary Hosts via a Tampered rooturl Parameter7.5 HighUpdated
2026-09-26CVE-2026-80149Lantronix Serial Console Servers Allow Unauthenticated Attackers to Redirect WebSSH Connections to Arbitrary Hosts via a Tampered rooturl Parameter8.6 HighUpdated
2026-09-26CVE-2026-80148Overlong Username in Lantronix Serial Console Server WebSSH Truncates the Device IP Suffix in snprintf, Redirecting SSH Connections to Attacker-Controlled Hosts8.6 HighUpdated
2026-09-26CVE-2026-80146Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root9.9 CriticalUpdated
2026-09-26CVE-2026-67279MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 286.5 MediumKEV
2026-09-25CVE-2026-93616Path Traversal Across Check Point Management and Log Server Infrastructure Missed the September 25th CISA KEV Window; Covered Organizations Are Now Out of Compliance9.8 CriticalKEV
2026-09-25CVE-2026-85046Google Chromium V8's Type Confusion Allows Remote Attackers to Execute Arbitrary Code or Escape the Browser Sandbox via a Crafted Web Page8.8 HighKEV
2026-09-25CVE-2026-81578PaperCut NG/MF's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Perform Administrative Actions Without Logging In; CISA's September 14th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-25CVE-2026-76461Cisco Secure Email Gateway's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Compromise the Email Security Platform9.8 CriticalKEV
2026-09-25CVE-2026-76460Cisco Identity Services Engine's Incorrect Use of Privileged APIs Allows Unauthenticated Remote Attackers to Gain Full Administrative Control; CISA's September 19th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-25CVE-2026-75650Adobe Commerce and Magento's Template Engine Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Server-Side Code on the E-Commerce Platform10.0 CriticalKEV
2026-09-25CVE-2026-97941CVE-2026-979417.8 HighUpdated
2026-09-25CVE-2026-97940CVE-2026-979407.8 HighUpdated
2026-09-25CVE-2026-97937CVE-2026-979377.8 HighUpdated
2026-09-25CVE-2026-97931CVE-2026-979317.0 HighUpdated
2026-09-25CVE-2026-97926CVE-2026-979267.0 HighUpdated
2026-09-25CVE-2026-97911CVE-2026-979117.8 HighUpdated
2026-09-25CVE-2026-97910CVE-2026-979107.8 HighUpdated
2026-09-25CVE-2026-97903CVE-2026-979037.8 HighUpdated
2026-09-25CVE-2026-97612CVE-2026-976127.8 HighUpdated
2026-09-25CVE-2026-97611CVE-2026-976117.8 HighUpdated
2026-09-25CVE-2026-97609CVE-2026-976097.0 HighUpdated
2026-09-25CVE-2026-97608CVE-2026-976087.0 HighUpdated
2026-09-25CVE-2026-97602CVE-2026-976027.8 HighUpdated
2026-09-25CVE-2026-97595CVE-2026-975957.5 HighUpdated
2026-09-25CVE-2026-97594CVE-2026-975947.8 HighUpdated
2026-09-25CVE-2026-97589CVE-2026-975897.0 HighUpdated
2026-09-25CVE-2026-97584CVE-2026-975847.8 HighUpdated
2026-09-25CVE-2026-97583CVE-2026-975837.5 HighUpdated
2026-09-25CVE-2026-97580CVE-2026-975807.8 HighUpdated
2026-09-25CVE-2026-97579CVE-2026-975797.8 HighUpdated
2026-09-25CVE-2026-97578CVE-2026-975787.8 HighUpdated
2026-09-25CVE-2026-97577CVE-2026-975777.8 HighUpdated
2026-09-25CVE-2026-97576CVE-2026-975767.8 HighUpdated
2026-09-25CVE-2026-97575CVE-2026-975757.8 HighUpdated
2026-09-25CVE-2026-97573CVE-2026-975738.1 HighUpdated
2026-09-25CVE-2026-97570CVE-2026-975708.1 HighUpdated
2026-09-25CVE-2026-97562CVE-2026-975627.5 HighUpdated
2026-09-25CVE-2026-97557CVE-2026-975577.5 HighUpdated
2026-09-25CVE-2026-97555CVE-2026-975558.8 HighUpdated
2026-09-25CVE-2026-97548CVE-2026-975487.8 HighUpdated
2026-09-25CVE-2026-97536CVE-2026-975367.5 HighUpdated
2026-09-25CVE-2026-97531CVE-2026-975317.5 HighUpdated
2026-09-25CVE-2026-97528CVE-2026-975288.8 HighUpdated
2026-09-25CVE-2026-97527CVE-2026-975278.8 HighUpdated
2026-09-25CVE-2026-97525CVE-2026-975258.2 HighUpdated
2026-09-25CVE-2026-97524CVE-2026-975247.5 HighUpdated
2026-09-25CVE-2026-97523CVE-2026-975237.5 HighUpdated
2026-09-25CVE-2026-97445CVE-2026-974457.7 HighUpdated
2026-09-25CVE-2026-97444CVE-2026-974447.7 HighUpdated
2026-09-25CVE-2026-97442CVE-2026-974428.8 HighUpdated
2026-09-25CVE-2026-97438CVE-2026-974387.1 HighUpdated
2026-09-25CVE-2026-97437CVE-2026-974377.1 HighUpdated
2026-09-25CVE-2026-97433CVE-2026-974338.2 HighUpdated
2026-09-25CVE-2026-97429CVE-2026-974297.8 HighUpdated
2026-09-25CVE-2026-97428CVE-2026-974287.7 HighUpdated
2026-09-25CVE-2026-97421CVE-2026-974217.8 HighUpdated
2026-09-25CVE-2026-97417CVE-2026-974177.5 HighUpdated
2026-09-25CVE-2026-97413CVE-2026-974139.8 CriticalUpdated
2026-09-25CVE-2026-97409CVE-2026-974098.8 HighUpdated
2026-09-25CVE-2026-93830CVE-2026-938307.5 HighUpdated
2026-09-25CVE-2026-93827CVE-2026-938278.4 HighUpdated
2026-09-25CVE-2026-93826CVE-2026-938267.5 HighUpdated
2026-09-25CVE-2026-93817CVE-2026-938177.8 HighUpdated
2026-09-25CVE-2026-93816CVE-2026-938167.1 HighUpdated
2026-09-25CVE-2026-93813CVE-2026-938137.8 HighUpdated
2026-09-25CVE-2026-93810CVE-2026-938107.0 HighUpdated
2026-09-25CVE-2026-93806CVE-2026-938068.8 HighUpdated
2026-09-25CVE-2026-93801CVE-2026-938017.0 HighUpdated
2026-09-25CVE-2026-93799CVE-2026-937998.8 HighUpdated
2026-09-25CVE-2026-93798CVE-2026-937987.8 HighUpdated
2026-09-25CVE-2026-93796CVE-2026-937967.0 HighUpdated
2026-09-25CVE-2026-93793CVE-2026-937938.8 HighUpdated
2026-09-25CVE-2026-93790CVE-2026-937908.8 HighUpdated
2026-09-25CVE-2026-93787CVE-2026-937878.1 HighUpdated
2026-09-25CVE-2026-93786CVE-2026-937868.1 HighUpdated
2026-09-25CVE-2026-93782CVE-2026-937827.8 HighUpdated
2026-09-25CVE-2026-93345MikroTik RouterOS Labelled-VPN NLRI Prefix-Length Underflow Holds the BGP Plane Down Indefinitely; Fix Is Only in a Development Build7.5 HighUpdated
2026-09-25CVE-2026-93288CVE-2026-932887.8 HighUpdated
2026-09-25CVE-2026-93287CVE-2026-932877.8 HighUpdated
2026-09-25CVE-2026-93284CVE-2026-932848.8 HighUpdated
2026-09-25CVE-2026-93282CVE-2026-932828.1 HighUpdated
2026-09-25CVE-2026-93280CVE-2026-932808.8 HighUpdated
2026-09-25CVE-2026-93277CVE-2026-932777.8 HighUpdated
2026-09-25CVE-2026-93265CVE-2026-932657.7 HighUpdated
2026-09-25CVE-2026-93262CVE-2026-932627.8 HighUpdated
2026-09-25CVE-2026-93260CVE-2026-932607.4 HighUpdated
2026-09-25CVE-2026-93250CVE-2026-932507.8 HighUpdated
2026-09-25CVE-2026-93237CVE-2026-932377.8 HighUpdated
2026-09-25CVE-2026-93229CVE-2026-932297.1 HighUpdated
2026-09-25CVE-2026-93228CVE-2026-932289.1 CriticalUpdated
2026-09-25CVE-2026-93225CVE-2026-932257.4 HighUpdated
2026-09-25CVE-2026-93224CVE-2026-932248.1 HighUpdated
2026-09-25CVE-2026-93221CVE-2026-932218.1 HighUpdated
2026-09-25CVE-2026-93207CVE-2026-932079.8 CriticalUpdated
2026-09-25CVE-2026-72463CVE-2026-724639.8 CriticalUpdated
2026-09-25CVE-2026-72315CVE-2026-723157.8 HighUpdated
2026-09-25CVE-2026-69458CVE-2026-694588.0 HighUpdated
2026-09-25CVE-2026-69456CVE-2026-694567.8 HighUpdated
2026-09-25CVE-2026-69455CVE-2026-694557.8 HighUpdated
2026-09-25CVE-2026-69451CVE-2026-694517.1 HighUpdated
2026-09-25CVE-2026-69448CVE-2026-694487.0 HighUpdated
2026-09-25CVE-2026-69447CVE-2026-694477.8 HighUpdated
2026-09-25CVE-2026-69445CVE-2026-694457.8 HighUpdated
2026-09-25CVE-2026-69444CVE-2026-694447.8 HighUpdated
2026-09-25CVE-2026-69441CVE-2026-694417.0 HighUpdated
2026-09-25CVE-2026-69440CVE-2026-694407.0 HighUpdated
2026-09-25CVE-2026-69436CVE-2026-694367.8 HighUpdated
2026-09-25CVE-2026-69434CVE-2026-694348.8 HighUpdated
2026-09-25CVE-2026-69433CVE-2026-694337.8 HighUpdated
2026-09-25CVE-2026-69396CVE-2026-693967.1 HighUpdated
2026-09-25CVE-2026-69394CVE-2026-693947.0 HighUpdated
2026-09-25CVE-2026-69392CVE-2026-693927.8 HighUpdated
2026-09-25CVE-2026-69391CVE-2026-693917.8 HighUpdated
2026-09-25CVE-2026-69389CVE-2026-693897.8 HighUpdated
2026-09-25CVE-2026-67281CVE-2026-672817.5 HighUpdated
2026-09-25CVE-2026-67278MikroTik RouterOS Accepts Malformed RSA/PKCS#1 v1.5 Signatures Across TLS and SSH, and Its Trust Store Includes an e=3 Root CA, Letting a Network Attacker Forge Valid Signatures Without the Private Key9.1 CriticalUpdated
2026-09-25CVE-2026-5430WSO2 API Gateway Path Traversal Reaches Federal Remediation Deadline of September 2710.0 CriticalKEV
2026-09-25CVE-2026-33824Microsoft Windows IKE Service Extensions' Double Free Enables Unauthenticated Remote Attackers to Execute Arbitrary Code; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-25CVE-2026-32157CVE-2026-321578.8 HighUpdated
2026-09-25CVE-2026-26174CVE-2026-261747.0 HighUpdated
2026-09-25CVE-2026-20190CVE-2026-201907.5 HighUpdated
2026-09-25CVE-2026-20147Critical Cisco ISE and ISE-PIC Command Injection Scores 9.99.9 CriticalEPSS-Imminent
2026-09-24CVE-2026-71474Red Hat insights-client logs a long-lived OpenShift pull-secret token that local pod-log access can expose7.1 HighUpdated
2026-09-24CVE-2026-54100Red Hat's Windows Machine Config Operator skips SSH host-key checks, letting adjacent attackers capture node bootstrap credentials8.3 HighUpdated
2026-09-24CVE-2026-54099A compromised Windows node can forge a cluster-administrator certificate through WMCO's CSR auto-approver, CVSS 8.88.8 HighUpdated
