PoC Archive PoC Archive

All proof-of-concept entries in the archive.

Entries

773

in the archive

CISA KEV

119

exploited in the wild

Ransomware

33

known campaign use

Unpatched

322

no vendor fix

Critical

378

49% of listed

773 entries
Category:

Severity

Exploitation signals

Patch status

Date range

→
Sort

773 result(s)

POC LIST 773 shown · 773 indexed
PoC titleSeverity
WordPress Divi Ajax Filter LFI (CVE-2026-11613)
CVE-2026-11613 web Unverified
CRITICAL 9.8
PaperCut MF/NG Auth Bypass + RCE Chain (CVE-2026-81578 / CVE-2026-82078)
CVE-2026-81578, CVE-2026-82078 web Unverified
CRITICAL 9.8
Linux XFRM nat_keepalive Double-Free LPE (CVE-2026-72137)
CVE-2026-72137 binary Unverified
HIGH 7.8
Linux SCTP Stream Rollback UAF LPE (CVE-2026-52929)
CVE-2026-52929 binary Unverified
HIGH 7.8
Linux SCTP Stale COOKIE-ECHO UAF LPE (CVE-2026-52924)
CVE-2026-52924 binary Unverified
CRITICAL 9.8
Linux SCTP auth_enable Sysctl UAF LPE (CVE-2026-68162)
CVE-2026-68162 binary Unverified
HIGH 7.8
Linux Open vSwitch Tunnel Netdev UAF LPE (CVE-2026-31678)
CVE-2026-31678 binary Unverified
HIGH 7.8
Linux Netfilter nf_queue Bridge Device UAF LPE (CVE-2026-72255)
CVE-2026-72255 binary Unverified
HIGH 7.8
Linux IPVS One-Packet Flag Propagation UAF LPE (CVE-2026-80714)
CVE-2026-80714 binary Unverified
CRITICAL 9.8
Linux IPv6 fib6 Rule Suppression UAF LPE (CVE-2026-74581)
CVE-2026-74581 binary Unverified
HIGH 7.8
Linux io_uring Poll Signed Comparison LPE (CVE-2026-52933)
CVE-2026-52933 binary Unverified
HIGH 7.8
Linux Bridge Fast-Leave Port Deletion UAF LPE (CVE-2026-74480)
CVE-2026-74480 binary Unverified
CRITICAL 9.8
WP Cookie Notice Unauthenticated File Upload RCE (CVE-2026-82970)
CVE-2026-82970 web Unverified
CRITICAL 10
React Router Session Path Traversal (CVE-2025-61686)
CVE-2025-61686 web Unverified
CRITICAL 9.1
Node.js Permission Model Symlink Escape (CVE-2025-55130)
CVE-2025-55130 binary Unverified
CRITICAL 9.1
Nginx HTTP/3 QUIC Pool Corruption RCE (CVE-2026-42530)
CVE-2026-42530 binary Unverified
HIGH 8.1
Next.js Windows Cache Path Traversal RCE (CVE-2026-75604)
CVE-2026-75604 web Unverified
CRITICAL 9
Linux Netfilter xt_IDLETIMER UAF LPE (CVE-2026-23274)
CVE-2026-23274 binary Unverified
HIGH 7.8
Linux Netfilter nf_queue UAF LPE (CVE-2026-52912)
CVE-2026-52912 binary Unverified
HIGH 7.8
Linux MPLS Subsystem UAF LPE (CVE-2026-43042)
CVE-2026-43042 binary Unverified
HIGH 7.1
Linux Kernel posix-cpu-timers Use-After-Free LPE (CVE-2026-64560)
CVE-2026-64560 binary Unverified
HIGH 7.8
Linux Kernel IPC msg_msg Use-After-Free LPE (CVE-2026-52923)
CVE-2026-52923 binary Unverified
HIGH 7.8
Linux Kernel eventpoll Use-After-Free LPE (CVE-2026-43074)
CVE-2026-43074 binary Unverified
HIGH 7.8
Linux IPv6 RPL Routing UAF LPE (CVE-2026-43501)
CVE-2026-43501 binary Unverified
CRITICAL 9.8
Kestra Authentication Bypass to RCE (CVE-2026-49869)
CVE-2026-49869, CVE-2026-53576 web Unverified
CRITICAL 10
Firefox SpiderMonkey JIT Type Confusion (CVE-2026-10702)
CVE-2026-10702 binary Unverified
MEDIUM 4.3
Chrome V8 Type Confusion RCE (CVE-2026-5865)
CVE-2026-5865 binary Unverified
HIGH 8.8
Windows Media Player DLL Hijack -- Local Privilege Escalation (CVE-2026-21508)
CVE-2026-21508 binary Patched
HIGH 7.8
UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910) KEV EPSS 87%
CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 network Patched
CRITICAL 10
Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)
CVE-2026-68398 binary Patched
HIGH 7.8
PHP bcmath bccomp() Out-of-Bounds Write (CVE-2026-17544)
CVE-2026-17544 / GHSA-x692-q9x7-8c3f web Unverified
CRITICAL 9.8
nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)
CVE-2026-42533 web Patched
CRITICAL 9.8
Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)
CVE-2026-23111 binary Patched
HIGH 7.8
Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)
CVE-2026-53361 binary Patched
CRITICAL 9.8
Firefox SpiderMonkey JIT Miscompilation and Use-After-Free (CVE-2026-2764)
CVE-2026-2764 / MFSA 2026-13 binary Unverified
HIGH 8.8
Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452) KEV
CVE-2026-8452 network Patched
CRITICAL 9.8
Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)
CVE-2026-20200 / NSIDE-SA-2026-003 network Patched
CRITICAL 9.9
Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)
CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7 web Patched
CRITICAL 10
Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)
CVE-2026-47301 network Unverified
CRITICAL 9.8
Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)
CVE-2026-64564 binary Patched
HIGH 7.8
Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)
CVE-2026-68138 binary Patched
HIGH 7.8
Linux Kernel — OVSwrap: Open vSwitch Conntrack Local Privilege Escalation (CVE-2026-64531)
CVE-2026-64531 binary Patched
HIGH 7.8
Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)
CVE-2026-17106 binary Unverified
CRITICAL 9.8
Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)
CVE-2026-27912 network Unverified
HIGH 8
Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks EPSS 11%
Bypass of CVE-2026-50656 (RoguePlanet); no CVE assigned to ShieldBreak as of 2026-08-11 binary Unpatched
HIGH 7.8
Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)
CVE-2026-25177 network Patched
HIGH 8.8
Zapscape — KVM/x86 Shadow-MMU Recursive-Zap Guest-to-Host Escape (CVE-2026-64561)
CVE-2026-64561 binary Patched
HIGH 8.8
WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell") EPSS 31%
CVE-2026-64638 web Unverified
HIGH 8.9
TeamCity — Unauthenticated RCE via Agent Polling Deserialization (CVE-2026-63077) KEV EPSS 88%
CVE-2026-63077 web Patched
CRITICAL 9.8
Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882) KEV RW EPSS 100%
CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025) web Patched
CRITICAL 9.8
MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free
MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet binary Unpatched
CRITICAL 8.8
Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078) KEV RW EPSS 100%
CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD) network Unverified
CRITICAL 9.8
Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457) KEV RW EPSS 100%
CVE-2025-22457 network Unpatched
CRITICAL 9
GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205) KEV RW EPSS 100%
CVE-2021-22205 (chains CVE-2021-22204 in ExifTool) web Patched
CRITICAL 10
Gitea — diffpatch API Git Hook Remote Code Execution (CVE-2026-60004) KEV EPSS 85%
CVE-2026-60004 web Patched
HIGH 8.8
Ghidra — Swift Demangler Arbitrary Code Execution via Shared Project Files (CVE-2026-18718)
CVE-2026-18718 misc Patched
HIGH 7.5
CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378) KEV RW EPSS 95%
CVE-2024-51378 web Patched
CRITICAL 10
Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232) KEV EPSS 72%
CVE-2026-16232 network Patched
CRITICAL 9.1
Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)
CVE-2026-64640 cloud Patched
HIGH 8.1
Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)
NotCVE-2026-0010 (disputed CVE assignment — author contests the identifier) binary Unverified
HIGH
Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)
CVE-2026-65694 (VulnCheck advisory) web Patched
HIGH 7.5
IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198) KEV EPSS 35%
CVE-2026-9198 web Patched
CRITICAL 9.8
CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner) KEV RW EPSS 100%
CVE-2022-40684 network Unverified
CRITICAL 9.8
Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432) KEV EPSS 100%
CVE-2025-32432 web Patched
CRITICAL 10
Apache Tika PDF Parser XXE via Crafted XFA Form (CVE-2025-54988) EPSS 15%
CVE-2025-54988 (GHSA-p72g-pv48-7w9x, Apache JIRA TIKA-4459) web Patched
CRITICAL 9.8
Alibaba Fastjson 1.x checkAutoType Bypass to Remote Code Execution via jar:http SSRF and fd-Reread Trick (CVE-2026-16723) EPSS 16%
CVE-2026-16723 web Unpatched
CRITICAL 9
Windows WalletService Known-Folder Redirection → ESE Persisted-Callback DLL Load Local Privilege Escalation (CVE-2026-49176)
CVE-2026-49176 binary Patched
HIGH 7.8
Windows Message Queuing (MSMQ) Queue Manager Heap-Based Buffer Overflow (CVE-2026-54992)
CVE-2026-54992 network Patched
HIGH 8.4
Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066) EPSS 28%
CVE-2026-66066 (GHSA-xr9x-r78c-5hrm) web Patched
CRITICAL 9.5
MISP Core `deleteSelection` Broken Access Control — Bulk Deletion of Foreign Event Reports & Sharing Groups (CVE-2026-56423)
CVE-2026-56423 web Patched
HIGH 8.8
Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522) KEV EPSS 85%
CVE-2026-50522 web Patched
CRITICAL 9.8
Joomla Helix Ultimate Framework — Unauthenticated Arbitrary File Deletion (CVE-2026-57830)
CVE-2026-57830 web Patched
CRITICAL 9.1
Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291) KEV EPSS 15%
CVE-2026-56291 web Unverified
CRITICAL 9.8
ITScape — KVM/arm64 vGIC-ITS Guest-to-Host VM Escape (CVE-2026-46316)
CVE-2026-46316 (GHSA-qcxh-2cm7-9fcc) binary Patched
CRITICAL 9.3
GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)
N/A (no CVE assigned, no Microsoft advisory as of 2026-07-27) binary Unpatched
HIGH
GitLab Notebook-Diff Oj Parser Memory-Corruption Chain → Unauthenticated-Reach RCE (No CVE Yet)
N/A (no CVE assigned as of 2026-07-27 — researcher disclosure via depthfirst.com blog, covered by The Hacker News) web Unverified
CRITICAL
Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)
CVE-2026-53753 (GHSA-qxjp-w3pj-48m7) web Patched
CRITICAL 9.8
ClickFix Social-Engineering Technique — Fortinet-Branded Multi-Stage Lure (Fake File-Access Page + Fake CAPTCHA + Clipboard Injection)
N/A (social-engineering technique, not a software vulnerability) social-engineering Unverified
HIGH
ClickFix Social Engineering Technique — Fake Cloudflare Turnstile Just a Moment Verification Lure
N/A (social-engineering technique, not a software vulnerability) social-engineering Unverified
HIGH
ClickFix Fake-CAPTCHA Social-Engineering Kit with IP Fencing and 19-Language Localization
N/A (social-engineering technique, not a software vulnerability) social-engineering Unverified
HIGH
ClickFix Fake reCAPTCHA to mshta/HTA Execution Chain
N/A (social-engineering technique, not a software vulnerability) social-engineering Unverified
HIGH
Budibase Unauthenticated NoSQL Operator Injection (CVE-2026-54350)
CVE-2026-54350 (GHSA-8qv3-p479-cj62) web Patched
CRITICAL 10
Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)
CVE-2026-49230 web Patched
CRITICAL 9.1
AD CS/AD FS Enrollment "cdc" Chase Attribute Abuse → Domain Controller Impersonation (CertiGhost, CVE-2026-54121)
CVE-2026-54121 network Patched
HIGH 8.8
wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137) KEV EPSS 97%
CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf web Patched
CRITICAL 9.1
V8 Array Iterator Maglev Type Confusion — addrof/fakeobj Primitives (CVE-2026-14431)
CVE-2026-14431 binary Unpatched
HIGH 8.8
SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558) KEV EPSS 12%
CVE-2026-48558 web Patched
CRITICAL 10
LLaMA-Factory WebUI Remote Code Execution via Hardcoded `trust_remote_code` (CVE-2026-58116)
CVE-2026-58116 web Patched
CRITICAL 9.8
LegacyHive - Windows user profile service arbitrary hive load elevation of privileges vulnerability
binary Patched
HIGH
Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255) KEV
CVE-2026-55255 (GHSA-qrpv-q767-xqq2) web Patched
HIGH 8.4
Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW) network Patched
CRITICAL 8.6
Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282) KEV EPSS 42%
CVE-2026-48282 (Adobe APSB26-68) web Patched
CRITICAL 10
SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409) KEV RW EPSS 84%
CVE-2026-15409 (SNWLID-2026-0008) network Patched
CRITICAL 10
OpenSSH Forwarded-Agent Lock/Unlock State Confusion → Unauthorized PKCS#11 Provider Load (No CVE)
network Unpatched
HIGH
Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8) web Patched
CRITICAL 9.8
Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
CVE-2026-56260 (GHSA-365w-hqf6-vxfg) web Patched
CRITICAL 9.1
ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950) KEV EPSS 85%
CVE-2023-38950 web Patched
HIGH 7.5
Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939) KEV EPSS 20%
CVE-2026-48939 web Patched
CRITICAL 9.8
Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237) KEV RW EPSS 98%
CVE-2021-42237 (Sitecore advisory SC2021-003-499266) web Patched
CRITICAL 9.8
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296) KEV EPSS 72%
CVE-2021-25296 web Patched
HIGH 8.8
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297) KEV EPSS 57%
CVE-2021-25297 web Patched
HIGH 8.8
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298) KEV EPSS 75%
CVE-2021-25298 web Patched
HIGH 8.8
LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208) KEV EPSS 89%
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc) web Patched
CRITICAL 9.8
Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)
CVE-2026-20896 (GHSA-f75j-4cw6-rmx4) web Patched
CRITICAL 9.8
D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258) KEV EPSS 80%
CVE-2022-26258 network Unverified
CRITICAL 9.8
XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)
network Unpatched
CRITICAL
Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)
CVE-2026-43499 (aka "GhostLock") binary Patched
HIGH 7.8
XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893) KEV EPSS 100%
CVE-2025-24893 web Patched
CRITICAL 9.8
XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322) EPSS 15%
CVE-2025-54322 network Unpatched
CRITICAL 10
Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)
CVE-2025-65856 hardware Unverified
CRITICAL 9.8
WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)
CVE-2025-11170 web Unpatched
CRITICAL 9.8
WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)
CVE-2025-13390 web Patched
CRITICAL 10
WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
CVE-2025-39401 web Unverified
CRITICAL 10
WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)
CVE-2025-49901 web Patched
CRITICAL 9.8
WordPress Service Finder Bookings ≤ 6.0 Authentication Bypass via `original_user_id` Cookie (CVE-2025-5947)
CVE-2025-5947 web Unverified
CRITICAL 9.8
WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)
CVE-2025-68860 web Unpatched
CRITICAL 9.8
WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440) EPSS 31%
CVE-2025-6440 web Unverified
CRITICAL 9.8
Wing FTP Server NULL-Byte Lua Injection Unauthenticated RCE (CVE-2025-47812) KEV EPSS 93%
CVE-2025-47812 web Patched
CRITICAL 10
Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
CVE-2025-29009 web Patched
CRITICAL 10
WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
CVE-2025-12057 web Unverified
CRITICAL 9.8
Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass & Admin Credential Log Leak (CVE-2025-13315) EPSS 33%
CVE-2025-13315 network Unpatched
CRITICAL 9.8
TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)
CVE-2025-12539 web Patched
CRITICAL 10
tj-actions/branch-names GitHub Actions Command Injection (CVE-2025-54416)
CVE-2025-54416 cloud Patched
CRITICAL 9.1
ThinkPHP 5.0.24 File Inclusion Leading to Remote Code Execution (CVE-2025-63888)
CVE-2025-63888 web Unverified
CRITICAL 9.8
ThingsBoard IoT Platform SSRF via SVG Image Upload (CVE-2025-34282)
CVE-2025-34282 web Patched
CRITICAL 9.1
Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)
CVE-2025-29384 network Unpatched
CRITICAL 9.8
Sudo `chroot` Option Local Privilege Escalation (CVE-2025-32463) KEV EPSS 59%
CVE-2025-32463 binary Patched
CRITICAL 9.3
StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441) EPSS 39%
CVE-2025-7441 web Unpatched
CRITICAL 9.8
StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148) EPSS 15%
CVE-2025-48148 web Unverified
CRITICAL 9.8
Squid Proxy Sensitive Header Leak via Error Page `mailto:` Diagnostic Block (CVE-2025-62168) EPSS 63%
CVE-2025-62168 network Patched
CRITICAL 10
Spring Cloud Gateway Actuator RCE — Vulnerable Environment Lab (CVE-2025-41243)
CVE-2025-41243 web Unpatched
CRITICAL 10
Sneeit Framework <= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389) EPSS 76%
CVE-2025-6389 web Unverified
CRITICAL 9.8
SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001) KEV RW EPSS 86%
CVE-2025-52691 web Patched
CRITICAL 10
Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)
CVE-2025-4334 web Unverified
CRITICAL 9.8
Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
CVE-2025-53580 web Patched
CRITICAL 9.8
SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324) KEV RW EPSS 100%
CVE-2025-31324 web Patched
CRITICAL 10
Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632) KEV EPSS 24%
CVE-2025-4632 web Patched
CRITICAL 9.8
safe-expr-eval: Mitigation Library for the expr-eval Unsafe eval() RCE (CVE-2025-12735)
CVE-2025-12735 misc Patched
CRITICAL 9.8
RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926) EPSS 31%
CVE-2025-68926 cloud Patched
CRITICAL 9.8
Roundcube Webmail Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113) KEV EPSS 99%
CVE-2025-49113 web Patched
CRITICAL 9.9
RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)
CVE-2025-9209 web Unpatched
CRITICAL 9.8
RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844) EPSS 87%
CVE-2025-49844 binary Patched
CRITICAL 9.9
Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)
CVE-2025-6758 web Unverified
CRITICAL 9.8
React Server Components Flight-Protocol Prototype Pollution RCE — "React2Shell" (CVE-2025-55182) KEV RW EPSS 100%
CVE-2025-55182 web Patched
CRITICAL 10
React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953) KEV EPSS 94%
CVE-2025-11953 network Patched
CRITICAL 9.8
Python tarfile `filter="data"` Bypass via PATH_MAX/realpath Confusion (CVE-2025-4517)
CVE-2025-4517 misc Patched
CRITICAL 9.4
Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132) EPSS 53%
CVE-2025-49132 web Patched
CRITICAL 10
PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)
CVE-2025-61922 web Patched
CRITICAL 9.1
PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391 web Patched
CRITICAL 9.8
Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)
CVE-2025-10147 web Unverified
CRITICAL 9.8
pgAdmin 4 Restore Feature Regex-Bypass Command Injection RCE (CVE-2025-13780)
CVE-2025-13780 web Unverified
CRITICAL 9.1
pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945) EPSS 54%
CVE-2025-2945 web Patched
CRITICAL 9.9
Oracle Identity Manager `;.wadl` Authentication Bypass + Groovy Script RCE (CVE-2025-61757) KEV EPSS 88%
CVE-2025-61757 web Unpatched
CRITICAL 9.8
Opal Estate Pro WordPress Plugin Unauthenticated Administrator Registration (CVE-2025-6934) EPSS 25%
CVE-2025-6934 web Unverified
CRITICAL 9.8
Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299) EPSS 73%
CVE-2025-34299 network Patched
CRITICAL 9.8
Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)
CVE-2025-23061 web Patched
CRITICAL 9
Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)
CVE-2025-52913 network Unverified
CRITICAL 9.8
Laravel Livewire Remote Code Execution via Known APP_KEY (CVE-2025-54068) KEV EPSS 96%
CVE-2025-54068 web Patched
CRITICAL 9.8
Laravel `files.*` Wildcard Validation Bypass via Polyglot JPEG+PHP Upload (CVE-2025-27515)
CVE-2025-27515 web Patched
CRITICAL 9.8
Langflow Pre-Auth RCE Mass Scanner (CVE-2026-27966) EPSS 34%
CVE-2026-27966 (GHSA-3645-fxcv-hqr4) web Patched
CRITICAL 9.8
Kubio AI Page Builder <= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294) EPSS 78%
CVE-2025-2294 web Unverified
CRITICAL 9.8
KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
CVE-2025-12674 web Unverified
CRITICAL 9.8
JAY Login & Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)
CVE-2025-14440 web Unverified
CRITICAL 9.8
Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916) EPSS 84%
CVE-2025-47916 web Patched
CRITICAL 10
IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974) EPSS 100%
CVE-2025-1974 cloud Unverified
CRITICAL 9.8
HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164) KEV EPSS 90%
CVE-2025-37164 network Unpatched
CRITICAL 10
Hoverfly Middleware Command Injection to RCE (CVE-2025-54123) EPSS 11%
CVE-2025-54123 web Patched
CRITICAL 9.8
Grafana Enterprise SCIM User ID Collision / Impersonation (CVE-2025-41115) EPSS 19%
CVE-2025-41115 web Patched
CRITICAL 10
Gladinet CentreStack / Triofox Hardcoded AES Key Access-Ticket Forgery to Arbitrary File Read (CVE-2025-14611) KEV EPSS 53%
CVE-2025-14611 web Unverified
CRITICAL 9.8
GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
CVE-2025-22777 web Patched
CRITICAL 9.8
Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
CVE-2025-13342 web Patched
CRITICAL 9.8
FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819) KEV EPSS 88%
CVE-2025-57819 web Patched
CRITICAL 9.8
FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)
CVE-2025-66039 network Patched
CRITICAL 9.8
Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)
CVE-2025-14156 web Unverified
CRITICAL 9.8
FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446) KEV EPSS 92%
CVE-2025-64446 network Unverified
CRITICAL 9.8
FortiOS/FortiProxy/FortiSwitchManager/FortiWeb FortiCloud SSO Authentication Bypass Detection Tool (CVE-2025-59718) KEV EPSS 69%
CVE-2025-59718 (Fortinet advisory FG-IR-25-647; related: CVE-2025-59719) network Patched
CRITICAL 9.8
Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
CVE-2025-49071 web Unverified
CRITICAL 9.8
FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434) EPSS 50%
CVE-2025-58434 web Patched
CRITICAL 9.8
Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528) EPSS 87%
CVE-2025-59528 web Patched
CRITICAL 10
FiberHome HG6145F1 Predictable Default Wi-Fi PSK Derived from Broadcast SSID (CVE-2025-63353)
CVE-2025-63353 / GHSA-cg2x-c25f-6327 network Patched
CRITICAL 9.8
Dolby Unified (DDPlus) Decoder Out-of-Bounds Write via Evolution Data (CVE-2025-54957)
CVE-2025-54957 binary Unverified
CRITICAL 9.8
Django QuerySet/Q Object SQL Injection via `_connector` Kwarg (CVE-2025-64459) EPSS 19%
CVE-2025-64459 web Patched
CRITICAL 9.1
DataEase PostgreSQL JDBC Datasource-Validation Bypass to Remote Code Execution (CVE-2025-49002) EPSS 47%
CVE-2025-49002 web Patched
CRITICAL 9.8
D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
CVE-2025-60854 network Patched
CRITICAL 9.8
CrushFTP AS2 Header Authentication Bypass (CVE-2025-54309) KEV EPSS 95%
CVE-2025-54309 web Patched
CRITICAL 9
Crafty Controller Webhook Jinja2 Server-Side Template Injection RCE (CVE-2025-14700)
CVE-2025-14700 web Unverified
CRITICAL 9.9
ConnectWise Automate Adversary-in-the-Middle Remote Code Execution (CVE-2025-11492)
CVE-2025-11492 network Patched
CRITICAL 9.6
Cisco AsyncOS Spam Quarantine (TCP/6025) Exposure & IOC Scanner (CVE-2025-20393) KEV EPSS 30%
CVE-2025-20393 network Unverified
CRITICAL 10
Cisco ASA/FTD WebVPN File-Handler Heap Buffer Overflow Exposure Scanner (CVE-2025-20333) KEV EPSS 71%
CVE-2025-20333 network Unverified
CRITICAL 9.9
Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)
CVE-2025-13595 web Unverified
CRITICAL 9.8
camel-coap Header Injection → RCE Self-Contained Reproducer (CVE-2026-33453)
CVE-2026-33453 web Unverified
CRITICAL 9.8
ASP.NET Core Kestrel HTTP Request Smuggling (CVE-2025-55315) EPSS 66%
