CVE Database

444+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76460
10.0 CRITICAL KEV

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to …

Sep 16, 2026
CVE-2026-58704
8.8 HIGH KEV

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of …

Sep 15, 2026
CVE-2026-76461
9.8 CRITICAL KEV

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands …

Sep 14, 2026
CVE-2026-85706
10.0 CRITICAL KEV

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain …

Sep 12, 2026
CVE-2026-87491
8.8 HIGH KEV

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a …

Sep 9, 2026
CVE-2026-84869
9.9 CRITICAL KEV

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in …

Sep 8, 2026
CVE-2026-85880
7.8 HIGH KEV

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-81963
7.8 HIGH KEV

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-75650
10.0 CRITICAL KEV

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in …

Sep 7, 2026
CVE-2026-86218
9.8 CRITICAL KEV

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Sep 6, 2026
CVE-2026-86060
9.8 CRITICAL KEV

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask …

Sep 5, 2026
CVE-2026-67277
8.2 HIGH KEV

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 …

Sep 5, 2026
CVE-2026-83549
7.8 HIGH KEV

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) …

Sep 1, 2026
CVE-2026-83548
KEV

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially …

Sep 1, 2026
CVE-2026-82329
9.8 CRITICAL KEV

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Aug 28, 2026
CVE-2026-82078
9.1 CRITICAL KEV

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based …

Aug 28, 2026
CVE-2026-81578
9.8 CRITICAL KEV

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative …

Aug 28, 2026
CVE-2026-60004
9.8 CRITICAL KEV

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Aug 26, 2026
CVE-2026-72530
9.0 CRITICAL KEV

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and …

Aug 19, 2026
CVE-2026-72529
9.8 CRITICAL KEV

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and …

Aug 19, 2026
CVE-2026-19490
KEV

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 …

Aug 19, 2026
CVE-2026-18577
8.1 HIGH KEV

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Aug 2, 2026
CVE-2026-18556
7.4 HIGH KEV

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

Aug 1, 2026
CVE-2026-59310
9.8 CRITICAL KEV

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute …

Jul 30, 2026
CVE-2026-20316
5.3 MEDIUM KEV

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an …

Jul 29, 2026
CVE-2026-42016
8.1 HIGH KEV

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not …

Jul 27, 2026
CVE-2026-63077
9.8 CRITICAL KEV

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Jul 27, 2026
CVE-2026-16812
10.0 CRITICAL KEV

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO …

Jul 27, 2026
CVE-2026-16232
9.1 CRITICAL KEV

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it …

Jul 22, 2026
CVE-2026-63030
9.8 CRITICAL KEV

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query …

Jul 17, 2026
CVE-2026-60137
5.9 MEDIUM KEV

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection …

Jul 17, 2026
CVE-2026-9198
9.8 CRITICAL KEV

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via …

Jul 17, 2026
CVE-2026-9586
KEV

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates …

Jul 17, 2026
CVE-2021-27137
8.1 HIGH KEV

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send …

Jul 16, 2026
CVE-2026-15410
7.2 HIGH KEV

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could …

Jul 14, 2026
CVE-2026-15409
10.0 CRITICAL KEV

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance …

Jul 14, 2026
CVE-2026-55040
9.1 CRITICAL KEV

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Jul 14, 2026
CVE-2026-58644
9.8 CRITICAL KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-56164
5.3 MEDIUM KEV

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-56155
7.8 HIGH KEV

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-50522
9.8 CRITICAL KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-56291
9.8 CRITICAL KEV

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Jul 9, 2026
CVE-2026-59822
8.2 HIGH KEV

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed …

Jul 8, 2026
CVE-2026-53362
KEV

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch …

Jul 4, 2026
CVE-2026-48282
10.0 CRITICAL KEV

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead …

Jun 30, 2026
CVE-2026-8452
9.8 CRITICAL KEV

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a …

Jun 30, 2026
CVE-2026-56290
9.8 CRITICAL KEV

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Jun 29, 2026
CVE-2026-49869
10.0 CRITICAL KEV

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from …

Jun 26, 2026
CVE-2026-12569
KEV

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization …

Jun 18, 2026
CVE-2026-20262
6.5 MEDIUM KEV

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or …

Jun 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.