2026-09-24CVE-2026-4740Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation8.2 HighUpdated
2026-09-24CVE-2026-40141A critical query-injection flaw in BeyondTrust Remote Support lets low-privileged users reach unauthorized resources, CVSS 9.99.9 CriticalUpdated
2026-09-24CVE-2026-40140Unauthenticated attackers can crash BeyondTrust Remote Support appliances via a network-communication flaw7.5 HighUpdated
2026-09-24CVE-2026-40139Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access9.8 CriticalUpdated
2026-09-24CVE-2026-40138BeyondTrust Privileged Remote Access Shares Pre-Authentication Bypass Flaw with Remote Support8.1 HighUpdated
2026-09-24CVE-2026-33105Critical Authorization Bypass in Microsoft Azure Kubernetes Service Allows Network Privilege Escalation10.0 CriticalUpdated
2026-09-24CVE-2026-32590Unsafe Deserialization in Red Hat Quay Resumable Upload Handling7.1 HighUpdated
2026-09-24CVE-2026-32153Use-After-Free in Windows Speech Component Allows Local Privilege Escalation7.8 HighUpdated
2026-09-24CVE-2026-32091Race Condition in Microsoft Brokering File System Allows Unauthorized Privilege Escalation8.4 HighUpdated
2026-09-24CVE-2026-27914Improper Access Control in Microsoft Management Console Allows Local Privilege Escalation7.8 HighUpdated
2026-09-24CVE-2026-27909Use-After-Free in Windows Search Component Allows Authorized Attacker to Escalate Privileges7.8 HighUpdated
2026-09-24CVE-2026-26181Use-After-Free in Microsoft Brokering File System Lets Authorized User Escalate Privileges7.8 HighUpdated
2026-09-24CVE-2026-26170Input Validation Flaw in Microsoft PowerShell Allows Local Privilege Escalation7.8 HighUpdated
2026-09-24CVE-2026-23429Linux Kernel IOMMU SVA Use-After-Free in Unbind Path Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23428Critical Linux Kernel ksmbd Use-After-Free in Compound Request Handling Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-23427Critical Linux Kernel ksmbd Use-After-Free in Durable Handle Replay Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-23425Linux Kernel KVM arm64 ID Register Initialization Flaw Scores 8.88.8 HighUpdated
2026-09-24CVE-2026-23424Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.17.1 HighUpdated
2026-09-24CVE-2026-23422Linux Kernel dpaa2-switch Out-of-Bounds Write from Malformed Interrupt Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23415Linux Kernel Futex Use-After-Free between Key Lookup and VMA Policy Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23414Linux Kernel TLS Memory Leak in Async Decrypt Wait Scores 7.57.5 HighUpdated
2026-09-24CVE-2026-23413Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23412Linux Kernel Netfilter BPF Use-After-Free in Hook Memory Release Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23411Linux Kernel AppArmor Race Condition Frees i_private Data Early Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23410Linux Kernel AppArmor Race on Rawdata Dereference Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23408Linux Kernel AppArmor Double Free of Namespace Name Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-23407Linux Kernel AppArmor Out-of-Bounds Read in DFA Verification Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-22619Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-21662Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-20160Critical Cisco Smart Software Manager On-Prem Resource Exposure Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-20155Cisco Evolved Programmable Network Manager Missing Authorization Scores 8.08.0 HighUpdated
2026-09-24CVE-2026-20151Cisco Smart Software Manager On-Prem Leaks Sensitive Data in Transmitted Requests7.3 HighUpdated
2026-09-24CVE-2026-20094Cisco UCS Command Injection Scores 8.88.8 HighUpdated
2026-09-24CVE-2026-16443Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.47.4 HighUpdated
2026-09-24CVE-2026-0265Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.18.1 HighUpdated
2026-09-24CVE-2026-0264Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-0262Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE18087.5 HighUpdated
2026-09-24CVE-2026-0261Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.27.2 HighUpdated
2026-09-24CVE-2026-0258Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.19.1 CriticalUpdated
2026-09-24CVE-2026-89028MikroTik RouterOS SMB1 SessionSetupAndX Handler Integer Underflow in uniPwdLen Corrupts Adjacent Heap Memory7.5 HighUpdated
2026-09-24CVE-2026-85880Microsoft Windows' Heap-Based Buffer Overflow Allows Local Attackers to Escalate Privileges by Corrupting Heap Memory; CISA's September 22nd KEV Deadline Has Passed7.8 HighKEV
2026-09-24CVE-2026-80156Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Strips Backslash Characters but Not Forward Slashes During Path Validation, Letting Authenticated Attackers Write Files to Arbitrary Filesystem Locations9.1 CriticalUpdated
2026-09-24CVE-2026-80155Lantronix SLC8000, SLC9000, EMG, and SLB Series Upload Endpoint Requires No Authentication, Allowing Unauthenticated Attackers to Read Configuration Files and Upload to Arbitrary Filesystem Locations, Scoring CVSS 10.010.0 CriticalUpdated
2026-09-24CVE-2026-80154Lantronix SLC8000, SLC9000, EMG, and SLB Series Web Portal Derives Session Tokens Deterministically from Device Model and Current Second, Letting Unauthenticated Attackers Predict and Forge Valid Sessions on All Firmware Versions9.6 CriticalUpdated
2026-09-24CVE-2026-80147Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Copies Unbounded Input into a Stack Buffer Before system(), Enabling Authenticated Attackers to Execute Arbitrary Code as Root9.9 CriticalUpdated
2026-09-24CVE-2026-80145Lantronix SLC8000/SLC9000 and EMG Series Set CIFS Password Command Passes User Input Unsanitized to system(), Enabling Authenticated Users with Services Permission to Run Commands as Root9.1 CriticalUpdated
2026-09-24CVE-2026-80144Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom write Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution9.9 CriticalUpdated
2026-09-24CVE-2026-80143Lantronix SLC8000/SLC9000 and EMG Series Undocumented mfc eeprom read Command Passes Input Directly to system() via the CLI Interface, Reachable by Any Authenticated User for Root Command Execution9.9 CriticalUpdated
2026-09-24CVE-2026-69571Windows USB Audio Class driver (usbaudio.sys) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69567Windows NTFS Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69564Windows Online Certificate Status Protocol (OCSP) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69563Windows Program Compatibility Assistant Service Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69561Windows CD-ROM Driver Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69560Windows Work Folder Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69553Windows Hyper-V Missing authorization Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69551Windows DNS Use after free Lets Authorized Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69547Windows DHCP Server Heap-based buffer overflow Lets Authorized Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69544Windows SMB Client Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69542Windows Camera Frame Server Monitor Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69540Windows Audio Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69539Windows Remote Desktop Services Use after free Lets Authorized Attackers Execute Code over the Network (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-69538Windows Spaceport.sys Out-of-bounds read Lets Authorized Attackers Execute Code Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69535Windows Spaceport.sys Numeric Truncation Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.8 HighUpdated
2026-09-24CVE-2026-69534Windows Program Compatibility Assistant Service Command Injection Lets Authorized Attackers Escalate Privileges Locally7.8 HighUpdated
2026-09-24CVE-2026-69532Windows NTFS Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69525Windows Remote Desktop Services Use after free Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8)9.8 CriticalUpdated
2026-09-24CVE-2026-69518Windows Remote Desktop Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69514Windows Remote Desktop Services Heap-based buffer overflow Lets Authorized Attackers Execute Code over the Network (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-69511Microsoft Windows Media Foundation Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69510Windows DHCP Server Stack-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.1)8.1 HighUpdated
2026-09-24CVE-2026-69509Windows Fax Service Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69505Windows NTFS Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69500Windows Image Acquisition Use after free Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69500)7.0 HighUpdated