CVE-2025-55315 network Patched
CRITICAL 9.9
Apache Parquet-Avro Schema Deserialization RCE/SSRF — Incomplete-Fix Bypass (CVE-2025-30065) EPSS 43%
CVE-2025-30065 misc Patched
CRITICAL 9.8
Apache mod_ssl TLS 1.3 Session Resumption Client Certificate Bypass (CVE-2025-23048)
CVE-2025-23048 web Patched
CRITICAL 9.1
Apache Druid Kerberos Cookie-Signing Secret Recovery via ThreadLocalRandom Seed Inversion (CVE-2025-59390)
CVE-2025-59390 crypto Patched
CRITICAL 9.8
Apache Camel `camel-consul` ConsulRegistry Deserialization RCE (CVE-2026-27172)
CVE-2026-27172 web Patched
CRITICAL 9.8
AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)
CVE-2025-13597 web Unverified
CRITICAL 9.8
AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749) EPSS 75%
CVE-2025-11749 web Unverified
CRITICAL 9.8
Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236) KEV EPSS 95%
CVE-2025-54236 web Patched
CRITICAL 9.1
Adobe Experience Manager Forms XXE to JNDI RCE Scanner (CVE-2025-54253) KEV EPSS 88%
CVE-2025-54253 web Unverified
CRITICAL 10
ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486) EPSS 68%
CVE-2025-13486 web Unverified
CRITICAL 9.8
"Grocery" PHP Application `search_products_itname.php` `sitem_name` Boolean-Based SQL Injection (CVE-2025-65354)
CVE-2025-65354 web Unpatched
CRITICAL 9.8
Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)
CVE-2026-1459 network Unverified
HIGH
ZXIC/Sanechips ZX297520V3 BootROM Arbitrary Memory Write via USB Download Mode (CVE-2026-40003)
CVE-2026-40003 hardware Unverified
HIGH
ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474) EPSS 25%
CVE-2026-34474 network Unverified
HIGH
ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)
CVE-2026-34472 network Unverified
CRITICAL
ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)
CVE-2026-34473 network Unverified
HIGH
ZoneMinder — Second-Order SQL Injection via Event Rename (CVE-2026-27470)
CVE-2026-27470 web Patched
HIGH 8.8
ZimaOS Arbitrary File Write via Unvalidated File API Path — CVE-2026-28286
CVE-2026-28286 web Unverified
CRITICAL
ZAI-Shell — Unauthenticated Remote Code Execution via P2P Terminal Sharing (CVE-2026-25807)
CVE-2026-25807 network Patched
CRITICAL
YayMail WooCommerce Plugin Missing Authorization to Privilege Escalation — CVE-2026-1937
CVE-2026-1937 web Unverified
HIGH 7.2
YAMCS Unauthorized User Enumeration via IAM API (CVE-2026-44595)
CVE-2026-44595 / GHSA-p2rj-mrmc-9w29 web Patched
MEDIUM 4.3
YAMCS Missing Rate Limiting on Authentication Endpoint (CVE-2026-44596)
CVE-2026-44596 / GHSA-w5r6-mcgq-7pq4 web Patched
MEDIUM 5.3
YAMCS LdapAuthModule LDAP Injection Authentication Bypass (CVE-2026-42568)
CVE-2026-42568 / GHSA-cqh3-jg8p-336j network Patched
MEDIUM
XWiki Unauthenticated XAR Import Leading to RCE — CVE-2026-33137
CVE-2026-33137 web Patched
CRITICAL 9.3
XNU PF_ROUTE RTA_GENMASK Heap Buffer Overflow (CVE-2026-20698)
CVE-2026-20698 binary Patched
HIGH
XIGNCODE3 Anti-Cheat Driver PPL-Bypass LSASS Credential Dump (CVE-2026-3609)
CVE-2026-3609 binary Patched
HIGH
Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)
CVE-2026-39912 web Patched
CRITICAL 9.1
Wyze Cam Pan v3 / TUTK SDK — tutk_packet_alloc Heap Overflow (CVE-2026-38698)
CVE-2026-38698 network Unverified
CRITICAL
WPvivid Backup & Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357) EPSS 33%
CVE-2026-1357 web Unverified
CRITICAL
WP Zendesk for Contact Form 7 Unauthenticated PHP Object Injection (CVE-2026-49105)
CVE-2026-49105 web Unverified
HIGH 8.1
WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)
CVE-2026-40791 web Patched
HIGH 7.2
WP Photo Album Plus Unauthenticated SQL Injection — CVE-2026-6379
CVE-2026-6379 web Patched
CRITICAL 8.6
WP Insightly Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49085)
CVE-2026-49085 web Unverified
HIGH 8.1
WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415
CVE-2026-5415 web Unverified
HIGH 8.8
WP Activity Log Unauthenticated PHP Object Injection — CVE-2026-54806
CVE-2026-54806 web Patched
CRITICAL 9.8
WordPress User Language Switch Plugin SSRF — CVE-2026-0745
CVE-2026-0745 (GHSA-m38c-5p3m-p7gm) web Unverified
MEDIUM
WordPress SignUp/SignIn & Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)
CVE-2026-12416, CVE-2026-12417 web Unverified
CRITICAL 9.8
WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740 EPSS 63%
CVE-2026-0740 web Unverified
HIGH
WordPress HT Mega (Absolute Addons for Elementor) Unauthenticated PII Disclosure (CVE-2026-4106)
CVE-2026-4106 web Unverified
HIGH
WordPress Download Manager 3.3.5.2 — Unauthenticated IDOR (CVE-2026-39676)
CVE-2026-39676 web Unverified
MEDIUM
WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180
CVE-2026-3180 web Unverified
HIGH
WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844) EPSS 28%
CVE-2026-3844 web Unverified
CRITICAL
WordPress "List Site Contributors" Plugin Reflected XSS Scanner (CVE-2026-0594)
CVE-2026-0594 web Unverified
MEDIUM
WordPress "Import and Export Users and Customers" Plugin Privilege Escalation (CVE-2026-3629)
CVE-2026-3629 web Unverified
CRITICAL
WordPress "Form Maker" Plugin Unauthenticated SQL Injection — CVE-2026-3359
CVE-2026-3359 web Unverified
CRITICAL
WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364
CVE-2026-5364 web Unverified
HIGH 8.1
WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
CVE-2026-27542 (bundled with CVE-2026-27540) web Unverified
CRITICAL 9.8
WooCommerce Frontend Registration Form Unauthenticated Admin Role Assignment — CVE-2026-54807
CVE-2026-54807 web Unverified
INFO
Wing FTP Server Admin Session Poisoning via Lua loadfile() RCE (CVE-2026-44403)
CVE-2026-44403 web Patched
HIGH
Windows ShellLink (.lnk) Remote Code Execution — CVE-2026-21510 LNK-Stomping Generator KEV EPSS 26%
CVE-2026-21510 social-engineering Unverified
HIGH
Windows Shell LNK _IDCONTROLW Zero-Click SMB Coercion Builder — CVE-2026-32202 KEV EPSS 64%
CVE-2026-32202 (related: CVE-2026-21510) binary Unverified
HIGH
Windows Server 2025 Local NTLM Reflection LPE via SMB Arbitrary Port + PetitPotam (CVE-2026-24294)
CVE-2026-24294 (Microsoft Security Response Center) network Patched
CRITICAL
Windows Secure Kernel (VTL1/VSM) Memory Corruption PoC (CVE-2026-26179 / ZDI-26-276)
CVE-2026-26179 / ZDI-26-276 binary Unverified
HIGH
Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)
CVE-2026-42978 binary Unverified
HIGH 7.8
Windows pstrip64.sys BYOVD Physical Memory Local Privilege Escalation — CVE-2026-29923
CVE-2026-29923 binary Unverified
CRITICAL
Windows Kernel Local Privilege Escalation via SeDebugPrivilege Bit Corruption (CVE-2026-40369)
CVE-2026-40369 binary Unverified
HIGH
Windows Kerberos Reflection via Unicode SPN Normalization Bypass (CVE-2026-26128)
CVE-2026-26128 network Unverified
CRITICAL
Windows ikeext.dll IKEv2 Double-Free Remote Kernel Exploit — CVE-2026-33824 KEV EPSS 73%
CVE-2026-33824 network Patched
CRITICAL
Windows HTTP.sys Header-Count-Triggered Kernel Memory Corruption / BSOD (CVE-2026-49160) EPSS 54%
CVE-2026-49160 binary Patched
HIGH
Windows Error Reporting Service ALPC Local Privilege Escalation (CVE-2026-20817)
CVE-2026-20817 binary Unverified
HIGH
Windows CLFS.sys Unrecoverable State / BSoD via ReadFile on Log File Handle (CVE-2026-2636)
CVE-2026-2636 binary Patched
MEDIUM
WeGIA Authenticated Error-Based SQL Injection Exploitation Helper (CVE-2026-23723)
CVE-2026-23723 / GHSA-xfmp-2hf9-gfjp web Patched
HIGH
WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555
CVE-2026-1555 web Unverified
CRITICAL 9.8
WebSocket Authentication Brute-Force via Missing Rate Limiting (CVE-2026-27778)
CVE-2026-27778 web Patched
MEDIUM
Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126
CVE-2026-24126 web Patched
HIGH 6.5
WebKit WebGPU `importExternalTexture` Cross-Origin Video Frame Leak (CVE-2026-43700)
CVE-2026-43700 web Unverified
HIGH
WebKit Navigation API Cross-Port canIntercept Bypass (CVE-2026-20643)
CVE-2026-20643 web Unverified
MEDIUM
WebKit Navigation API `NavigateEvent.sourceElement` Cross-Origin DOM Leak (CVE-2026-43735)
CVE-2026-43735 web Unverified
HIGH
VvvebJs SVG Upload Stored Cross-Site Scripting — CVE-2026-5615
CVE-2026-5615 web Patched
HIGH 8.5
Visitor Management System 1.0 — Unrestricted File Upload to RCE (CVE-2026-37748)
CVE-2026-37748 web Unverified
HIGH 7.2
VirtualBox DevVGA_VBVA Integer Overflow leading to Guest-Triggerable DoS (CVE-2026-35250)
CVE-2026-35250 binary Unverified
LOW 2.3
Vim Modeline `path` Option Backtick-Expansion Command Injection (CVE-2026-44656)
CVE-2026-44656 binary Patched
HIGH
Veno File Manager Unauthenticated User Enumeration (CVE-2026-37064)
CVE-2026-37064 web Unverified
MEDIUM
Veno File Manager Path Traversal to Arbitrary File Read (CVE-2026-37066)
CVE-2026-37066 web Unverified
HIGH
Veno File Manager Incorrect Access Control — Application Log Extraction (CVE-2026-37067)
CVE-2026-37067 web Unverified
MEDIUM
Veno File Manager Arbitrary PHP File Overwrite (CVE-2026-37068)
CVE-2026-37068 web Unverified
CRITICAL
Veno File Manager Arbitrary File Deletion (CVE-2026-37065)
CVE-2026-37065 web Unverified
HIGH
Veno File Manager Absolute Path Disclosure (CVE-2026-37069)
CVE-2026-37069 web Unverified
LOW
Veno File Manager 4.4.9 — Unauthenticated LFI to Superadmin Takeover (CVE-2026-37072)
CVE-2026-37072 web Unverified
CRITICAL
Veno File Manager 4.4.9 — Unauthenticated Email Hijack via SMTP Relay (CVE-2026-37073)
CVE-2026-37073 web Unverified
MEDIUM
Veno File Manager 4.4.9 — Authenticated Arbitrary File Read (CVE-2026-37070)
CVE-2026-37070 web Unverified
MEDIUM
Veno File Manager 4.4.9 — Arbitrary File Rename to Privilege Escalation (CVE-2026-37071)
CVE-2026-37071 web Unverified
HIGH
Vendure GraphQL Admin API Authentication Timing Attack / User Enumeration (CVE-2026-25050)
CVE-2026-25050 web Patched
MEDIUM
Vaultwarden Organization Collection Permissions Bypass & Cipher Enumeration (CVE-2026-26012)
CVE-2026-26012 (GHSA-h265-g7rm-h337) web Patched
MEDIUM 6.5
V8 JavaScript Engine Exploit — "Longinus" Kit (CVE-2026-6307)
CVE-2026-6307 binary Unverified
CRITICAL
User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)
CVE-2026-4882 web Unverified
CRITICAL 9.8
User Registration & Membership Unauthenticated Admin Privilege Escalation (CVE-2026-1492) EPSS 24%
CVE-2026-1492 web Unverified
CRITICAL 9.8
User Registration & Membership for WordPress — Unauthenticated Admin Approval Bypass (CVE-2026-6145)
CVE-2026-6145 web Unverified
MEDIUM 5.3
UpdraftPlus WordPress Plugin — Unauthenticated RPC Key Bypass to Admin Creation & RCE (CVE-2026-10795)
CVE-2026-10795 web Unverified
CRITICAL
UnPoller Path Traversal / Arbitrary File Read via file:// Password Prefix (CVE-2026-36851)
CVE-2026-36851 misc Unverified
HIGH 7.5
Unauthenticated SSRF in Ech0 via /api/website/title (CVE-2026-35037)
CVE-2026-35037 web Patched
HIGH
Unauthenticated NaN Injection via MAVLink PARAM_SET in ArduPilot ArduPlane (CVE-2026-36522)
CVE-2026-36522 network Unverified
CRITICAL 9.1
TypiCMS Core — Stored XSS via Unsanitized SVG File Upload (CVE-2026-27621)
CVE-2026-27621 (GHSA-xfvg-8v67-j7wp) web Patched
MEDIUM
Typebot Unauthenticated Preview-Chat SSRF — CVE-2026-33712
CVE-2026-33712 web Patched
HIGH
TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651
CVE-2026-0651 (chained with CVE-2026-0652, CVE-2026-0653) network Unverified
CRITICAL
TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834
CVE-2026-11834 network Unverified
CRITICAL
TP-Link Archer C64 Web UI Rate-Limit Bypass via Residual Debug SSH Service (CVE-2026-8697)
CVE-2026-8697 network Unverified
CRITICAL 9.3
Tornet Scooter Mobile App OTP Brute Force via Missing Rate Limiting (CVE-2026-7671)