2026-09-24CVE-2026-69496Windows Compressed Folder Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8)9.8 CriticalUpdated
2026-09-24CVE-2026-69491Windows Microsoft DirectMusic Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8)9.8 CriticalUpdated
2026-09-24CVE-2026-69479Windows NTFS Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code Locally (CVSS 8.4)8.4 HighUpdated
2026-09-24CVE-2026-69475Windows Remote Desktop Services Untrusted Pointer Dereference Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69473Windows Kernel Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69466Windows Kernel TOCTOU Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69463Windows NTFS Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8)9.8 CriticalUpdated
2026-09-24CVE-2026-69461Windows NTFS Stack-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69450Windows Error Reporting Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69430Windows Embedded Mode Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69429Windows IKE Extension Heap-based buffer overflow Lets Authorized Attackers Execute Code over the Network (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-69428Windows LDAP - Lightweight Directory Access Protocol Out-of-bounds read Lets Unauthenticated Attackers Disclose Sensitive Information over the Network (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-69427Windows VOLSNAP.SYS Out-of-bounds read Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69426Windows VOLSNAP.SYS Heap-based buffer overflow Lets Authorized Attackers Execute Code Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69424Windows Distributed File System (DFS) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69423Windows USB Video Driver Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69421Windows Kernel Mode Driver Integer Underflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.8 HighUpdated
2026-09-24CVE-2026-69420Windows VOLSNAP.SYS Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69413Windows USB Audio Class driver (usbaudio.sys) Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69412Windows DHCP Server Stack-based buffer overflow Lets Authorized Attackers Execute Code (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69410Windows Win32K Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69408Microsoft Windows Media Foundation Integer overflow or wraparound Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8)9.8 CriticalUpdated
2026-09-24CVE-2026-69404Windows TCP/IP Race Condition Lets Authorized Attackers Execute Code over the Network (CVSS 8.1)7.0 HighUpdated
2026-09-24CVE-2026-69398Windows Bluetooth Service Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69397OpenSSH for Windows Use after free Lets Unauthenticated Attackers Execute Code over the Network (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-69388Windows Bluetooth Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69386Microsoft Windows Media Foundation Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69385Windows TCP/IP Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69383Windows Shell Arbitrary File Path Control Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69377Windows Modern Device Management (MDM) Missing authorization Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69371Windows Overlay Filter Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69368Windows Overlay Filter Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69366Windows Kernel Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69364Windows Print Spooler Components Race Condition Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69362Windows Error Reporting Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69357Windows NDIS Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69347Windows Fast FAT Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code Locally (CVSS 7.4)7.4 HighUpdated
2026-09-24CVE-2026-69346Windows Print Spooler Components Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69342Windows DHCP Server Out-of-bounds read Lets Unauthenticated Attackers Disclose Sensitive Information over the Network (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-69341Windows Image Acquisition Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69340Windows NTFS Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69337Windows Registry Double free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69335Windows Win32K Use after free Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69335)7.0 HighUpdated
2026-09-24CVE-2026-69334Windows Volume Manager Extension Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69332Windows NTFS Out-of-bounds read Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69331Windows Remote Access Connection Manager Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69328Windows Storage Untrusted search path Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69324Windows Performance Monitor Type Confusion Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.8 HighUpdated
2026-09-24CVE-2026-69322Microsoft Windows Search Component Double free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69319Windows USB Video Driver Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69312Windows NTFS Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69312)7.8 HighUpdated
2026-09-24CVE-2026-69311Windows Audio Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69310Windows DNS Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69309Windows Print Spooler Components Double free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69307Windows USB Audio Class driver (usbaudio.sys) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69305Microsoft Windows Search Component Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69301Windows Win32K Stack-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69300Windows Push Notifications Use after free Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69300)7.0 HighUpdated
2026-09-24CVE-2026-69299Microsoft COM for Windows Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69296Windows Device Association Service Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69295Windows USB Driver Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69291Windows Volume Manager Extension Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69290Windows Storage Spaces Controller Stack-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69289Windows Setup Files Cleanup Symbolic Link Following Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69287Windows Remote Desktop Services Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69284Windows DCOM Server Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69283Windows CD-ROM Driver Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69281Windows License Manager Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69280Windows Push Notifications Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69279Windows Cloud Files Mini Filter Driver Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69274Windows Win32K Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69270Windows USB Audio Class driver (usbaudio.sys) Heap-based buffer overflow Lets Authorized Attackers Execute Code Locally (CVSS 7.8) (CVE-2026-69270)7.8 HighUpdated
2026-09-24CVE-2026-69266Windows DHCP Server Integer Overflow or Wraparound Lets Unauthenticated Attackers Execute Code over the Network8.8 HighUpdated
2026-09-24CVE-2026-69265Windows NTFS Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69265)7.8 HighUpdated
2026-09-24CVE-2026-68896Microsoft Windows Search Component Absolute path traversal Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-68894Windows Error Reporting Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network8.0 HighUpdated
2026-09-24CVE-2026-68893Windows Remote Desktop Licensing Service Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-68887Windows Message Queuing Queue Manager Out-of-Bounds Read Lets Unauthenticated Attackers Access Sensitive Data over the Network7.5 HighUpdated
2026-09-24CVE-2026-68880Windows Win32K Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network8.0 HighUpdated
2026-09-24CVE-2026-68878Windows Fast FAT Driver Stack-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network8.0 HighUpdated
2026-09-24CVE-2026-68877Windows Storage Spaces Controller Heap-Based Buffer Overflow Lets Authorized Attackers Execute Code Locally (CVE-2026-68877)7.8 HighUpdated
2026-09-24CVE-2026-68876Windows Program Compatibility Assistant Service Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network8.0 HighUpdated
2026-09-24CVE-2026-68875Windows NTFS Buffer Over-read Lets Authorized Attackers Execute Code Locally7.8 HighUpdated
2026-09-24CVE-2026-68848Windows Print Spooler Components Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges Locally7.8 HighUpdated
2026-09-24CVE-2026-68846Windows Kernel Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-68845Windows Program Compatibility Assistant Service Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges Locally7.8 HighUpdated
2026-09-24CVE-2026-68844Windows Storage Spaces Controller Heap-Based Buffer Overflow Lets Authorized Attackers Execute Code Locally7.8 HighUpdated
2026-09-24CVE-2026-68841Windows NTFS Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-68840Windows USB Driver Concurrent execution using shared resource with improper synchronization ('race condition') Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-68839Windows USB Mass Storage Class Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8)9.8 CriticalUpdated
2026-09-24CVE-2026-68838Windows NTFS Stack-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-68835Windows Print Spooler Components Use-After-Free Lets Authorized Attackers Escalate Privileges over the Network7.1 HighUpdated
2026-09-24CVE-2026-68834Windows NTFS Stack-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network (CVE-2026-68834)8.0 HighUpdated
2026-09-24CVE-2026-68832Windows NTFS Integer Overflow Lets Authorized Attackers Escalate Privileges Locally7.8 HighUpdated
2026-09-24CVE-2026-68827Windows GDI+ Integer Underflow Lets Authorized Attackers Escalate Privileges over the Network8.0 HighUpdated
2026-09-24CVE-2026-62759Windows Netlogon Authentication Bypass Lets Unauthenticated Attackers Compromise the System Locally7.5 HighUpdated
2026-09-24CVE-2026-62706Microsoft Windows Media Foundation Out-of-Bounds Read Lets Unauthenticated Attackers Execute Code over the Network8.8 HighUpdated
2026-09-24CVE-2026-62694Windows Installer Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-5857Contiki-NG MQTT Client parse_publish_vhdr Persists a Flag Past an Over-Length Topic, Skipping the Length Guard on the Next Segment and Overflowing the Topic Buffer8.1 HighUpdated
2026-09-24CVE-2026-50349Windows Ancillary Function Driver for WinSock Race Condition Lets Authorized Attackers Escalate Privileges Locally7.0 HighUpdated
2026-09-24CVE-2026-19654Privilege Escalation in Enterprise Linux 9, Allowing Privilege Escalation7.5 HighUpdated
2026-09-24CVE-2026-13249Honeywell PD45 Industrial Printer F10.19.010040 Web Management Interface Allows Unauthenticated File Upload of Attacker-Controlled Files, Enabling Remote Code Execution Without Credentials9.8 CriticalUpdated
2026-09-24CVE-2026-13248Honeywell PD45 Industrial Printer Fingerprint command interface allows authenticated admin to write arbitrary files and execute code8.8 HighUpdated
2026-09-23CVE-2026-20180Critical Cisco ISE Path Traversal Enables Remote Code Execution, Scores 9.99.9 CriticalEPSS-Imminent
2026-09-23CVE-2026-94127CISA's September 25th Remediation Deadline for F5 BIG-IP APM's OAuth Profile Heap Overflow Has Passed; Covered Entities Running Affected Virtual Servers Are Out of Compliance9.8 CriticalKEV
2026-09-23CVE-2026-93952Arista VeloCloud Orchestrator Input Validation Gap Lets Remote Attackers Reach Privileged APIs; CISA's September 25th KEV Deadline for Covered Entities Has Now Passed10.0 CriticalKEV
2026-09-23CVE-2026-83998Remote Desktop Client Heap-Based Buffer Overflow Lets Unauthenticated Attackers Execute Code over the Network8.8 HighUpdated
2026-09-23CVE-2026-82028absmach magistrala SQL Injection Reachable by Authenticated Remote Attackers with High Severity (CVSS 8.8)8.8 HighUpdated
2026-09-23CVE-2026-73176Advantech EKI-1242IEIMS Web Management Interface Passes Request Parameters to OS Commands Without Sanitization, Enabling Root Execution for Authenticated Administrators8.6 HighUpdated
2026-09-23CVE-2026-73175Adjacent Unauthenticated Attacker Can Exhaust the Advantech EKI-1242EIMS OPC UA Session Pool by Opening Multiple Anonymous Connections7.1 HighUpdated
2026-09-23CVE-2026-73174Advantech EKI-1242EIMS edgserver Management Protocol Transmits Device Identity and Network Metadata in Cleartext, Recoverable by a Network-Adjacent Passive Observer8.7 HighUpdated
2026-09-23CVE-2026-73173Advantech EKI-1242EIMS edgserver on TCP Port 5058 Requires No Authentication, Allowing Remote Attackers to Reconfigure the Network, Reboot, Reset, or Replace Firmware8.8 HighUpdated
2026-09-23CVE-2026-73172Advantech EKI-1242EIMS Firmware V1.06.01 edgserver Management Service Passes Unsanitized Input to the OS Shell, Enabling Unauthenticated Remote Attackers to Execute Arbitrary Commands9.3 CriticalUpdated
2026-09-23CVE-2026-73171Advantech EKI-1242EIMS Backup-Restore Workflow Accepts Crafted Archives That Overwrite Arbitrary Files on the Device Filesystem8.6 HighUpdated
2026-09-23CVE-2026-73170Advantech EKI-1242EIMS Modbus CSV Import Evaluates Crafted File Content as Lua, Allowing Authenticated Administrators to Execute Arbitrary Code8.6 HighUpdated
2026-09-23CVE-2026-73167Authenticated Administrator Can Inject OS Commands as Root via Crafted Request Parameters in the Advantech EKI-1242IEIMS Web Management Interface8.6 HighUpdated
2026-09-23CVE-2026-73166Advantech EKI-1242IEIMS Web Management Interface Evaluates Code from Request Parameters, Giving Authenticated Administrators Root-Level Code Execution8.6 HighUpdated
2026-09-23CVE-2026-73165Advantech EKI-1242IEIMS Web Management Endpoint Executes Attacker-Supplied OS Commands as Root When Request Parameters Are Not Sanitized8.6 HighUpdated
2026-09-23CVE-2026-73164Crafted HTTP Request Parameters Reach Root-Level OS Execution in Advantech EKI-1242IEIMS Due to Unsanitized Web Interface Input8.6 HighUpdated
2026-09-23CVE-2026-73163Advantech EKI-1242IEIMS Web Interface OS Command Injection Grants Root Access to Authenticated Administrators8.6 HighUpdated
2026-09-23CVE-2026-73014Data Sharing Service Client Missing authorization Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-23CVE-2026-70584Windows Core Messaging Type Confusion Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-23CVE-2026-69528Windows Shell Missing Authentication Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-23CVE-2026-69517Windows Wireless Networking Use-After-Free Lets Authorized Attackers Escalate Privileges Locally7.0 HighUpdated
2026-09-23CVE-2026-69512Windows Spaceport.sys Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network8.0 HighUpdated
2026-09-23CVE-2026-69508Windows MIDI Service Module Stack-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges Locally7.8 HighUpdated
2026-09-23CVE-2026-69443Microsoft Azure Attestation service and Device Health Attestation Service Out-of-Bounds Read Lets Unauthenticated Attackers Access Sensitive Data over the Network7.5 HighUpdated
2026-09-23CVE-2026-53983Ground Station Socket.IO Server Accepts Attacker-Supplied Orbital Source URLs Without Authentication, Enabling Unauthenticated SSRF via the Orbital Sync Trigger8.6 HighUpdated
2026-09-23CVE-2026-19535Advantech EKI-1242IEIMS LuCI admin interface CSRF allows unauthenticated attacker to trigger privileged management actions8.6 HighUpdated
2026-09-23CVE-2026-19438ABB Mint Workbench I Path Traversal Lets Unauthenticated Remote Attackers Access Sensitive Files (CVSS 7.5)7.5 HighUpdated
2026-09-23CVE-2026-12974Forcepoint NGFW security policy bypass affects versions across 7.1, 7.3, 7.4, and 7.5 branches7.9 HighUpdated
2026-09-22CVE-2026-9586Sangoma Switchvox's SQL Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Database Queries and Compromise the Telephony Platform9.8 CriticalKEV
2026-09-22CVE-2026-9198IBM Langflow's Code Injection Flaw Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the AI Workflow Platform; CISA's August 7th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-9082Drupal Core's SQL Injection via Specially Crafted Database Abstraction API Requests Enables Privilege Escalation and Remote Code Execution; CISA's May 27th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-86218N-able N-central's Static Code Injection Flaw Allows Remote Attackers to Inject and Execute Arbitrary Code on the RMM Platform Without Prior Authentication9.8 CriticalKEV
2026-09-22CVE-2026-85706GitLab Community and Enterprise Edition's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Read Arbitrary Files on the Server and Fully Compromise the GitLab Instance10.0 CriticalKEV
2026-09-22CVE-2026-83549SonicWall SMA1000 Appliances' OS Command Injection Allows Authenticated Local Attackers to Execute Arbitrary Commands with Root Privileges; CISA's September 5th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-83548SonicWall SMA1000 Appliances' Server-Side Request Forgery Allows Unauthenticated Remote Attackers to Reach Internal Services and Compromise the Secure Mobile Access Gateway; CISA's September 5th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-82329JFrog Artifactory Carries a 9.8 Critical Improper Authentication Flaw That Lets Unauthenticated Attackers Bypass Login Controls on the Artifact Repository9.8 CriticalKEV