CVE-2026-7671 web Unverified
MEDIUM
Thymeleaf SpEL Injection Remote Code Execution (CVE-2026-41901)
CVE-2026-41901 web Patched
CRITICAL
The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)
CVE-2026-49772 web Patched
CRITICAL 9.3
Termix Stored XSS via Malicious SVG Upload -> LFI / Session Hijack (CVE-2026-22804 / GHSA-m3cv-5hgp-hv35)
CVE-2026-22804 (GHSA-m3cv-5hgp-hv35) web Patched
HIGH
Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499
CVE-2026-11499 network Unverified
HIGH
Tasmota fetch_jpg() strcpy() Buffer Overflow in boundary[40] (CVE-2026-38426)
CVE-2026-38426 network Patched
CRITICAL 9.8
Tasmota fetch_jpg() Integer Wraparound to Heap Corruption (CVE-2026-38427)
CVE-2026-38427 network Patched
CRITICAL 9.8
Tasmota fetch_jpg() Combined Buffer Overflow RCE Chain (CVE-2026-38422)
CVE-2026-38422 network Patched
CRITICAL 9.8
TanStack Query — Unbounded Recursion Denial of Service in `replaceEqualDeep` (CVE-2026-26903)
CVE-2026-26903 web Patched
MEDIUM
Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)
CVE-2026-25964 (GHSA-6485-jr28-52xx) web Patched
MEDIUM 4.9
Supply Chain Command Injection in AWS CDK's NodejsFunction — CVE-2026-11417
CVE-2026-11417 cloud Patched
HIGH 3.1
strongSwan RADIUS Attribute-Iterator Pre-Auth Infinite Loop / Remote DoS (CVE-2026-35333)
CVE-2026-35333 network Unverified
MEDIUM
strongSwan EAP-SIM/EAP-AKA Pre-Auth Heap Buffer Overflow via Integer Underflow (CVE-2026-35330)
CVE-2026-35330 network Unverified
HIGH
Strapi CMS Admin Account Takeover via Query Filter Bypass — CVE-2026-27886
CVE-2026-27886 web Patched
CRITICAL
Spring Security Lazy Header Writing Security Header Bypass (CVE-2026-22732)
CVE-2026-22732 web Patched
CRITICAL 9.1
Spring AI SimpleVectorStore SpEL Injection RCE (CVE-2026-22738)
CVE-2026-22738 web Patched
CRITICAL 9.8
Splunk Secure Gateway jsonpickle Deserialization RCE (CVE-2026-20251) EPSS 32%
CVE-2026-20251 web Unverified
HIGH 8.8
Spinnaker Clouddriver — Git Clone Shell Injection RCE (CVE-2026-32604)
CVE-2026-32604 (CWE-78) cloud Patched
CRITICAL 10
Spectra Gutenberg Blocks Authenticated Remote Code Execution — CVE-2026-7465
CVE-2026-7465 web Unverified
CRITICAL 8.8
Sparx Enterprise Architect / Pro Cloud Server Unauthenticated Binary-Protocol SQL Injection (CVE-2026-42096)
CVE-2026-42096 network Unverified
CRITICAL
SP LMS PHP Object Injection → Unauthenticated RCE (CVE-2026-48909)
CVE-2026-48909 (GHSA-gf8c-xmwj-whrh) web Patched
CRITICAL 9.5
SonicWall SMA 8200v Cross-Parameter Blind SQL Injection to Root (CVE-2026-4112)
CVE-2026-4112 (SonicWall Advisory SNWLID-2026-0003) network Unverified
HIGH 7.2
Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056) EPSS 12%
CVE-2026-1056 web Unverified
CRITICAL
snapd snap-confine / systemd-tmpfiles Race Condition LPE (CVE-2026-3888)
CVE-2026-3888 binary Patched
HIGH
SmarterMail Unauthenticated Admin Password Reset (CVE-2026-0001 / WT-2026-0001)
CVE-2026-0001 (tracked publicly as WT-2026-0001) web Patched
CRITICAL 9
SmarterMail ConnectToHub Unauthenticated SSRF Leading to Remote Command Execution — CVE-2026-24423 KEV RW EPSS 88%
CVE-2026-24423 web Unverified
CRITICAL
SmarterMail Admin Password-Reset Authentication Bypass (CVE-2026-23760) KEV RW EPSS 96%
CVE-2026-23760 web Patched
CRITICAL 9.3
Sliver C2 Server mTLS Nil-Pointer Panic / Infrastructure Kill-Switch — CVE-2026-29781
CVE-2026-29781 (GHSA-hx52-cv84-jr5v) network Unverified
HIGH
Sliver C2 MCP Server Unauthenticated CORS/Preflight Bypass (CVE-2026-34227)
CVE-2026-34227 (GHSA-6fpf-248c-m7wm) web Unverified
HIGH
SimpleHelp OIDC Authentication Bypass (CVE-2026-48558) KEV EPSS 12%
CVE-2026-48558 web Patched
CRITICAL 9.8
Simple History Missing Authorization Account Takeover — CVE-2026-7459
CVE-2026-7459 web Unverified
HIGH 7.5
Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912
CVE-2026-11912 web Patched
HIGH 7.5
Shopware Twig Rendered-View Code Injection Regression (CVE-2026-23498)
CVE-2026-23498 web Patched
HIGH
Sherlock CI `pull_request_target` Command Injection → GitHub Actions Secret Exfiltration (CVE-2026-44590)
CVE-2026-44590 cloud Patched
CRITICAL 9.3
Sequelize ORM JSON Cast SQL Injection — CVE-2026-30951
CVE-2026-30951 web Patched
HIGH
sealed-env Unseal Token TOTP/Enterprise Secret Disclosure (CVE-2026-45091)
CVE-2026-45091 crypto Patched
HIGH
School Management System 1.0 — Reflected XSS in register.php (CVE-2026-37750)
CVE-2026-37750 web Unverified
MEDIUM 6.1
Schema & Structured Data for WP & AMP Unauthenticated Unrestricted File Upload (CVE-2026-9067)
CVE-2026-9067 web Unverified
HIGH 8.1
Samsung SveService Native Out-of-Bounds Write (CVE-2026-21018)
CVE-2026-21018 (Samsung SVE-2026-0478, SMR May 2026) binary Unverified
HIGH
Samsung Android AT-Command Filter Bypass to system_server Code Execution (CVE-2026-20980)
CVE-2026-20980 (chained with CVE-2026-20981 and CVE-2026-20982) binary Unverified
CRITICAL
samlify SAML AttributeValue XML Injection → Privilege Escalation (CVE-2026-46490)
CVE-2026-46490 / GHSA-34r5-q4jw-r36m web Patched
HIGH 8.8
Samba spoolss Print Job Command Injection RCE (CVE-2026-4480) EPSS 14%
CVE-2026-4480 network Patched
CRITICAL
Saleor Stored XSS via Unrestricted File Upload (CVE-2026-23499)
CVE-2026-23499 web Patched
HIGH
Saleor Rich Text (EditorJS) Field Stored XSS (CVE-2026-22849)
CVE-2026-22849 (GHSA-8jcj-r5g2-qrpv) web Patched
HIGH
Saleor GraphQL IDOR — Unauthenticated Order PII Exfiltration (CVE-2026-24136)
CVE-2026-24136 web Patched
HIGH 7.5
RustFS — Presigned POST Policy Condition Bypass (CVE-2026-27607)
CVE-2026-27607 (GHSA-w5fh-f8xh-5x3p) cloud Patched
HIGH
RTF Protected-View Bypass (CVE-2026-21514) Chained with ShellLink RCE (CVE-2026-21510) — Builder Scripts KEV
CVE-2026-21514, CVE-2026-21510 social-engineering Unverified
HIGH
Rocket.Chat OAuth2 NoSQL Injection Privilege Escalation — CVE-2026-29198
CVE-2026-29198 web Patched
CRITICAL
rldns 1.3 Heap-Based Out-of-Bounds Read Remote DoS (CVE-2026-27831)
CVE-2026-27831 binary Patched
MEDIUM
Responsive Filemanager 9.14.0 — Unauthenticated RCE via Duplicate File (CVE-2026-39023)
CVE-2026-39023 web Unpatched
CRITICAL
Red Hat Cockpit `logsJournal.jsx` Shell Injection RCE (CVE-2026-4802)
CVE-2026-4802 web Unpatched
HIGH
Realtime Collaboration Platform — CORS Misconfiguration Leading to Authenticated Data Exposure (CVE-2026-27579)
CVE-2026-27579 (GHSA-qh5m-p8jh-hx88) web Unverified
HIGH 7.4
Realtek rtl819x Jungle SDK Unauthenticated Kernel Memory R/W via Debug IOCTLs (CVE-2026-36355)
CVE-2026-36355 network Unverified
CRITICAL
rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)
CVE-2026-41179 web Patched
CRITICAL 9.8
Rapid7 Nexpose Weak Keystore Entropy Credential Decryption — CVE-2026-1814
CVE-2026-1814 misc Unverified
HIGH
Rack::Session::Cookie Decrypt-Failure Fallback to Unencrypted Cookies (CVE-2026-39324)
CVE-2026-39324 / GHSA-33qg-7wpp-89cq web Patched
CRITICAL
pypdf Circular Outline Reference Infinite-Loop DoS (CVE-2026-24688)
CVE-2026-24688 misc Patched
HIGH
PX4-Autopilot tattu_can Driver — CAN Bus Stack Buffer Overflow DoS (CVE-2026-32707)
CVE-2026-32707 (GHSA-wxwm-xmx9-hr32, CWE-121) hardware Patched
HIGH 7.5
PX4 Autopilot MAVLink FTP Stack Buffer Overflow (CVE-2026-32743)
CVE-2026-32743 hardware Patched
MEDIUM 6.5
psf/black GitHub Action RCE via Insecure Regex Version Validation — CVE-2026-31900
CVE-2026-31900 (GHSA-v53h-f6m7-xcgm) misc Patched
HIGH 8.7
ProjeQtor Unauthenticated Login SQL Injection (CVE-2026-41462)
CVE-2026-41462 web Patched
CRITICAL 9.8
ProFTPD mod_sql Pre-Auth SQL Injection Leading to RCE (CVE-2026-42167)
CVE-2026-42167 network Patched
HIGH 8.1
Prodigy Commerce WordPress Plugin — Unauthenticated Local File Inclusion (CVE-2026-0926)
CVE-2026-0926 web Unverified
HIGH
Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366
CVE-2026-5366 (Huntr bounty e2e88a0f-a8f6-49c9-94c5-e98dc385f07a) web Patched
HIGH
PraisonAI API Server Missing Authentication (CVE-2026-44338) EPSS 29%
CVE-2026-44338 / [GHSA-6rmh-7xcm-cpxj](https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6rmh-7xcm-cpxj) web Patched
HIGH
Postiz Arbitrary File Upload to Stored XSS / Account Takeover (CVE-2026-40487)
CVE-2026-40487 / GHSA-44wg-r34q-hvfx web Patched
HIGH 8.9
PostgreSQL pgcrypto PGP Heap Overflow to Superuser Escalation — CVE-2026-2005
CVE-2026-2005 binary Unverified
CRITICAL
Portwell Engineering Toolkits Driver Arbitrary Physical Memory R/W LPE (CVE-2026-3437)
CVE-2026-3437 binary Unverified
HIGH
PolarLearn Forum Vote Count Manipulation (CVE-2026-25126)
CVE-2026-25126 web Patched
MEDIUM
PocketBase OAuth2 Account Pre-Hijacking (CVE-2026-44166)
CVE-2026-44166 / [GHSA-pq7p-mc74-g65w](https://github.com/pocketbase/pocketbase/security/advisories/GHSA-pq7p-mc74-g65w) web Patched
MEDIUM 6.1
Plunk SSRF via Unvalidated AWS SNS SubscriptionConfirmation — CVE-2026-32096
CVE-2026-32096 cloud Patched
CRITICAL 9.3
PJSIP DNS Compression Pointer Heap Out-of-Bounds Read (CVE-2026-32945)
CVE-2026-32945 network Patched
MEDIUM
PJSIP / PJNATH ICE Session Stack Buffer Overflow via SDP ice-ufrag (CVE-2026-25994)
CVE-2026-25994 network Patched
HIGH
Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
CVE-2026-4885 web Unverified
CRITICAL
PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)
CVE-2026-43494 binary Patched
HIGH
phpVMS Unauthenticated Legacy Importer Database Wipe (CVE-2026-42569)
CVE-2026-42569 web Patched
CRITICAL
phpSysInfo IP Allowlist Bypass via X-Forwarded-For Spoofing — CVE-2026-55584
CVE-2026-55584 / GHSA-786w-p5pm-cvgh web Patched
HIGH 7.5
PgBouncer SASL Length Field Integer Overflow Crash — CVE-2026-6664
CVE-2026-6664 network Patched
HIGH
Perfmatters WordPress Plugin Arbitrary File Deletion (CVE-2026-4350)
CVE-2026-4350 web Unverified
HIGH 8.1
Percona PMM Authenticated RCE via PostgreSQL COPY TO PROGRAM (CVE-2026-25212)
CVE-2026-25212 web Patched
CRITICAL 9.9
pdfmake Server-Side Request Forgery via Unvalidated Document URLs (CVE-2026-26801)
CVE-2026-26801 web Patched
HIGH
PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)
CVE-2026-36239 web Unverified
CRITICAL
Pardus Software Center Local Privilege Escalation via APT Option Injection (CVE-2026-14459 / CVE-2026-14460)
CVE-2026-14459 (also covers CVE-2026-14460) binary Patched
HIGH 8.8
PackageKit TOCTOU Local Privilege Escalation (CVE-2026-41651)
CVE-2026-41651 binary Patched
HIGH
pac4j JWT Authentication Bypass via Unsigned Token in JWE Wrapper — CVE-2026-29000
CVE-2026-29000 web Patched
CRITICAL 9.8
OWASP CoreRuleSet Multipart Charset WAF Bypass (CVE-2026-21876) EPSS 14%
CVE-2026-21876 web Patched
CRITICAL
OS Command Injection in KubeAI via Model URL (CVE-2026-34940)
CVE-2026-34940 cloud Patched
HIGH 8.7
Orval OpenAPI Codegen Arbitrary Code Execution via Malicious Spec (CVE-2026-23947)
CVE-2026-23947 misc Patched
HIGH
oRPC OpenAPI Reference Plugin Stored XSS via Unescaped Spec Embedding (CVE-2026-33331)
CVE-2026-33331 (GHSA-7f6v-3gx7-27q8) web Patched
HIGH
Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
CVE-2026-26198 (GHSA-xxh2-68g9-8jqr) web Patched
CRITICAL 9.8
Oracle VirtualBox Shared Folders Kernel Memory Exhaustion DoS (CVE-2026-21986)
CVE-2026-21986 binary Patched
MEDIUM 7.1
OpenXDMoD `user_interface.php` Report Title Command Injection (CVE-2026-45777)
CVE-2026-45777 web Patched
CRITICAL
OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766 EPSS 26%
CVE-2026-0766 (ZDI-26-032, GHSA-cggw-334c-f4mj) web Unverified
HIGH 8.8
OpenSTAManager Scadenzario Bulk Operations Error-Based SQL Injection — CVE-2026-24418
CVE-2026-24418 web Patched
HIGH 8.8
OpenSTAManager Reflected XSS via `righe` Parameter (CVE-2026-24415)
CVE-2026-24415 (GHSA-jfgp-g7x7-j25j) web Patched