2026-09-22CVE-2026-73570Zimbra Collaboration Suite's OS Command Injection Allows Authenticated Attackers to Execute Arbitrary Commands on the Email Server with Elevated Privileges; CISA's August 24th KEV Deadline Has Passed8.9 HighKEV
2026-09-22CVE-2026-72898Metabase's SQL Injection Flaw Allows Unauthenticated Attackers to Execute Arbitrary Database Queries and Achieve Full Platform Compromise; CISA's August 14th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-6973Ivanti Endpoint Manager Mobile's Improper Input Validation Allows a Remotely Authenticated Administrator to Execute Code Remotely; CISA's May 10th KEV Deadline Has Passed7.2 HighKEV
2026-09-22CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock's Use-After-Free Allows a Local Attacker to Gain Elevated Privileges via a Freed Memory Reference; CISA's August 25th KEV Deadline Has Passed7.0 HighKEV
2026-09-22CVE-2026-65400Apple macOS's Improper Authentication Flaw Allows a Network Attacker to Bypass Login Controls and Gain Unauthorized Access to the Operating System; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-64849MLflow's Server-Side Request Forgery Flaw Allows Remote Attackers to Use the ML Platform Server as a Proxy to Access Internal Services and Steal Credentials; CISA's September 2nd KEV Deadline Has Passed9.3 CriticalKEV
2026-09-22CVE-2026-63077JetBrains TeamCity's Deserialization of Untrusted Data Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the CI/CD Server; CISA's August 8th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-63030WordPress Core Input Interpretation Conflict Exploited in the Wild Carries a Lapsed July 24th CISA KEV Mandate for Covered Entities9.8 CriticalKEV
2026-09-22CVE-2026-60137WordPress Core SQL Injection Enabling Database Access Joins CISA's Known Exploited Vulnerabilities Catalog; Covered Entities Past the August 4th Remediation Deadline5.9 MediumKEV
2026-09-22CVE-2026-60004Gitea's Code Injection Vulnerability Allows Unauthenticated Remote Attackers to Execute Arbitrary Code on the Repository Platform; CISA's August 28th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-59310Broadcom VMware vCenter's Path Traversal Flaw Allows Unauthenticated Remote Attackers to Access Files Outside the Web Root and Potentially Compromise the Virtualization Platform; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-56291Balbooa Forms Unrestricted File Upload Requiring No Authentication Has Missed CISA's July 13th KEV Remediation Deadline; Covered Entities Are Now Out of Compliance9.8 CriticalKEV
2026-09-22CVE-2026-56290Joomlack Page Builder Lets Unauthenticated Users Upload Arbitrary Files, Enabling Remote Code Execution; CISA's July 10th KEV Mandate Has Lapsed9.8 CriticalKEV
2026-09-22CVE-2026-55040Microsoft SharePoint's Weak Authentication Allows Attackers to Bypass Login Controls and Gain Unauthorized Access to SharePoint Sites and Data; CISA's August 21st KEV Deadline Has Passed9.1 CriticalKEV
2026-09-22CVE-2026-50751Check Point Security Gateway's IKEv1 Key Exchange Flaw Lets Unauthenticated Attackers Establish Remote Access VPN Tunnels Without a Valid Password; CISA's June 11th KEV Deadline Has Passed9.3 CriticalKEV
2026-09-22CVE-2026-48939iCagenda Joomla Event Calendar Extension Accepts Unrestricted File Uploads Without Authentication, Enabling Remote Code Execution; CISA's July 13th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-48908JoomShaper SP Page Builder Accepts Arbitrary File Uploads from Unauthenticated Users; CISA's July 10th KEV Deadline for Covered Entities Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-48907Joomla Content Editor Plugin Exposes Privileged Functions Without Proper Authorization; CISA's June 19th KEV Deadline for Covered Entities Has Lapsed9.8 CriticalKEV
2026-09-22CVE-2026-48558SimpleHelp Accepts Unverified Cryptographic Signatures, Letting Remote Attackers Bypass Authentication; CISA's July 2nd KEV Deadline for Covered Entities Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-48172Any cPanel User Can Escalate Privileges Through LiteSpeed's Plugin; CISA's May 29th KEV Remediation Requirement for Covered Entities Has Expired9.8 CriticalKEV
2026-09-22CVE-2026-46817Oracle E-Business Suite's Improper Privilege Management in Oracle Payments Allows an Unauthenticated Network Attacker to Take Over the Payments Module via HTTP; CISA's July 18th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-45498Microsoft Defender's Unspecified Vulnerability Allows for Denial of Service; CISA's June 3rd KEV Deadline Has Passed4.0 MediumKEV
2026-09-22CVE-2026-45247Mirasvit Full Page Cache Warmer's Deserialization Flaw Lets Unauthenticated Attackers Reach Remote Code Execution via a Crafted PHP Object in the CacheWarmer Cookie; CISA's June 6th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-42897Microsoft Exchange Server's Outlook Web Access Cross-Site Scripting Flaw Executes Arbitrary JavaScript When Interaction Conditions Are Met; CISA's May 29th KEV Deadline Has Passed8.1 HighKEV
2026-09-22CVE-2026-42018JFrog Artifactory's Improper Authentication Allows Network-Based Attackers to Bypass Login Controls and Gain Unauthorized Access to the Artifact Repository7.5 HighKEV
2026-09-22CVE-2026-42016JFrog Artifactory's Incorrect Authorization Allows Authenticated Users to Access Artifacts and Repositories Outside Their Permitted Scope8.1 HighKEV
2026-09-22CVE-2026-41091Microsoft Defender's Link Following Flaw Enables an Authorized Attacker to Elevate Privileges Locally; CISA's June 3rd KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-39987Marimo's Pre-Authentication Flaw Gives Unauthenticated Attackers Shell Access and Arbitrary Command Execution; CISA's May 7th KEV Remediation Requirement for Covered Entities Has Long Lapsed9.8 CriticalKEV
2026-09-22CVE-2026-39808Fortinet FortiSandbox's OS Command Injection Gives Unauthenticated Attackers Remote Code Execution via Crafted HTTP Requests; CISA's July 19th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-35616Fortinet FortiClient EMS Access Control Bypass Entered CISA's Known Exploited Vulnerabilities Catalog with an April 9th Federal Deadline That Has Long Passed9.8 CriticalKEV
2026-09-22CVE-2026-35273Oracle PeopleSoft Enterprise PeopleTools' Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Take Over the Platform; CISA's June 15th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-34926Pre-Authenticated Local Attackers Can Use Relative Path Traversal in Trend Micro Apex One to Modify Key Configuration Data; CISA's June 4th KEV Mandate for Covered Entities Has Lapsed6.7 MediumKEV
2026-09-22CVE-2026-34910Network-Adjacent Attackers Can Inject Commands into Ubiquiti UniFi OS Through an Input Validation Flaw; CISA's June 26th KEV Remediation Window Has Closed for Covered Entities10.0 CriticalKEV
2026-09-22CVE-2026-34909Ubiquiti UniFi OS's Path Traversal Lets a Network-Adjacent Attacker Access Files on the Underlying System and Manipulate an Underlying Account; CISA's June 26th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-34908Ubiquiti UniFi OS's Improper Access Control Lets a Network-Adjacent Attacker Make Unauthorized Changes to the System; CISA's June 26th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-34486Apache Tomcat's Missing Encryption of Sensitive Session Data Exposes Credentials and Tokens to Network Interception; CISA's August 7th KEV Deadline Has Passed7.5 HighKEV
2026-09-22CVE-2026-34197Apache ActiveMQ's Improper Input Validation Enables Code Injection Affecting Both ActiveMQ and Broker Deployments; CISA's April 30th KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2026-33825Microsoft Defender's Insufficient Access Control Allows an Authorized Attacker to Escalate Privileges Locally; CISA's May 6th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-32202Microsoft Windows Shell's Protection Mechanism Failure Allows an Unauthorized Attacker to Perform Spoofing Over the Network; CISA's May 12th KEV Deadline Has Passed4.3 MediumKEV
2026-09-22CVE-2026-31431Linux Kernel Resource Mishandling That Allows Privilege Escalation Carries a Lapsed May 15th CISA KEV Mandate; Covered Entities on Unpatched Kernels Remain Out of Compliance7.8 HighKEV
2026-09-22CVE-2026-28318SolarWinds Serv-U File Transfer Server Resource Exhaustion Exploited in the Wild Carries a Lapsed June 19th CISA KEV Federal Deadline7.5 HighKEV