MEDIUM
OpenSTAManager Prima Nota Error-Based SQL Injection — CVE-2026-24419
CVE-2026-24419 web Patched
HIGH
OpenSTAManager Global Search Amplified Time-Based Blind SQL Injection — CVE-2026-24417
CVE-2026-24417 web Patched
HIGH
OpenSTAManager Article Pricing Time-Based Blind SQL Injection — CVE-2026-24416
CVE-2026-24416 web Patched
HIGH
OpenRemote — Expression Injection RCE in Rules Engine (CVE-2026-39842)
CVE-2026-39842 / GHSA-7mqr-33rv-p3mp web Patched
CRITICAL 10
OpenPLC_v3 glue_generator Path Traversal — CVE-2026-31156
CVE-2026-31156 hardware Unverified
HIGH
OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)
CVE-2026-41900 (GHSA-8h25-q488-4hxw) cloud Patched
HIGH 8.6
OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)
CVE-2026-24849 web Patched
CRITICAL 6.5
OpenCode Unauthenticated Local HTTP Server -> Remote Code Execution (CVE-2026-22812) EPSS 17%
CVE-2026-22812 (GHSA-vxw4-wv6m-9hhh) web Patched
HIGH 8.8
OpenClaw Gateway WebSocket Authentication Bypass RCE — CVE-2026-28466
CVE-2026-28466 network Patched
CRITICAL
OpenBSD slaacd/rad Infinite Loop via Malformed ND Option (CVE-2026-41285)
CVE-2026-41285 network Patched
HIGH
OpenAM Pre-Authentication RCE via `jato.clientSession` Deserialization (CVE-2026-33439) EPSS 10%
CVE-2026-33439 web Patched
CRITICAL 9.8
Open WebUI SSRF via HTTP Redirect Bypass of validate_url() (CVE-2026-45401)
CVE-2026-45401 web Patched
HIGH
OP-TEE PKCS#11 TA Out-of-Bounds Heap Write via `C_GetAttributeValue` (CVE-2026-33317)
CVE-2026-33317 (GHSA-8cqw-mg7v-c9p9) binary Patched
HIGH 8.7
Ollama GGUF Heap Out-of-Bounds Read During Quantization — CVE-2026-7482
CVE-2026-7482 misc Patched
MEDIUM
OliveTin OS Command Injection via Shell Mode Arguments (CVE-2026-27626)
CVE-2026-27626 / GHSA-49gm-hh7w-wfvf web Unverified
CRITICAL 9.9
NVIDIA Triton Inference Server SageMaker Auth Bypass to Unauthenticated RCE (CVE-2026-24207)
CVE-2026-24207 (sibling: CVE-2026-24206, Vertex AI, analysis only) network Patched
CRITICAL 9.8
npm `tar` Package Unicode-Normalization Race Condition / File Collision (CVE-2026-2395)
CVE-2026-2395 misc Unverified
MEDIUM
Notepad++ nativeLang.xml Format String Crash / Info Disclosure — CVE-2026-3008
CVE-2026-3008 binary Unverified
MEDIUM
Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)
CVE-2026-41242 web Patched
CRITICAL
Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786
CVE-2026-29786 misc Patched
HIGH
node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97 misc Patched
HIGH
Nhost Local MCP Server Unauthenticated CORS Bypass Leading to Full Project Takeover (CVE-2026-34200)
CVE-2026-34200 (GHSA-6c5x-3h35-vvw2) web Patched
CRITICAL 9.6
nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)
CVE-2026-40701 web Patched
MEDIUM 6.3
Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)
CVE-2026-0211 (repository explicitly labels this as a hypothetical/simulated CVE for coursework, not a confirmed vendor-assigned vulnerability) web Unverified
HIGH
nginx PoolSlip × Rift Chained ASLR-Independent Remote Code Execution (CVE-2026-9256 / CVE-2026-42945)
CVE-2026-9256 ("PoolSlip"), chained with CVE-2026-42945 ("rift") web Unverified
CRITICAL
NGINX HTTP/2 Frame Injection via Vulnerable Upstream Proxying (CVE-2026-42926)
CVE-2026-42926 web Patched
HIGH
Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519
CVE-2026-53519 (GHSA-5c25-7vpj-9mqh) web Patched
INFO
NextScripts Social Networks Auto-Poster — WordPress Stored XSS (CVE-2026-3228)
CVE-2026-3228 web Unverified
MEDIUM 6.4
Nextcloud user_oidc ID4me JWT Signature Bypass (CVE-2026-45156)
CVE-2026-45156 web Patched
HIGH 8.1
Next.js Vendored picomatch Vulnerable Dependency — CVE-2026-33671
CVE-2026-33671 web Patched
HIGH
Netflix Conductor Unauthenticated RCE via INLINE GraalVM Evaluator — CVE-2026-58138
CVE-2026-58138 ([VulnCheck advisory](https://www.vulncheck.com/advisories/orkes-conductor-unauthenticated-rce-via-graalvm-script-evaluators)) misc Patched
CRITICAL 9.8
Neo4j Bolt Transaction Metadata Log Injection (CVE-2026-1337)
CVE-2026-1337 network Unverified
LOW
n8n Unauthenticated Arbitrary File Read to RCE Full Chain — CVE-2026-21858 + CVE-2025-68613 EPSS 78%
CVE-2026-21858, CVE-2025-68613 web Patched
CRITICAL 10
n8n HTTP Request Node Pagination Prototype Pollution → Remote Code Execution (CVE-2026-44789)
CVE-2026-44789 / GHSA-c8xv-5998-g76h web Patched
CRITICAL 9.4
Multiparty Denial of Service via Prototype-Pollution Field Name (CVE-2026-8161)
CVE-2026-8161 / GHSA-qxch-whhj-8956 misc Patched
MEDIUM
Multer Orphaned Temporary File Disk-Exhaustion DoS — CVE-2026-3304
CVE-2026-3304 web Patched
HIGH 8.7
MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)
CVE-2026-6992 network Unverified
HIGH
MLflow / MLServer Insecure Pickle Deserialization RCE — CVE-2026-0596
CVE-2026-0596 (GHSA-rvhj-8chj-8v3c) web Unverified
CRITICAL 9.6
MIPS-Based Managed Switch Firmware Pre-Auth Kernel RCE — CVE-2026-1668
CVE-2026-1668 binary Unverified
CRITICAL
MiniTool pwdrvio.sys Kernel Write-What-Where — Local Privilege Escalation Primitive (CVE-2026-36981)
CVE-2026-36981 binary Patched
HIGH
MiniTool pwdrvio.sys Kernel Driver Buffer Overflow — Local DoS/BSOD (CVE-2026-36980)
CVE-2026-36980 binary Patched
MEDIUM
MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483) EPSS 11%
CVE-2026-27483 web Patched
CRITICAL
MikroORM Custom Type Raw SQL Injection (CVE-2026-34220)
CVE-2026-34220 web Patched
HIGH
midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)
CVE-2026-1306 web Unverified
CRITICAL 9.8
Microsoft Semantic Kernel In-Memory Vector Store Filter eval() Sandbox Bypass RCE (CVE-2026-26030)
CVE-2026-26030 misc Patched
CRITICAL
Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)
CVE-2026-45504 web Patched
HIGH
Microsoft Defender Link Following Local Privilege Escalation (CVE-2026-41091) KEV
CVE-2026-41091 binary Unpatched
HIGH 7.8
Mercator Configuration SSRF Chained to Internal Redis RCE (CVE-2026-49345)
CVE-2026-49345 web Unverified
CRITICAL
MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356) EPSS 14%
CVE-2026-36356 network Unverified
CRITICAL
MCPJam Inspector Unauthenticated Command Injection RCE (CVE-2026-23744) EPSS 45%
CVE-2026-23744 web Patched
CRITICAL
MCPJam Inspector / Arcane MCP Connect Command Injection RCE via Host-Header Vhost Routing (CVE-2026-23520)
CVE-2026-23520 web Patched
CRITICAL
mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825) EPSS 13%
CVE-2026-27825 (read-side twin of GHSA-xjgw-4wvw-rgm4) web Patched
CRITICAL 9.3
Math.js Expression Parser Sandbox Bypass RCE (CVE-2026-40897)
CVE-2026-40897 web Patched
CRITICAL
Masteriyo LMS Authenticated Privilege Escalation to Administrator (CVE-2026-4484)
CVE-2026-4484 web Unverified
HIGH 8.8
Marlin Firmware M421 G-code Handler Out-of-Bounds Write — CVE-2026-56111
CVE-2026-56111 hardware Patched
HIGH 8.3
MariaDB server_audit Plugin Logging Bypass via Inline Comments (CVE-2026-3494)
CVE-2026-3494 network Patched
MEDIUM
MariaDB JSON_SCHEMA_VALID() Heap Overflow — Privilege Escalation to UDF RCE (CVE-2026-32710)
CVE-2026-32710 binary Patched
CRITICAL
MantisBT SOAP `mc_issue_add` Authentication Bypass (Type Juggling) — CVE-2026-30849
CVE-2026-30849 web Patched
HIGH
Malicious DOCX/OLE CLSID Object Embedding Builder (CVE-2026-21509) KEV EPSS 73%
CVE-2026-21509 misc Unverified
HIGH
MagicMirror² Unauthenticated SSRF via `/cors` Endpoint (CVE-2026-42281)
CVE-2026-42281 web Patched
CRITICAL 9.2
lwIP SNMPv3 USM Stack-Based Buffer Overflow (CVE-2026-8836)
CVE-2026-8836 network Patched
CRITICAL 9.8
local-mcp exec Tool Sandbox/Restriction Bypass (CVE-2026-6130)
CVE-2026-6130 misc Unverified
MEDIUM
LiteSpeed cPanel/WHM Plugin Symlink Privilege Escalation — CVE-2026-54420 KEV
CVE-2026-54420 network Unverified
HIGH 8.5
LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)
CVE-2026-49468 web Patched
CRITICAL 9.8
LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)
CVE-2026-47102 web Patched
HIGH 8.8
LiteLLM Guardrail Custom-Code Sandbox Escape to Root RCE (CVE-2026-40217) EPSS 15%
CVE-2026-40217 (X41-2026-001, GHSA-3926-2jvf-fg29) web Patched
CRITICAL 8.8
LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CVE-2026-35030)
CVE-2026-35030 web Patched
CRITICAL 9.1
LiteLLM /config/update Broken Access Control (CVE-2026-35029) EPSS 26%
CVE-2026-35029 web Patched
HIGH 8.8
LiquidJS Template Engine Path Traversal — CVE-2026-30952
CVE-2026-30952 (GHSA-wmfp-5q7x-987x) misc Patched
HIGH 8.7
Linux Kernel PPP Unprivileged User-Namespace Precondition Probe — CVE-2026-53075
CVE-2026-53075 binary Patched
INFO
Linux Kernel mm/mseal VMA-Merge Stale-Bound Bug (CVE-2026-23416)
CVE-2026-23416 binary Patched
MEDIUM
Linux Kernel KFENCE Cross-Cache Free of SKB Head via bpf_prog_test_run_skb — CVE-2026-31429
CVE-2026-31429 binary Patched
MEDIUM
Linux Kernel ICMP Fragmentation-Needed NULL Pointer Dereference (CVE-2026-23398)
CVE-2026-23398 network Patched
HIGH
Linux Kernel Futex-PI rtmutex remove_waiter() Use-After-Free (CVE-2026-43499)
CVE-2026-43499 binary Patched
HIGH 7.8
Linux FUSE Readdir Cache Out-of-Bounds Write to Root LPE — CVE-2026-31694
CVE-2026-31694 binary Patched
HIGH
Linux BPF Verifier Scalar-Forking Soundness Bug to Container Escape — CVE-2026-31413
CVE-2026-31413 binary Patched
CRITICAL
Lightspeed Classroom Management Weak Authentication / Device Takeover — CVE-2026-30368
CVE-2026-30368 web Unverified
HIGH
LibRaw pana8.cpp GetDBit() Out-of-Bounds Array Read (CVE-2026-36834)
CVE-2026-36834 binary Unverified
MEDIUM 6.5
libopenapv / Android APV Codec Zero-Click Heap Buffer Overflow (CVE-2026-0006)
CVE-2026-0006 binary Unverified
CRITICAL 9.8
Lenovo LDE (LdeApi.Server.exe) Unimpersonated Junction-Based Arbitrary File Write to SYSTEM (CVE-2026-0827)
CVE-2026-0827 (Lenovo advisory LEN-210693) binary Unverified
HIGH
LatePoint Calendar Booking Plugin Contributor-to-Administrator Privilege Escalation (CVE-2026-49083)
CVE-2026-49083 web Unverified
HIGH 8.8
LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741
CVE-2026-6741 web Patched
HIGH 8.8
Lansweeper lsrunase 2.0 / lsencrypt 2.0 — RC4 Password Recovery (CVE-2026-39031)
CVE-2026-39031 crypto Unverified
HIGH
Langflow Unauthenticated Remote Code Execution via `validate/code` Endpoint (CVE-2026-0770) KEV EPSS 63%
CVE-2026-0770 web Patched
CRITICAL
Langflow Remote Code Execution — CVE-2026-27966 EPSS 34%
CVE-2026-27966 web Patched
CRITICAL 9.8
Langflow Knowledge Base Path Traversal / Arbitrary Directory Deletion (CVE-2026-42048)
CVE-2026-42048 (GHSA-9whx-c884-c68q) web Patched
HIGH
Langflow Custom Component Remote Code Execution — CVE-2026-33017 KEV EPSS 96%
CVE-2026-33017 web Patched
CRITICAL
LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)
CVE-2026-0920 web Unverified
CRITICAL 9.8
KVM SEV-SNP Page State Change (PSC) Heap Out-of-Bounds — CVE-2026-53360
CVE-2026-53360 binary Patched
HIGH
Kubernetes `runAsNonRoot` Bypass via UID Integer Overflow (CVE-2026-46680)
CVE-2026-46680 cloud Patched
HIGH
Krayin CRM — TinyMCE Upload Unrestricted File Upload to RCE (CVE-2026-38526)
CVE-2026-38526 web Unverified
CRITICAL
KnowledgeDeliver ASP.NET ViewState Deserialization RCE via Hardcoded Machine Keys — CVE-2026-5426
CVE-2026-5426 web Unverified
CRITICAL
Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)
CVE-2026-8206 web Unverified
CRITICAL 9.8
KillChain — Vulnerable Kernel Driver IOCTL Protected-Process Termination (CVE-2026-0828)
CVE-2026-0828 binary Unverified
HIGH
Keycloak Unauthorized Organization Registration via Invitation Token Flaw — CVE-2026-1529
CVE-2026-1529 web Unverified
CRITICAL
Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
CVE-2026-25924 / GHSA-grch-p7vf-vc4f web Patched
HIGH 8.4
Kan SSRF via Attachment Download Endpoint — CVE-2026-32255 EPSS 21%
CVE-2026-32255 (GHSA-qrx8-9hc6-jvqg) web Patched
HIGH 8.6
JupyterHub Cross-Origin Form POST XSRF Bypass (CVE-2026-40864)
CVE-2026-40864 (GHSA-m68r-v472-jgq9) web Patched
MEDIUM
Joomla Page Builder CK Unauthenticated Arbitrary File Upload RCE — CVE-2026-56290 KEV EPSS 30%
CVE-2026-56290 web Patched
CRITICAL 9.8
Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627
CVE-2026-21627 web Patched
CRITICAL 9.5
JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)
CVE-2026-49048 (Advisory ID JOOMCCK-2026-001) web Unpatched
CRITICAL 8.7
Jinjava Server-Side Template Injection to RCE via Jackson ObjectMapper (CVE-2026-25526)
CVE-2026-25526 web Patched
CRITICAL
JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
CVE-2026-49079 web Unverified
HIGH 7.5
Jenkins ClassFilter Deserialization Bypass → Arbitrary File Read — CVE-2026-53435 EPSS 53%
CVE-2026-53435 (Jenkins SECURITY-3707) web Patched
HIGH 9.1
JeecgBoot mLogin Endpoint CAPTCHA Bypass Enabling Credential Brute Force (CVE-2026-8196)
CVE-2026-8196 web Unverified
HIGH
Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion (CVE-2026-1281 / CVE-2026-1340) KEV EPSS 82%
CVE-2026-1281, CVE-2026-1340 network Patched
CRITICAL
ITFlow Time-Based Blind SQL Injection via agent/ajax.php expires Parameter (CVE-2026-54597)
CVE-2026-54597 web Unverified
HIGH
ITFlow SQL Injection via recurring_invoice_frequency (CVE-2026-54596)
CVE-2026-54596 web Unverified
HIGH
iOS App Intents Path Traversal — CVE-2026-28995
CVE-2026-28995 misc Patched
HIGH
InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)
CVE-2026-23491 web Patched
CRITICAL
Integration for Keap/Infusionsoft Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49104)
CVE-2026-49104 web Unverified
HIGH 8.1
Integration for ActiveCampaign Unauthenticated PHP Object Injection via Unsafe Deserialization (CVE-2026-9691)
CVE-2026-9691 web Unpatched
HIGH 8.1
Immich Stored XSS to API Key Exfiltration and Account Hijacking (CVE-2026-35455)
CVE-2026-35455 web Patched
HIGH
Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)
CVE-2026-0911 web Unverified
HIGH
HPE Aruba AOS-CX Pre-Auth REST API Bypass via nginx Version Smuggling (CVE-2026-23813)
CVE-2026-23813 network Patched
CRITICAL 9.8
Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
CVE-2026-10580 web Unverified
CRITICAL 9.8
HAXcms Node.js Private Key Disclosure via Broken HMAC (CVE-2026-46395)
CVE-2026-46395 web Patched
CRITICAL 9.8
HAXcms Git.php OS Command Injection (CVE-2026-46394)
CVE-2026-46394 web Patched
HIGH 7.2
HashiCorp go-getter Git Pathspec Arbitrary File Read (CVE-2026-4660)
CVE-2026-4660 / HCSEC-2026-04 cloud Patched
HIGH 7.5
HAProxy HTTP/3 (QUIC) Standalone FIN Body Validation Bypass Leading to Request Smuggling — CVE-2026-33555
CVE-2026-33555 network Patched
HIGH
Handlebars AST Injection Remote Code Execution — CVE-2026-33937
CVE-2026-33937 web Patched
CRITICAL
gRPC-Go RBAC Authorization Bypass via Missing Leading Slash in `:path` (CVE-2026-33186)
CVE-2026-33186 (GHSA-p77j-4mvh-x3m3) network Patched
HIGH
Group-Office TNEF Attachment Handler OS Command Injection (CVE-2026-25512) EPSS 19%
CVE-2026-25512 web Patched
CRITICAL 9.4
Group-Office PHP Deserialization Remote Code Execution (CVE-2026-34838)
CVE-2026-34838 (GHSA-h22j-frrf-5vxq) web Patched
CRITICAL
Gravity Forms Unauthenticated Reflected XSS via `gform_get_config` `form_ids` Parameter (CVE-2026-4406)
CVE-2026-4406 web Patched
MEDIUM 6.1
Gravity Forms Path Traversal → Arbitrary File Deletion (CVE-2026-48866)
CVE-2026-48866 web Patched
CRITICAL 9.6
GRASSMARLIN XML External Entity (XXE) Out-of-Band File Exfiltration (CVE-2026-6807)
CVE-2026-6807 network Unverified
HIGH
graphiti-core Cypher Injection via Unsanitized node_labels — CVE-2026-32247
CVE-2026-32247 (GHSA, getzep/graphiti) web Patched
HIGH 8.1
Grafana Dashboard Permissions Broken Access Control — Editor-to-Admin Privilege Escalation (CVE-2026-21721)
CVE-2026-21721 web Patched
HIGH
Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)
CVE-2026-42589 web Patched
CRITICAL 9.8
Gogs Wiki Arbitrary File Deletion via Path Traversal (CVE-2026-24135)
CVE-2026-24135 (GHSA-jp7c-wj6q-3qf2) web Patched
HIGH 7.5
Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813
CVE-2026-52813 web Patched
INFO
GNU inetutils telnetd Local Privilege Escalation via NEW-ENVIRON Injection — CVE-2026-28372
CVE-2026-28372 binary Patched
HIGH 7.4
GNU InetUtils telnetd LINEMODE SLC Pre-Auth Buffer Overflow (CVE-2026-32746) EPSS 24%
CVE-2026-32746 network Unverified
CRITICAL 9.8
GitLab WebSocket GraphqlChannel Unauthorized Method Enumeration — CVE-2026-5173
CVE-2026-5173 web Patched
HIGH
Gitea OAuth2 Scope Enforcement Bypass via HTTP Basic Auth — CVE-2026-28699
CVE-2026-28699 web Patched
HIGH
Gitea Container Registry Anonymous Auth Bypass (CVE-2026-27771)
CVE-2026-27771 web Patched
CRITICAL
Ghost CMS Theme JSONPath Remote Code Execution — CVE-2026-29053
CVE-2026-29053 (GHSA-cgc2-rcrh-qr5x) web Patched
HIGH
Ghost CMS Content API — Unauthenticated Blind SQL Injection (CVE-2026-26980) EPSS 70%
CVE-2026-26980 web Patched
CRITICAL
gdk-pixbuf JPEG Loader Heap Buffer Overflow — CVE-2026-5201
CVE-2026-5201 binary Patched
HIGH 7.5
FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895) EPSS 11%
CVE-2026-25895 web Patched
CRITICAL 9.8
Friendly Functions for Welcart WordPress Plugin CSRF (CVE-2026-1208)
CVE-2026-1208 web Patched
MEDIUM 4.3
FreeScout Zero-Click RCE via Email Attachment Filename Sanitization Bypass ("Mail2Shell") — CVE-2026-28289 EPSS 31%
CVE-2026-28289 web Patched
CRITICAL 10
FreePBX Unauthenticated UCP Access via Hard-Coded Credentials (CVE-2026-46376)
CVE-2026-46376 (GHSA-m55x-h47x-v3gx) web Patched
CRITICAL 9.1
FreeBSD setcred(2) Kernel Stack Buffer Overflow — Local Privilege Escalation (CVE-2026-45250)
CVE-2026-45250 binary Unverified
CRITICAL
FreeBSD OSS /dev/dsp Stale Kernel-Stack Buffer Local Privilege Escalation (CVE-2026-49417)
CVE-2026-49417 binary Unverified
HIGH
FreeBSD Linuxulator AT_SECURE=0 Local Privilege Escalation via LD_PRELOAD (CVE-2026-49413)
CVE-2026-49413 binary Unverified
HIGH
FreeBSD exec_args_adjust_args() Out-of-Bounds memmove — Local Privilege Escalation via sshd Race (CVE-2026-7270)
CVE-2026-7270 binary Unverified
CRITICAL
FreeBSD /dev/dsp (OSS) Negative-Offset mmap Kernel Memory Corruption LPE (CVE-2026-45258)
CVE-2026-45258 binary Unverified
CRITICAL
FOSSBilling Unauthenticated API Key Config Disclosure & Password Reset Token Reuse — CVE-2026-53647
CVE-2026-53647 (also documents chained CVE-2026-53646) web Patched
MEDIUM 6.9
FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808) KEV EPSS 93%
CVE-2026-39808 network Unverified
CRITICAL 9.8
Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089) KEV EPSS 76%
CVE-2026-25089 network Patched
CRITICAL 9.8
Fortinet FortiClientLinux VPN Config Symlink/Shared-Object Loading LPE — CVE-2026-24018
CVE-2026-24018 binary Unverified
HIGH
FortiAuthenticator Unauthenticated RCE Endpoint Probe (CVE-2026-44277)
CVE-2026-44277 web Patched
CRITICAL
Form Notify WordPress Plugin — LINE OAuth Authentication Bypass to Account Takeover (CVE-2026-5229)
CVE-2026-5229 web Patched
CRITICAL 9.8
Flowise NVIDIA NIM Endpoint Authentication Bypass — CVE-2026-30824 EPSS 36%
CVE-2026-30824 web Patched
CRITICAL 9.8
Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337
CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx)) web Unverified
INFO
Firefox/Tor Browser IndexedDB Ordering Fingerprint — CVE-2026-6770
CVE-2026-6770 binary Unverified
MEDIUM
Feast Registry gRPC Unauthenticated RCE via dill.loads — CVE-2026-56121
CVE-2026-56121 misc Patched
CRITICAL 9.8
exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)
CVE-2026-43893 / GHSA-cw26-7653-2rp5 misc Patched
HIGH 8.2
ExifTool Metadata Field Command Injection (macOS) — CVE-2026-3102
CVE-2026-3102 binary Patched
HIGH
Everest Forms Unauthenticated PHP Object Injection to RCE (CVE-2026-3296)
CVE-2026-3296 web Patched
CRITICAL 9.8
Everest Forms Pro Unauthenticated PHP Code Injection via Calculation Addon (CVE-2026-3300) EPSS 39%
CVE-2026-3300 web Unverified
CRITICAL
EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657
CVE-2026-1657 web Patched
MEDIUM
Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)
CVE-2026-40776 / Patchstack PSID 85de025d71e7 web Patched
HIGH 7.5
EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656
CVE-2026-33656 web Patched
CRITICAL
EspoCRM 9.3.3 Stored HTML Injection in Email Notifications — CVE-2026-33657
CVE-2026-33657 web Patched
MEDIUM
EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534
CVE-2026-33534 web Patched
MEDIUM
ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)
CVE-2026-2600 web Patched
MEDIUM 6.4
EGroupware Nextmatch Filter Authenticated SQL Injection (CVE-2026-22243)
CVE-2026-22243 web Patched
CRITICAL
EcoOnline EHS Android App — Deep Link Validation Bypass to WebView Open Redirect (CVE-2026-26897)
CVE-2026-26897 web Patched
MEDIUM 6.3
Easy Elements for Elementor Unauthenticated Privilege Escalation via `custom_meta` Overwrite (CVE-2026-9018)
CVE-2026-9018 web Patched
HIGH 8.8
Dolibarr selectobject.php Authenticated Local File Inclusion (CVE-2026-34036)
CVE-2026-34036 web Patched
MEDIUM
Dolibarr ERP/CRM OS Command Injection via MAIN_ODT_AS_PDF (CVE-2026-23500)
CVE-2026-23500 / GHSA-w5j3-8fcr-h87w web Patched
CRITICAL
docling-core Unsafe YAML Deserialization Leading to Code Execution — CVE-2026-24009
CVE-2026-24009 misc Patched
HIGH
dnsmasq extract_addresses() RDLEN/RDATA Buffer Overflow — CVE-2026-5172
CVE-2026-5172 network Patched
INFO
dnsmasq EDNS Client Subnet (ECS) Response Validation Bypass (CVE-2026-4893)
CVE-2026-4893 network Patched
MEDIUM
Django MultiPartParser Base64 Whitespace CPU Amplification DoS — CVE-2026-33033
CVE-2026-33033 web Patched
MEDIUM
Django GIS RasterField SQL Injection (CVE-2026-1207) EPSS 13%
CVE-2026-1207 web Patched
HIGH
Divi Form Builder <= 5.1.2 Unauthenticated Privilege Escalation via Role Injection (CVE-2026-5118)
CVE-2026-5118 web Unverified
CRITICAL 9.8
diskover-community — CSRF Leading to Authentication Bypass (CVE-2026-38934)
CVE-2026-38934 web Unverified
HIGH 8.8
Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)
CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11) web Unverified
CRITICAL
Discord Desktop Client Uncontrolled Search Path Element / Local Code Execution (CVE-2026-0776)
CVE-2026-0776 (ZDI-CAN-27057, credit: Trend Micro Zero Day Initiative) binary Unverified
HIGH 7.3
DirtyDecrypt-Go — RxRPC rxgk Page-Cache Overwrite LPE (Go Port) — CVE-2026-31635
CVE-2026-31635 binary Patched
HIGH
dedoc/scramble Laravel API-Doc Generator Unauthenticated eval() RCE (CVE-2026-44262)
CVE-2026-44262 / [GHSA-4rm2-28vj-fj39](https://github.com/advisories/GHSA-4rm2-28vj-fj39) web Patched
CRITICAL
DbGate Unauthenticated RCE via JSON Script Runner (CVE-2026-47668)
CVE-2026-47668 web Patched
CRITICAL 3.1
DbGate `loadReader` `functionName` Injection RCE (CVE-2026-48017)
CVE-2026-48017 / GHSA-hv83-ggc4-v385 web Patched
HIGH 8.8
Dagster Database I/O Manager SQL Injection via Dynamic Partition Keys (CVE-2026-41490)
CVE-2026-41490 (GHSA-mjw2-v2hm-wj34) web Patched
HIGH
curl SMB Connection-Reuse Use-After-Free (CVE-2026-3805)
CVE-2026-3805 network Patched
HIGH
CRLF Email Header Injection in Plunk via Raw MIME Construction (CVE-2026-34975)
CVE-2026-34975 web Patched
HIGH 8.5
Coolify Authenticated Remote Command Injection via Deployment Config (CVE-2026-34038)
CVE-2026-34038 (GHSA-qqrq-r9h4-x6wp) web Patched
CRITICAL 10