2026-09-22CVE-2026-25089Fortinet FortiSandbox's Unauthenticated OS Command Injection via Crafted HTTP Requests Covers Cloud and PaaS Deployments; CISA's July 19th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-21962Oracle HTTP Server and WebLogic Server Proxy Plug-in's Improper Access Control Allows Unauthenticated Network Attackers to Fully Compromise the Middleware Platform; CISA's August 27th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-21643Fortinet FortiClient EMS's SQL Injection Allows Unauthenticated Attackers to Execute Unauthorized Code via Crafted HTTP Requests; CISA's April 16th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-20316Cisco Secure Firewall Management Center Hard-Coded Password Lets Attackers Bypass Authentication; CISA's August 1st KEV Deadline for Covered Entities Has Passed5.3 MediumKEV
2026-09-22CVE-2026-20262Authenticated Path Traversal in Cisco Catalyst SD-WAN Manager Lets Remote Attackers Write Files Outside Allowed Directories; CISA's June 29th KEV Deadline Has Passed6.5 MediumKEV
2026-09-22CVE-2026-20253Splunk Enterprise's Missing Authentication on a PostgreSQL Sidecar Service Endpoint Lets Unauthenticated Users Create or Truncate Arbitrary Files; CISA's June 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-20245Cisco Catalyst SD-WAN Manager's Improper Encoding Allows an Authenticated Local Attacker to Execute Arbitrary Commands as Root via a Crafted File; CISA's June 23rd KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-20230Cisco Unified Communications Manager SSRF Flaw Routes Attacker Requests to Internal Resources; CISA's June 28th KEV Deadline for Covered Entities Has Lapsed8.6 HighKEV
2026-09-22CVE-2026-20200Cisco Unified Computing System's Argument Delimiter Injection Allows an Authenticated Attacker to Execute Arbitrary Commands on the Management Controller8.8 HighExploited
2026-09-22CVE-2026-20182Cisco Catalyst SD-WAN Controller and Manager's Authentication Bypass Gives Unauthenticated Remote Attackers Administrative Privileges; CISA's May 17th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-20133Cisco Catalyst SD-WAN Manager Leaks Sensitive Configuration Data to Unauthorized Users; CISA's April 23rd KEV Remediation Requirement Has Expired for Covered Entities6.5 MediumKEV
2026-09-22CVE-2026-20128Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed7.5 HighKEV
2026-09-22CVE-2026-20122Cisco Catalyst SD-WAN Manager Exposes Privileged API Functions to Unauthorized Callers; CISA's April 23rd KEV Remediation Deadline for Covered Entities Has Long Passed5.4 MediumKEV
2026-09-22CVE-2026-20079Cisco Firewall Management Center's Authentication Bypass via an Alternate Path Grants Unauthenticated Remote Attackers Full Administrative Control; CISA's September 12th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-19490Citrix NetScaler's Authentication Bypass via an Alternate Path Allows Unauthenticated Remote Attackers to Access Protected Resources Without Valid Credentials9.8 CriticalKEV
2026-09-22CVE-2026-16232Check Point SmartConsole's Improper Authentication Allows Unauthenticated Remote Attackers to Obtain a Login Token and Authenticate with Full Administrative Privileges; CISA's July 25th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-15410SonicWall SMA1000's Code Injection Allows a Remote Authenticated Administrator to Execute Arbitrary OS Commands Under Specific Conditions; CISA's July 17th KEV Deadline Has Passed7.2 HighKEV
2026-09-22CVE-2026-15409SonicWall SMA1000 Secure Access Appliances Accept Forged Server-Side Requests, Enabling Internal Network Pivoting; CISA's July 17th KEV Remediation Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-1340Ivanti Endpoint Manager Mobile's Code Injection Vulnerability Allows Attackers to Achieve Unauthenticated Remote Code Execution; CISA's April 11th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-12569PTC Windchill and FlexPLM's Improper Input Validation Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via Malicious Network Requests; CISA's June 28th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-10520Ivanti Sentry's OS Command Injection Gives Remote Unauthenticated Attackers Root-Level Remote Code Execution; CISA's June 14th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-0300PAN-OS Out-of-Bounds Write Enabling Code Execution Affects Both Palo Alto Networks Firewalls and Siemens RUGGEDCOM APE1808 Industrial Appliances; CISA's May 9th KEV Window Has Closed9.8 CriticalKEV
2026-09-22CVE-2026-0257PAN-OS Authentication Bypass Enabling Unauthorized VPN Tunnels Affects Palo Alto Networks Prisma Access and Siemens RUGGEDCOM APE1808; Now Listed in CISA's Known Exploited Vulnerabilities Catalog9.1 CriticalKEV
2026-09-22CVE-2026-95862Ubiquiti Inc Dream Wall Out-of-Bounds Write Reachable by Unauthenticated Remote Attackers7.5 HighUpdated
2026-09-22CVE-2026-95861Ubiquiti Inc Dream Wall Denial of Service Reachable by Unauthenticated Remote Attackers in Ubiquiti Inc Dream Wall7.5 HighUpdated
2026-09-22CVE-2026-95675D-Link DAP-1360 Remote Code Execution Reachable by Unauthenticated Remote Attackers at Critical Severity (CVSS 9.8)9.8 CriticalUpdated
2026-09-22CVE-2026-94089D-Link DIR-868L Buffer Overflow Reachable by Unauthenticated Remote Attackers at Critical Severity (CVSS 10.0)10.0 CriticalUpdated
2026-09-22CVE-2026-77558Ubiquiti UniFi Dream Wall Out-of-Bounds Read Lets Unauthenticated Network Attackers Cause Denial of Service (CVSS 7.5)7.5 HighUpdated
2026-09-22CVE-2026-77556Ubiquiti UniFi Dream Wall Out-of-Bounds Read Lets Network-Adjacent Attackers Read Sensitive Data (CVSS 7.5)7.5 HighUpdated
2026-09-22CVE-2026-77555Ubiquiti Inc Dream Wall Out-of-Bounds Write Reachable by Unauthenticated Remote Attackers (CVE-2026-77555)7.5 HighUpdated
2026-09-22CVE-2026-77544Ubiquiti Inc Dream Wall Out-of-Bounds Write Reachable by Unauthenticated Remote Attackers in Ubiquiti Inc Dream Wall7.5 HighUpdated
2026-09-22CVE-2026-72946Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-09-22CVE-2026-72940Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network8.8 HighUpdated
2026-09-22CVE-2026-72936Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network8.1 HighUpdated
2026-09-22CVE-2026-72929Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-09-22CVE-2026-72926Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-7273Zyxel GS1900 Series Switches' CGI Program Stack-Based Buffer Overflow Allows a LAN-Side Unauthenticated Attacker to Execute OS Commands via Crafted HTTP Requests; CISA's September 24th KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2026-71221Enterprise Linux gfs2-utils Code Execution Reachable by Unauthenticated Local Attackers (CVSS 7.0)7.0 HighUpdated
2026-09-22CVE-2026-71220Enterprise Linux gfs2-utils Buffer Overflow Reachable by Unauthenticated Local Attackers (CVSS 7.0)7.0 HighUpdated
2026-09-22CVE-2026-69791Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69790Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-09-22CVE-2026-69784Windows Hello Use-After-Free Lets Authorized Attackers Escalate Privileges Locally8.8 HighUpdated
2026-09-22CVE-2026-69775Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network7.1 HighUpdated
2026-09-22CVE-2026-69762Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network8.0 HighUpdated
2026-09-22CVE-2026-69760Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network7.5 HighUpdated
2026-09-22CVE-2026-69757Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network7.1 HighUpdated
2026-09-22CVE-2026-69744Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network7.5 HighUpdated
2026-09-22CVE-2026-69740Use after free in Windows Hello allows an authorized attacker to elevate privileges locally8.8 HighUpdated
2026-09-22CVE-2026-69735Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69729Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network8.8 HighUpdated
2026-09-22CVE-2026-69725Double free in Windows Hello allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-09-22CVE-2026-69720Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-09-22CVE-2026-69711Windows Device Association Service Use-After-Free Lets Authorized Attackers Escalate Privileges Locally7.0 HighUpdated
2026-09-22CVE-2026-69710Windows Hello Race Condition Lets Authorized Attackers Escalate Privileges Locally7.5 HighUpdated
2026-09-22CVE-2026-69708Use after free in Windows Web Platform Storage allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69694Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69693Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69689Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network8.0 HighUpdated
2026-09-22CVE-2026-69682Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69654Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69652Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-31278Suprema BioStar 2 Active Directory service account credentials exposed in cleartext via GET request7.7 HighUpdated
2026-09-21CVE-2026-94036D-Link DIR-X1860Z Improper Access Control Reachable by Adjacent-Network Attackers8.8 HighUpdated
2026-09-21CVE-2026-93958D-Link R95 Command Injection Exploitable by Authenticated Admin Network Attackers (CVSS 9.1)9.1 CriticalUpdated