Control Web Panel Pre-Auth Blind SQL Injection to RCE — CVE-2026-57517
CVE-2026-57517 web Patched
CRITICAL 9.8
Contact Form by Supsystic <= 1.7.36 Unauthenticated SSTI to RCE (CVE-2026-4257) EPSS 41%
CVE-2026-4257 web Unverified
CRITICAL
CodeAstro Simple Attendance Management System 1.0 — SQL Injection Auth Bypass (CVE-2026-37749)
CVE-2026-37749 web Unverified
CRITICAL 9.8
Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631) EPSS 15%
CVE-2026-4631 (GHSA-m4gv-x78h-3427) web Patched
CRITICAL 9.8
Claude Code WebFetch Hardcoded HuggingFace Bare-Hostname Allow-List Bypass — CVE-2026-54316
CVE-2026-54316 (GHSA-fg94-h982-f3mm) misc Patched
MEDIUM
Cisco Catalyst SD-WAN Peering Authentication Bypass — CVE-2026-20182 KEV EPSS 92%
CVE-2026-20182 network Patched
CRITICAL 10
ChatterBot Denial of Service via SQLAlchemy Connection Pool Exhaustion (CVE-2026-23842)
CVE-2026-23842 misc Patched
HIGH 7.5
Chamilo LMS Unauthenticated install.ajax.php SSRF + Open Mail Relay — CVE-2026-33715
CVE-2026-33715 / GHSA-mxc9-9335-45mc web Unverified
HIGH 7.5
Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041
CVE-2026-29041 web Patched
HIGH 8.8
Centreon Multi-Vector RCE — Path Traversal, Command Injection & Blind SQLi (CVE-2026-2749)
CVE-2026-2749 (bundled with related CVE-2026-2750, CVE-2026-2751) web Patched
CRITICAL
Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)
CVE-2026-6815 web Unverified
HIGH
Cacti Authenticated OS Command Injection via Host Notes Variable (CVE-2026-39949)
CVE-2026-39949 web Patched
HIGH
Business Directory Plugin for WordPress — Unauthenticated Time-Based Blind SQL Injection (CVE-2026-2576)
CVE-2026-2576 web Patched
HIGH 7.5
Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181) EPSS 15%
CVE-2026-8181 web Patched
CRITICAL 9.8
Budibase Authentication Bypass to Plugin-Upload Reverse Shell — CVE-2026-31816 EPSS 15%
CVE-2026-31816 web Unverified
CRITICAL
Branda White Label & Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551
CVE-2026-11551 web Patched
CRITICAL 9.8
Bookly Booking Form Cookie-Based Stored XSS — CVE-2026-5513
CVE-2026-5513 web Patched
HIGH 7.2
BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)
CVE-2026-6960 web Unverified
CRITICAL 9.8
BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)
CVE-2026-39387 web Patched
HIGH
Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)
CVE-2026-25099 web Patched
HIGH
BIRD/BIRD2 BGP AS_PATH Mask Matching Stack Buffer Overflow (CVE-2026-49943)
CVE-2026-49943 network Patched
HIGH 3.1
BetterDocs Pro Unauthenticated Local File Inclusion to RCE — CVE-2026-7515
CVE-2026-7515 web Unverified
CRITICAL 9.8
BentoPDF Stored XSS to File Exfiltration (CVE-2026-41653)
CVE-2026-41653 web Patched
CRITICAL
Balena Etcher Windows TOCTOU Privilege Escalation — CVE-2026-30332
CVE-2026-30332 binary Unverified
HIGH
Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415
CVE-2026-54415 web Patched
HIGH 3.1
Avada Builder Unauthenticated RCE via call_user_func() Allowlist Bypass (CVE-2026-6279)
CVE-2026-6279 web Unverified
CRITICAL
AutoGPT Platform Chat Session IDOR / Session Hijack — CVE-2026-30950
CVE-2026-30950 (GHSA-q58p-v9r9-7gqj) web Patched
HIGH 7.1
ASUSTOR ADM vpnupload.cgi Format String / Stack Buffer Overflow RCE — CVE-2026-6643
CVE-2026-6643 binary Unverified
CRITICAL
ASUS DriverHub Update TOCTOU Local Privilege Escalation — CVE-2026-1880
CVE-2026-1880 binary Patched
MEDIUM
ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)
CVE-2026-5076 (chained with CVE-2026-5073, CVE-2026-5074) web Patched
CRITICAL 9.8
Arista EOS Tunnel Decapsulation Protocol-Type Bypass — CVE-2026-7473 KEV
CVE-2026-7473 network Unverified
MEDIUM 5.8
Appsmith Table Widget Stored XSS to Admin Account Takeover — CVE-2026-30862
CVE-2026-30862 (GHSA-5hw4-whxv-6794) web Patched
CRITICAL 9.1
AppleSEPKeyStore IOKit Use-After-Free (CVE-2026-20637)
CVE-2026-20637 binary Patched
HIGH
AppleM2ScalerCSCDriver Shared Scheduler Use-After-Free (CVE-2026-43655)
CVE-2026-43655 binary Unverified
HIGH
AppleJPEGDriver startDecoder Timeout Use-After-Free (CVE-2026-20687)
CVE-2026-20687 binary Patched
HIGH
ApostropheCMS Import — Malicious Tar Archive Path Traversal (CVE-2026-32731)
CVE-2026-32731 web Patched
HIGH
Apktool Resource Table Path Traversal — Malicious APK Builder (CVE-2026-39973)
CVE-2026-39973 misc Patched
HIGH
Apache Tomcat Tribes EncryptInterceptor Fail-Open Unauthenticated RCE (CVE-2026-34486) KEV EPSS 99%
CVE-2026-34486 web Patched
CRITICAL
Apache Tomcat Split-Collection Security Constraint Bypass (CVE-2026-43515)
CVE-2026-43515 web Patched
HIGH
Apache Tomcat Mutual TLS OCSP Soft-Fail Authentication Bypass — CVE-2026-29145
CVE-2026-29145 web Patched
CRITICAL 9.1
Apache Tomcat LoadBalancerDrainingValve — Cross-System Open Redirect / Session Fixation (CVE-2026-25854)
CVE-2026-25854 web Patched
MEDIUM 6.1
Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980
CVE-2026-23980 web Patched
MEDIUM 6.5
Apache Solr Velocity Template Injection RCE (CVE-2026-44825)
CVE-2026-44825 web Patched
CRITICAL 9.8
Apache Solr UNC Path Validation Bypass to RCE (CVE-2026-22444)
CVE-2026-22444 web Patched
CRITICAL
Apache NiFi 2.8.0 — EXECUTE_CODE Permission Bypass to Groovy RCE (CVE-2026-39816)
CVE-2026-39816 web Patched
CRITICAL
Apache MINA acceptMatchers Deserialization Filter Bypass to RCE (CVE-2026-42779)
CVE-2026-42779 network Patched
CRITICAL 9.8
Apache HTTP Server mod_rewrite/mod_setenvif/mod_proxy_fcgi ap_expr Local File Read — CVE-2026-24072
CVE-2026-24072 web Patched
MEDIUM
Apache HTTP Server mod_auth_digest Timing Attack — CVE-2026-33006
CVE-2026-33006 web Patched
MEDIUM 4.8
Apache HTTP Server HTTP/2 HPACK Cookie-Merging Memory Bomb (CVE-2026-49975) EPSS 31%
CVE-2026-49975 network Unverified
HIGH
Apache Flink Kubernetes Operator SSRF via jarURI (CVE-2026-40564)
CVE-2026-40564 cloud Patched
HIGH
Apache Camel camel-coap Header Injection to Remote Code Execution (CVE-2026-33453)
CVE-2026-33453 web Patched
CRITICAL 10
Apache APISIX forward-auth CRLF Header Injection — CVE-2026-31908
CVE-2026-31908 web Patched
CRITICAL 10
Apache Airflow AWS Auth Manager SAML Host Header Injection (CVE-2026-25604)
CVE-2026-25604 web Patched
HIGH
Apache ActiveMQ Jolokia addNetworkConnector Spring Bean RCE (CVE-2026-42588)
CVE-2026-42588 web Patched
HIGH 8.1
Apache ActiveMQ Classic Jolokia addNetworkConnector Xbean Spring-XML RCE (CVE-2026-34197) KEV EPSS 97%
CVE-2026-34197 (related bypass: CVE-2026-42588) network Patched
CRITICAL
Android ActivityManagerService dumpBitmapsProto() Missing Permission Check (CVE-2026-0047)
CVE-2026-0047 binary Unpatched
CRITICAL 8.4
Amazon WorkSpaces Skylight Workspace Config Service Local Privilege Escalation (CVE-2026-7791)
CVE-2026-7791 cloud Unverified
HIGH
Algorithmic Complexity DoS in musl libc `iconv` GB18030 Decoder — CVE-2026-6042
CVE-2026-6042 network Unverified
HIGH 7.5
AI Model-Loader `trust_remote_code` Order-of-Operations RCE Simulation (CVE-2026-22807)
CVE-2026-22807 misc Patched
HIGH
adx-mcp-server KQL Injection via table_name Parameter (CVE-2026-33980)
CVE-2026-33980 web Patched
HIGH 8.8
Advanced Custom Fields: Extended Unauthenticated Privilege Escalation via `_acf_post_id` Validation Bypass (CVE-2026-8809)
CVE-2026-8809 web Unverified
CRITICAL 9.8
AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)
CVE-2026-21440 (GHSA-gvq6-hvvp-h34h) web Patched
CRITICAL 9.2
Adobe Acrobat/Reader PDF Exploit Generator — Claimed Prototype Pollution (CVE-2026-3462)
CVE-2026-3462 (repo internally references CVE-2026-34621 — CVE-ID mismatch, see Notes) misc Patched
CRITICAL
AdminPanel 4.0 CSRF File Deletion / Setup-Mode Reset — CVE-2026-30498
CVE-2026-30498 (reserved by MITRE) web Unverified
HIGH
AdForest WordPress Theme OTP Login Authentication Bypass — CVE-2026-1729
CVE-2026-1729 web Unverified
CRITICAL
@haxtheweb/open-apis Credential Exposure via SSRF in cacheAddress Endpoint (CVE-2026-46391)
CVE-2026-46391 (GHSA-4fg7-f244-3j49) web Unverified
HIGH
PostgreSQL Referential-Integrity Owner-Switched Implicit Cast RCE
None assigned as of 2026-07-04 network Unverified
HIGH
VLC Bundled FFmpeg VP9 Decoder Resolution-Change Heap Crash
None assigned as of 2026-07-03 binary Unverified
MEDIUM
System Informer phsvc Trusted-Host Confused Deputy LPE
None assigned as of 2026-07-03 binary Unverified
HIGH
RustDesk Relay Session Downgrade and FileTransfer Authorization Scope Bypass
None assigned as of 2026-07-03 network Unverified
HIGH
Redis Vector Set Duplicate HNSW Node ID RCE
None assigned as of 2026-07-03 network Unverified
CRITICAL
QEMU CXL Type-3 Mailbox Guest-to-Host Escape
None assigned as of 2026-07-03 binary Unverified
CRITICAL
Pillow ImageCms Mutable output_mode Heap OOB Write
None assigned as of 2026-07-03 binary Unverified
HIGH
PHP 8.5.7 StreamBucket-to-SOAP Numeric Cookie Remote Code Execution
None assigned as of 2026-07-03 web Unverified
CRITICAL
OpenVPN Connect Server-Pushed Option Current-User Command Execution
None assigned as of 2026-07-03 network Unverified
HIGH
objdump DLX ELF Backend Out-of-Bounds Write (Crash-to-Calc)
None assigned as of 2026-07-03 binary Unverified
MEDIUM
NodeBB ActivityPub attributedTo Local UID Spoof
None assigned as of 2026-07-03 web Unverified
HIGH
Nmap IPv6 Extension-Header Length Wrap
None assigned as of 2026-07-03 network Unverified
LOW
nghttpx HTTP/1.1 Upgrade Request Body Response Queue Poisoning
None assigned as of 2026-07-03 network Patched
HIGH
Nextcloud Federated Share OCM Bearer Token Scope Escalation to Sender WebDAV Access
None assigned as of 2026-07-03 cloud Unverified
HIGH
Next.js unstable_cache Object-Argument Cache-Key Collision
None assigned as of 2026-07-03 web Unverified
HIGH
MyBB 1.8.40 Limited Admin CP User-Manager to Full Administrator Privilege Escalation
None assigned as of 2026-07-03 (see Notes — CVE-2026-45115 identifies a separate, already-patched MyBB issue) web Unpatched
HIGH
Lunar Client Modrinth Explore Raw-HTML to Local Launcher Execution Chain
None assigned as of 2026-07-03 binary Unverified
CRITICAL 3.1
libssh2 Unchecked SSH packet_length Integer Wrap to RCE (CVE-2026-55200)
CVE-2026-55200 network Patched
CRITICAL
libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution
None assigned as of 2026-07-03 network Unverified
CRITICAL
libarchive ZIP Declared-Size Boundary Bypass via debuginfod
None assigned as of 2026-07-03 binary Unverified
MEDIUM
Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248) KEV RW EPSS 100%
CVE-2025-3248 web Patched
CRITICAL 9.8
Ladybird Browser WebAssembly ESM Host-Function Use-After-Free RCE
None assigned as of 2026-07-03 web Unverified
CRITICAL
ImageMagick Ghostscript Delegate Search Path Hijack
None assigned as of 2026-07-03 binary Unverified
HIGH
Gogs Admin User Edit CSRF to Git Hook RCE
None assigned as of 2026-07-03 web Unverified
CRITICAL
Gitea act_runner container.options Host Namespace Escape
None assigned as of 2026-07-03 cloud Unverified
HIGH
Ghidra 12.1.2 Conditional Swift Demangler ACE (plus TraceRMI RCE and SevenZipJBinding Reachability)
None assigned as of 2026-07-03 binary Unverified
MEDIUM
Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616) KEV EPSS 91%
CVE-2026-35616 network Patched
CRITICAL 9.1
Flowise Custom MCP Environment Variable Case Bypass
None assigned as of 2026-07-03 web Unverified
HIGH
Floci API Gateway VTL RCE + IAM Scope Bypass
None assigned as of 2026-07-03 cloud Unverified
CRITICAL
Firefox Smart Window Private URL Exfiltration
None assigned as of 2026-07-03 web Unverified
HIGH
FFmpeg RASC Decoder DLTA Heap Out-of-Bounds Write
None assigned as of 2026-07-03 binary Unpatched
CRITICAL