2026-09-21CVE-2026-90042Linux Kernel ceph properly decrypt filenames in vmalloc() buffers, Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-09-21CVE-2026-90041Linux Kernel HID: sony: clean up device list on probe failure8.8 HighUpdated
2026-09-21CVE-2026-90037Linux Kernel NFSD: Failure to Prevent client use-after-free during close_lru reaping, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-09-21CVE-2026-90036Linux Kernel NFSD Prevent client use-after-free during blocked-lock reaping, Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-09-21CVE-2026-89815Linux Kernel drm/ttm: Memory Safety Issue Allows Local Privilege Escalation7.8 HighUpdated
2026-09-21CVE-2026-89799Linux Kernel bpf: Disable preemption in bpf_get_stackid7.8 HighUpdated
2026-09-21CVE-2026-89763Linux Kernel KEYS trusted: Fix TPM teardown ordering7.8 HighUpdated
2026-09-21CVE-2026-89755Linux Kernel mm/migrate_device: Failure to Clear stale mapping after freeing swapcache7.8 HighUpdated
2026-09-21CVE-2026-89731Linux Kernel cxl/ras: Out-of-Bounds Read Allows Local Privilege Escalation7.1 HighUpdated
2026-09-21CVE-2026-89708Linux Kernel nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-09-21CVE-2026-89685Linux Kernel nfsd fix clock domain mismatch in clients_still_reclaiming(), Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-09-21CVE-2026-89676Linux Kernel nfsd: Reference Count Error Enables Remote Code Execution (CVSS 9.8)9.8 CriticalUpdated
2026-09-21CVE-2026-89667Linux Kernel nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache, Reachable from the Network Without Credentials (CVSS 8.1)8.1 HighUpdated
2026-09-21CVE-2026-89660Linux Kernel NFSD Prevent client use-after-free during admin state revocation, Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-09-21CVE-2026-89659Linux Kernel NFSD Prevent client use-after-free during delegation revoke, Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-09-21CVE-2026-89624Linux Kernel HID: universal-pidff: stop the device when force-feedback init fails7.8 HighUpdated
2026-09-21CVE-2026-89622Linux Kernel HID mcp2221: clear rxbuf after I2C/SMBus transfer completes7.8 HighUpdated
2026-09-21CVE-2026-89602Linux Kernel erofs: skip sufficiently large global buffers when resizing7.8 HighUpdated
2026-09-21CVE-2026-89564Linux Kernel ip orphan prefetched skbs before multicast forwarding7.8 HighUpdated
2026-09-21CVE-2026-89561Linux Kernel ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv(), Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-09-21CVE-2026-89545Linux Kernel sunrpc: defer rq_argp and rq_resp free until after RCU grace period7.8 HighUpdated
2026-09-21CVE-2026-89544Linux Kernel SUNRPC: Failure to Fix gssx_dec_option_array error path bugs, Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-09-21CVE-2026-89535Linux Kernel svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id, Reachable from the Network Without Credentials (CVSS 8.1)8.1 HighUpdated
2026-09-21CVE-2026-89492Linux Kernel ocfs2: Failure to Validate directory-index entry counts when reading metadata, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-09-21CVE-2026-80945Linux Kernel crypto: iaa - unmap dst before software fallback on decompress, Reachable Without Authentication (CVSS 9.1)9.1 CriticalUpdated
2026-09-21CVE-2026-80734Linux Kernel btrfs: Failure to Initialize inode mapping flags for cached inodes8.8 HighUpdated
2026-09-21CVE-2026-80685Linux Kernel mm/util: Missing Guard: don't read __page_2 for order-1 folios in snapshot_page()7.1 HighUpdated
2026-09-21CVE-2026-74407Linux Kernel wifi ath11k: cancel SSR work items during PCI shutdown8.8 HighUpdated
2026-09-21CVE-2026-74269Linux Kernel bnxt: Failure to Fix head underflow on XDP head-grow, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-09-21CVE-2026-72989Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network7.5 HighUpdated
2026-09-21CVE-2026-72962Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally8.2 HighUpdated
2026-09-21CVE-2026-72961Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally8.2 HighUpdated
2026-09-21CVE-2026-72960Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network8.8 HighUpdated
2026-09-21CVE-2026-72958Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally8.2 HighUpdated
2026-09-21CVE-2026-72953Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-09-21CVE-2026-72952Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally7.0 HighUpdated
2026-09-21CVE-2026-72949Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network7.5 HighUpdated
2026-09-21CVE-2026-72494Linux Kernel RDMA/irdma Replace waitqueue and flag with completion, Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-09-21CVE-2026-72438Linux Kernel md/raid10: Failure to Fix writes_pending and barrier reference leaks on discard failures, Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-09-21CVE-2026-72355Linux Kernel netfs: Failure to Fix barriering when walking subrequest list, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-09-21CVE-2026-71226Enterprise Linux Memory Corruption Reachable by Unauthenticated Local Attackers (CVSS 7.3)7.3 HighUpdated
2026-09-21CVE-2026-69648Use after free in Windows Notification allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-21CVE-2026-69625Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network8.0 HighUpdated
2026-09-21CVE-2026-69617Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-21CVE-2026-69606Use after free in Windows Shell allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-21CVE-2026-69602Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network7.1 HighUpdated
2026-09-21CVE-2026-69597Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network7.1 HighUpdated
2026-09-21CVE-2026-69586Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network9.8 CriticalUpdated
2026-09-21CVE-2026-69575Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-21CVE-2026-54230Enterprise Linux Arbitrary Filesystem Write Reachable by Low-Privilege Local Attackers (CVSS 7.0)7.0 HighUpdated
2026-09-20CVE-2026-87886Acronis Backup's Incorrect Default Permissions Allow a Local Attacker to Access Backup Files and Configurations Not Intended for Their Account; CISA's September 19th KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-84869ConnectWise ScreenConnect's Improper Privilege Management and Missing Authorization Allow Unauthenticated Attackers to Gain Administrative Control of the Remote Support Platform; CISA's September 14th KEV Deadline Has Passed9.9 CriticalKEV
2026-09-20CVE-2026-81963Windows Update Stack Symbolic Link Following Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighKEV
2026-09-20CVE-2026-67277MikroTik RouterOS's Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Access and Modify Router Configuration; CISA's September 13th KEV Deadline Has Passed8.2 HighKEV
2026-09-20CVE-2026-53362Linux Kernel's Unspecified Flaw Allows Local Attackers to Gain Elevated Privileges on Affected Systems; CISA's August 30th KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-53266Linux Kernel's Out-of-Bounds Write Vulnerability Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 21st KEV Deadline Has Passed8.8 HighKEV
2026-09-20CVE-2026-50516Microsoft Azure Kubernetes Service's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Interact with Privileged Cluster Management Endpoints9.4 CriticalUpdated
2026-09-20CVE-2026-20349Cisco Secure Firewall ASA and FTD's Heap Inspection Vulnerability Allows Remote Attackers to Extract Sensitive Memory Contents from the Firewall Device; CISA's August 14th KEV Deadline Has Passed8.6 HighKEV
2026-09-20CVE-2026-20301Cisco IOS XE's Unchecked Loop Condition Input Allows Network-Accessible Devices to Be Crashed via a Specially Crafted Packet8.6 HighExploited
2026-09-20CVE-2026-20124Cisco IOS XE's Memory Resource Leak Allows Remote Attackers to Exhaust Device Memory and Cause a Denial of Service via Repeated Packet Transmission7.7 HighExploited
2026-09-20CVE-2026-72530TrueConf Server's Code Injection Vulnerability Allows Remote Attackers to Execute Arbitrary Code on the Video Conferencing Platform; CISA's September 3rd KEV Deadline Has Passed9.0 CriticalKEV
2026-09-20CVE-2026-72529TrueConf Server's Missing Authentication on a Critical Function Allows Unauthenticated Remote Attackers to Access Administrative Capabilities; CISA's August 23rd KEV Deadline Has Passed9.8 CriticalKEV
2026-09-18CVE-2026-87491Google Chromium V8's Out-of-Bounds Write Allows Remote Attackers to Corrupt the JavaScript Engine's Heap and Execute Arbitrary Code via a Crafted Web Page8.8 HighKEV
2026-09-18CVE-2026-59822BerriAI LiteLLM's Improper Authentication Allows Unauthenticated Attackers to Access the AI Model Gateway and Interact with Configured LLM Endpoints Without Credentials8.2 HighKEV
2026-09-18CVE-2026-58704Google Pixel's Improper Authorization Flaw Allows an Attacker with Physical or Local Access to Bypass Permission Controls and Access Protected Device Functions8.8 HighKEV
2026-09-18CVE-2026-49869Kestra OSS's OS Command Injection Flaw Lets Unauthenticated Remote Attackers Execute Arbitrary Commands on the Workflow Orchestration Server with Full System Privileges10.0 CriticalKEV
2026-09-18CVE-2026-27563Crafted GET Request to the Datastorage API Lets Admin Credentials Trigger Root Command Execution on Pepperl+Fuchs ICE-Series IO-Link Masters7.2 HighUpdated
2026-09-18CVE-2026-27558Operator Access to the IODD File Removal Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Allows Root Command Injection8.8 HighUpdated
2026-09-18CVE-2026-27548Command Injection in the IODD Port Info Endpoint Grants Root Access on Pepperl+Fuchs ICE-Series IO-Link Masters to Any User or Operator Account8.8 HighUpdated
2026-09-16CVE-2026-27565Unauthenticated IODD File Upload on Pepperl+Fuchs ICE-Series IO-Link Masters Executes a Root Shell Script That Persists Across Reboots9.8 CriticalUpdated
2026-09-16CVE-2026-27564Pepperl+Fuchs ICE-Series IO-Link Masters Run Injected Root Commands When Admin Credentials Submit a Crafted PUT Request to the Datastorage API7.2 HighUpdated
2026-09-16CVE-2026-27562Admin-Level PUT Requests to the IODD Configuration API Execute Injected Commands as Root on Pepperl+Fuchs ICE-Series IO-Link Masters7.2 HighUpdated
2026-09-16CVE-2026-27561Admin Credentials Enable Root Command Injection via the IODD Config GET API on Pepperl+Fuchs ICE-Series IO-Link Masters7.2 HighUpdated
2026-09-16CVE-2026-27560Admin-Credentialed DELETE Requests to Pepperl+Fuchs ICE-Series IO-Link Masters' Status API Carry Injected Commands Executed at Root7.2 HighUpdated
2026-09-16CVE-2026-27559User Credentials Are Enough to Inject Root-Level Commands via the Status Data API on Pepperl+Fuchs ICE-Series IO-Link Masters8.8 HighUpdated
2026-09-16CVE-2026-27557Unauthenticated Path Traversal in Pepperl+Fuchs ICE-Series IO-Link Masters Exposes the Device's SSH Server Private Keys7.5 HighUpdated
2026-09-16CVE-2026-27556Operator Cookie Enables Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Parameter Save Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27555A Valid User Cookie Triggers Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Port Info Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27554IODD Parameter Save Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Accepts Injected Commands from Operator-Level Accounts, Yielding Root Access8.8 HighUpdated
2026-09-16CVE-2026-27552Pepperl+Fuchs ICE-Series IO-Link Masters Allow Low-Privileged Users to Upload Arbitrary IODD Files via a Missing Authorization Check, Enabling Device Manipulation or Crashes8.1 HighUpdated
2026-09-16CVE-2026-27551User-Level Credentials Give Root Shell on Pepperl+Fuchs ICE-Series IO-Link Masters via the Parameter Management Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27550Operator Credentials Can Inject Root-Level OS Commands via the Field_Shadow_Password Handler on Pepperl+Fuchs ICE-Series IO-Link Masters8.8 HighUpdated
2026-09-16CVE-2026-27549Operator-Level Credentials Suffice to Run Root Commands on Pepperl+Fuchs ICE-Series IO-Link Masters via the IODD Upload Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27547IODD Menu Info Request on Pepperl+Fuchs ICE-Series IO-Link Masters Passes Unvalidated Parameters to Root-Level Commands, Reachable with User-Level Credentials8.8 HighUpdated
2026-09-16CVE-2026-27546The _account_log Function in Pepperl+Fuchs ICE-Series IO-Link Masters Lets Unauthenticated Attackers Log In as Admin Regardless of Account Configuration9.8 CriticalUpdated
2026-09-11CVE-2026-63298LXD NVIDIA Instance Configuration Handler Accepts Newline Characters in nvidia.driver.capabilities and nvidia.require.* Values, Letting Authenticated Attackers Inject Arbitrary Directives into the GPU Configuration9.9 CriticalUpdated
2026-09-10CVE-2026-32589Red Hat Quay authenticated push access enables interference with other users' in-progress image uploads across repositories7.4 HighUpdated
2026-08-13CVE-2026-64125Linux Kernel bcmgenet Driver Enabling RBUF EEE and PM Bits Stops RX Traffic When MAC EEE Activates, Causing a Denial-of-Service Condition on Broadcom GENET Hardware9.8 CriticalUpdated
2026-07-28CVE-2026-16812Arista VeloCloud Orchestrator On-Prem Management Plane Executes Injected OS Commands; CISA's July 30th KEV Deadline Has Passed for Covered Entities10.0 CriticalKEV
2026-07-24CVE-2026-31405Linux Kernel DVB-net ULE Extension Handler Uses a Network-Controlled Index into a 255-Entry Table Without Bounds Checking, Enabling Out-of-Bounds Reads and Writes9.8 CriticalUpdated
2026-07-24CVE-2026-23458Linux kernel ctnetlink multi-round dump dereferences freed conntrack pointer in second callback invocation7.8 HighUpdated
2026-07-24CVE-2026-23450Linux Kernel SMC-over-TCP SYN Receive Path Calls sock_hold Then Schedules a tcp_close Work Item Without Synchronizing Against Concurrent Stack Cleanup, Enabling Use-After-Free and Null Dereference9.8 CriticalUpdated
2026-07-24CVE-2026-23419Linux kernel rds_tcp_tune circular locking dependency causes deadlock via sk_net_refcnt_upgrade7.5 HighUpdated
2026-07-23CVE-2026-54420LiteSpeed's cPanel Plugin Follows Symlinks Across Security Boundaries to Escalate Privileges; CISA's June 18th KEV Remediation Window Has Closed for Covered Entities8.5 HighKEV
2026-07-23CVE-2026-42542CVE-2026-425427.5 HighUpdated
2026-07-15CVE-2026-56155Microsoft Active Directory Federation Services Insufficient Access Control Allows an Authorized Attacker to Elevate Privileges Locally; CISA's July 28th KEV Deadline Has Passed7.8 HighKEV
2026-07-14CVE-2026-31446Linux kernel ext4 use-after-free in update_super_work races with unmount after sysfs unregistration7.8 HighUpdated
2026-07-08CVE-2026-46279Linux Kernel Page Extension Initialization Leaves Codetag Uninitialized for Pages Allocated Before page_ext Is Ready7.8 HighUpdated
2026-07-02CVE-2026-53225Linux Kernel SCTP ASCONF Lookup Reads Past the Validated Header Boundary, Exposing Uninitialized Memory to Downstream Address Parameter Processing9.1 CriticalUpdated
2026-06-17CVE-2026-8398Daemon Tools Lite Contains Embedded Malicious Code; CISA Added It to KEV with a May 30th Deadline That Has Since Passed for Covered Entities9.8 CriticalKEV
2026-06-17CVE-2026-7473Arista Extensible Operating System Validation Bypass Added to CISA's Known Exploited Vulnerabilities List; Federal Remediation Window for Covered Entities Closed June 23rd5.8 MediumKEV
2026-06-17CVE-2026-48027Nx Console Developer Tooling Published Packages Contain Embedded Malicious Code; CISA's June 10th KEV Mandate for Covered Entities Has Passed9.8 CriticalKEV
2026-06-17CVE-2026-45321TanStack JavaScript Library Suite Added to CISA's Known Exploited Vulnerabilities Catalog; Federal Remediation Deadline for Covered Entities Was June 10th9.6 CriticalKEV
2026-06-17CVE-2026-43296Linux Kernel octeontx2-af NIC SQ Manager Sticky Mode Causes Stalls and Potential PSE Deadlock When Multiple Queues Share an SMQ7.5 HighUpdated
2026-06-17CVE-2026-4116SonicWall SMA1000 Mishandles Unicode Encoding in TOTP Validation, Allowing an Authenticated SSLVPN User to Bypass Two-Factor Authentication7.2 HighUpdated
2026-06-17CVE-2026-4113SonicWall SMA1000 Distinguishable Authentication Error Responses Allow a Remote Attacker to Enumerate SSL VPN User Accounts7.2 HighUpdated
2026-06-17CVE-2026-4112SonicWall SMA1000 SQL Injection in the SSLVPN Component Allows a Read-Only Administrator to Escalate to Primary Administrator7.2 HighUpdated
2026-06-17CVE-2026-31693Linux kernel CIFS replay path missing variable reinitializations causes undefined behavior on request retry7.8 HighUpdated
2026-06-17CVE-2026-31568Linux kernel s390/mm missing secure storage access fixups for donated pages causes kernel context exceptions7.1 HighUpdated
2026-06-17CVE-2026-31426Linux kernel ACPI EC address space handler persists after probe failure leaves dangling pointer7.0 HighUpdated
2026-06-17CVE-2026-23406Linux kernel AppArmor match_char macro evaluates pointer multiple times and skips input characters during DFA traversal7.8 HighUpdated
2026-06-17CVE-2026-1952Delta Electronics AS320T Denial of Service via Undocumented Subfunction Call, Exploitable Remotely Without Authentication9.8 CriticalUpdated
2026-06-17CVE-2026-1951Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing Directory Name Length Check, Enabling Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-06-17CVE-2026-1950Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing File Name Length Check, Enabling Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-06-17CVE-2026-1949Delta Electronics AS320T GET/PUT Request Handler Incorrectly Calculates Stack Buffer Size, Enabling Unauthenticated Remote Code Execution via the Web Service9.8 CriticalUpdated

No advisories match this filter.