Docker cp Copy-Out Destination Escape via Symlink Race
None assigned as of 2026-07-03 cloud Unverified
MEDIUM
Discourse Scoped API Key Pre-Route Authorization Bypass
None assigned as of 2026-07-03 web Unverified
HIGH
curl SMTP EXPN Recipient CRLF Command Injection
None assigned as of 2026-07-03 network Unverified
MEDIUM
Citrix NetScaler ADC/Gateway Pre-Auth SAML Memory Overread — "CitrixBleed"-style Leak (CVE-2026-8451) EPSS 16%
CVE-2026-8451 network Unverified
HIGH 7.5
c-ares TCP ares_getaddrinfo() Use-After-Free Code Execution
None assigned as of 2026-07-03 network Unverified
HIGH
AnyDesk Printer Pipe COM Impersonation Local Privilege Escalation
None assigned as of 2026-07-03 binary Unverified
HIGH
7-Zip RAR5 Mark-of-the-Web / ADS Full-Chain Bypass
None assigned as of 2026-07-03 misc Unverified
HIGH
WinRAR Windows Path Traversal via NTFS Alternate Data Streams (CVE-2025-8088) KEV RW EPSS 95%
CVE-2025-8088 misc Patched
HIGH 8.4
Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247) KEV EPSS 28%
CVE-2026-45247 web Unverified
CRITICAL 9.3
Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907) KEV EPSS 78%
CVE-2026-48907 web Patched
CRITICAL 10
Squidbleed — Squid Proxy FTP Gateway Out-of-Bounds Heap Read (CVE-2026-47729)
CVE-2026-47729 network Patched
MEDIUM
PAN-OS GlobalProtect Authentication Bypass via Forged Cookie (CVE-2026-0257) KEV RW EPSS 94%
CVE-2026-0257 web Unverified
HIGH 7.8
Google Chromium V8 Out-of-Bounds Read/Write — Crash PoC (CVE-2026-11645) KEV
CVE-2026-11645 web Unverified
HIGH 8.8
Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 network Unverified
CRITICAL 8.6
Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262) KEV EPSS 28%
CVE-2026-20262 network Unverified
MEDIUM 6.5
Authenticated Command Injection in LiteLLM MCP Test Endpoints (CVE-2026-42271) KEV EPSS 84%
CVE-2026-42271 web Patched
HIGH 8.7
SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908) KEV EPSS 15%
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p) web Patched
CRITICAL 10
Linux Kernel act_pedit Partial COW Page-Cache LPE (CVE-2026-46331)
CVE-2026-46331 binary Patched
HIGH 7.8
libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)
CVE-2026-55200 network Patched
CRITICAL 9.8
libcurl mTLS Connection Reuse Authentication Bypass (CVE-2026-8932)
CVE-2026-8932 network Patched
LOW
GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061) KEV EPSS 98%
CVE-2026-24061 network Patched
CRITICAL 9.8
GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)
CVE-2026-12485 network Patched
CRITICAL 10
FFmpeg MagicYUV Decoder Out-of-Bounds Write / RCE — PixelSmash (CVE-2026-8461)
CVE-2026-8461 binary Patched
HIGH 8.8
Claude Desktop Cowork VM Image Integrity Bypass / Local Persistence (CVE-2026-7574)
CVE-2026-7574 binary Unverified
HIGH 8.7
Windows CTFMON Arbitrary Section Object EoP — GreenPlasma (CVE-2026-45586)
CVE-2026-45586 binary Patched
HIGH 7.8
Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910) KEV EPSS 85%
CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 network Patched
CRITICAL 10
Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253) KEV EPSS 97%
CVE-2026-20253 web Patched
CRITICAL
Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523) KEV EPSS 100%
CVE-2026-10520, CVE-2026-10523 network Patched
CRITICAL 10
DirtyClone — Linux Kernel LPE via Cloned Packet Page-Cache Overwrite (CVE-2026-43503)
CVE-2026-43503 binary Patched
HIGH 8.8
Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245) KEV EPSS 25%
CVE-2026-20245 network Unpatched
HIGH 7.8
Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751) KEV RW EPSS 84%
CVE-2026-50751 network Patched
CRITICAL 9.3
YellowKey — BitLocker Bypass via WinRE autofstx.exe (CVE-2026-45585)
CVE-2026-45585 misc Patched
MEDIUM 6.1
CVE-2026-50656 RoguePlanet — Safe Vulnerability Checker (Resurface) EPSS 11%
CVE-2026-50656 binary Patched
HIGH 7.8
RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition EPSS 11%
CVE-2026-50656 binary Unpatched
HIGH 7.8
FirefUXSS: Universal XSS in Firefox Focus for iOS via Redirect-Scheme Validation Race Condition
web Unpatched
CRITICAL 9.3
ssh-keysign-pwn: pidfd_getfd FD Theft via mm-NULL Exit Window (CVE-2026-46333)
CVE-2026-46333 binary Patched
HIGH
Netlogon CLDAP Stack Buffer Overflow (CVE-2026-41089) EPSS 80%
CVE-2026-41089 network Patched
CRITICAL 9.8
LiteSpeed User-End cPanel Plugin Local Privilege Escalation (CVE-2026-48172) KEV EPSS 19%
CVE-2026-48172 web Unverified
HIGH
Drupal Core PostgreSQL SQL Injection (CVE-2026-9082) KEV EPSS 88%
CVE-2026-9082 / SA-CORE-2026-004 web Patched
CRITICAL
Notepad++ <= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)
CVE-2026-48770, CVE-2026-48778, CVE-2026-48800 binary Patched
HIGH 5
PinTheft: RDS Double-Free → LPE
binary Unverified
HIGH
TossUp — TerraMaster TOS Unauthenticated Redis Root RCE + NFS LPE
N/A (vendor confirmed TOS4 is EOL; no fix planned) network Unpatched
CRITICAL
DirtyDecrypt / DirtyCBC — rxgk Page-Cache Write (Dirty Pipe Variant)
N/A (reported as duplicate by kernel maintainers; patched on mainline) binary Unverified
HIGH
Chrome WebGPU Use-After-Free (CVE-2026-5281) KEV
CVE-2026-5281 web Unverified
HIGH 8.8
Windows NTLM Hash Disclosure via File Explorer - CVE-2025-24054 KEV EPSS 59%
CVE-2025-24054 binary Unverified
MEDIUM 6.5
Windows MMC MSC EvilTwin - CVE-2025-26633 KEV RW EPSS 30%
CVE-2025-26633 binary Unverified
HIGH
Windows Kernel Elevation of Privilege - Race Condition / Double-Free (CVE-2025-62215) KEV
CVE-2025-62215 binary Patched
HIGH 7
ToolShell - SharePoint Unauthenticated RCE Chain KEV RW EPSS 100%
CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706 web Patched
CRITICAL
React2Shell - Next.js RSC Unauthenticated RCE KEV RW EPSS 100%
CVE-2025-55182 web Patched
CRITICAL 10
Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400) KEV RW EPSS 100%
CVE-2024-3400 web Patched
CRITICAL 10
Next.js x-nextjs-data Cache Poisoning (CVE-2026-44572)
CVE-2026-44572 web Patched
LOW 3.1
Next.js WebSocket Upgrade SSRF (Self-Hosted) (CVE-2026-44578) EPSS 39%
CVE-2026-44578 web Patched
HIGH 8.6
Next.js RSC Server-Action DoS via Flight Deserialization (CVE-2026-23870)
CVE-2026-23870 web Patched
HIGH 7.5
Next.js RSC Response Cache Poisoning (CVE-2026-44576)
CVE-2026-44576 web Patched
MEDIUM 5.4
Next.js RSC Cache-Busting Weak Hash Collision (CVE-2026-44582)
CVE-2026-44582 web Patched
LOW 3.7
Next.js Image Optimization API OOM DoS (Self-Hosted) (CVE-2026-44577)
CVE-2026-44577 web Patched
MEDIUM 5.9
Next.js i18n Middleware Bypass (CVE-2026-44573)
CVE-2026-44573 web Patched
HIGH 7.5
Next.js Dynamic Route Injection Auth Bypass (CVE-2026-44574)
CVE-2026-44574 web Patched
HIGH 8.1
Next.js CSP Nonce Cache-Poisoned XSS (CVE-2026-44581)
CVE-2026-44581 web Patched
MEDIUM 4.7
Next.js Cache Components Connection Exhaustion DoS (CVE-2026-44579)
CVE-2026-44579 web Patched
HIGH 7.5
Next.js beforeInteractive Script XSS (CVE-2026-44580)
CVE-2026-44580 web Patched
MEDIUM 6.1
Next.js App Router Segment-Prefetch Middleware Bypass (CVE-2026-44575)
CVE-2026-44575 web Patched
HIGH 7.5
Linux vsock Use-After-Free VM Escape (CVE-2025-21756)
CVE-2025-21756 binary Patched
HIGH 7.8
Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086) KEV RW EPSS 28%
CVE-2024-1086 binary Patched
HIGH 7.8
Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897) KEV RW EPSS 100%
CVE-2024-23897 web Patched
CRITICAL 9.8
Ivanti Connect Secure Pre-Auth RCE (Stack Overflow) KEV RW EPSS 100%
CVE-2025-0282 network Unverified
CRITICAL 9
IngressNightmare - Kubernetes Ingress-NGINX Unauthenticated RCE EPSS 100%
CVE-2025-1974 (primary); also CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 cloud Unverified
CRITICAL 9.8
Fortinet FortiManager FortiJump Unauthenticated RCE (CVE-2024-47575) KEV EPSS 95%
CVE-2024-47575 network Unverified
CRITICAL 9.8
Fortinet FortiCloud SSO Authentication Bypass KEV EPSS 69%
CVE-2025-59718, CVE-2025-59719 (Advisory: FG-IR-25-647) network Unverified
CRITICAL 9.8
Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433 KEV EPSS 99%
CVE-2025-32433 network Patched
CRITICAL 10
Copy Fail Linux Kernel Local Privilege Escalation (CVE-2026-31431) KEV EPSS 100%
CVE-2026-31431 binary Patched
HIGH
Confluence SSTI RCE - CVE-2023-22527 KEV RW EPSS 100%
CVE-2023-22527 web Patched
CRITICAL 10
Confluence Post-Auth RCE - CVE-2024-21683 EPSS 88%
CVE-2024-21683 web Unverified
HIGH 8.3
Azure Networking Privilege Escalation via Missing Privilege Check
CVE-2025-54914 cloud Patched
CRITICAL 10
Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918 EPSS 50%
CVE-2026-23918 web Patched
CRITICAL
Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298) EPSS 81%
CVE-2025-21298 binary Patched
CRITICAL 9.8
VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079) KEV EPSS 22%
CVE-2024-37079 network Patched
CRITICAL 9.8
VMware ESXi Active Directory Authentication Bypass (CVE-2024-37085) KEV RW EPSS 27%
CVE-2024-37085 network Patched
MEDIUM 6.8
QEMUtiny - QEMU CXL Type-3 Memory Corruption Chain
binary Unverified
CRITICAL
Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108) KEV EPSS 98%
CVE-2025-0108 web Patched
CRITICAL 9.1
OpenSSH regreSSHion Signal-Handler Race Unauthenticated RCE (CVE-2024-6387) EPSS 100%
CVE-2024-6387 network Patched
HIGH 8.1
Fortinet FortiOS SSL VPN Unauthenticated RCE (CVE-2024-21762) KEV RW EPSS 84%
CVE-2024-21762 web Patched
CRITICAL 9.6
Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591) KEV RW EPSS 98%
CVE-2024-55591 (Fortinet FG-IR-24-535) web Unverified
CRITICAL 9.6
cPanel & WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940) KEV RW EPSS 99%
CVE-2026-41940 web Patched
CRITICAL 10
Citrix NetScaler CitrixBleed 2 Session Token Disclosure (CVE-2025-5777) KEV RW EPSS 100%
CVE-2025-5777 web Patched
CRITICAL 9.3
Chrome CSSFontFeatureValuesMap Use-After-Free (CVE-2026-2441) KEV EPSS 22%
CVE-2026-2441 web Unpatched
HIGH 8.8
Apache Parquet Java Unsafe Deserialization RCE (CVE-2025-30065) EPSS 43%
CVE-2025-30065 misc Patched
CRITICAL 10
Adobe Acrobat/Reader Prototype Pollution Sandbox Escape (CVE-2026-34621) KEV
CVE-2026-34621 binary Unverified
CRITICAL 9.8
WinRAR Archive Extraction Path Traversal (CVE-2025-6218) KEV EPSS 90%
CVE-2025-6218 misc Unverified
HIGH
RedSun Privileged File Write (CVE-2026-33825) KEV RW
CVE-2026-33825 binary Patched
HIGH 7.8
Next.js Corrupt Middleware Auth Bypass (CVE-2025-29927) EPSS 99%
CVE-2025-29927 web Patched
CRITICAL 9.1
MiniPlasma - Windows Cloud Files Mini Filter Driver LPE (CVE-2020-17103) EPSS 27%
CVE-2020-17103 binary Patched
HIGH 7.8
LDAP Nightmare — Windows LDAP Client RCE/DoS (CVE-2024-49113) EPSS 83%
CVE-2024-49113 network Patched
CRITICAL
HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166) KEV EPSS 100%
CVE-2021-31166 network Patched
CRITICAL 9.8
Exchange Health Checker Outbound Rule Blind Spot (CVE-2026-42897) KEV EPSS 71%
CVE-2026-42897 web Unverified
MEDIUM 5.3
CVE-2024-21338 — Local Privilege Escalation from Admin to Kernel KEV RW EPSS 60%
CVE-2024-21338 binary Patched
HIGH 7.8
BlueHammer Defender Local Privilege Escalation (CVE-2026-33825) KEV RW
CVE-2026-33825 binary Patched
HIGH 7.8
BlueDucky — Unauthenticated Peering Leading to Code Execution (CVE-2023-45866)
CVE-2023-45866 network Patched
HIGH 8.8
NGINX Rift — Heap Buffer Overflow RCE (CVE-2026-42945) EPSS 68%
CVE-2026-42945 web Unverified
CRITICAL 9.8
Linux XFRM ESP-in-TCP Local Privilege Escalation (Fragnesia)
CVE-2026-46300 binary Patched
HIGH 7.8
Dirty Frag: Linux XFRM/RxRPC Page Cache Write Chain LPE EPSS 93%
CVE-2026-43500, CVE-2026-43284 binary Patched
CRITICAL 7.8
CVE-2026-27876: Grafana SQL Expressions Arbitrary File Write to RCE
Unverified