| WordPress Divi Ajax Filter LFI (CVE-2026-11613)
new CVE-2026-11613
web
Unverified | CVE-2026-11613 | web | CRITICAL 9.8 | Unverified | 2026-09-05 |
| WP Cookie Notice Unauthenticated File Upload RCE (CVE-2026-82970)
new CVE-2026-82970
web
Unverified | CVE-2026-82970 | web | CRITICAL 10 | Unverified | 2026-09-03 |
| Kestra Authentication Bypass to RCE (CVE-2026-49869)
new CVE-2026-49869, CVE-2026-53576
web
Unverified | CVE-2026-49869, CVE-2026-53576 | web | CRITICAL 10 | Unverified | 2026-09-03 |
| Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)
new
KEV
RW
EPSS 100% CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD)
network
Unverified | CVE-2023-35078 | network | CRITICAL 9.8 | Unverified | 2026-08-09 |
| Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457)
new
KEV
RW
EPSS 100% CVE-2025-22457
network
Unpatched | CVE-2025-22457 | network | CRITICAL 9 | Unpatched | 2026-08-09 |
| GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205)
new
KEV
RW
EPSS 100% CVE-2021-22205 (chains CVE-2021-22204 in ExifTool)
web
Patched | CVE-2021-22205 | web | CRITICAL 10 | Patched | 2026-08-09 |
| CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378)
new
KEV
RW
EPSS 95% CVE-2024-51378
web
Patched | CVE-2024-51378 | web | CRITICAL 10 | Patched | 2026-08-09 |
| Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)
new NotCVE-2026-0010 (disputed CVE assignment — author contests the identifier)
binary
Unverified | NotCVE-2026-0010 | binary | HIGH | Unverified | 2026-08-01 |
| Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)
new CVE-2026-65694 (VulnCheck advisory)
web
Patched | CVE-2026-65694 | web | HIGH 7.5 | Patched | 2026-07-31 |
| IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198)
new
KEV
EPSS 35% CVE-2026-9198
web
Patched | CVE-2026-9198 | web | CRITICAL 9.8 | Patched | 2026-07-31 |
| Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432)
new
KEV
EPSS 100% CVE-2025-32432
web
Patched | CVE-2025-32432 | web | CRITICAL 10 | Patched | 2026-07-31 |
| Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066)
new
EPSS 28% CVE-2026-66066 (GHSA-xr9x-r78c-5hrm)
web
Patched | CVE-2026-66066 | web | CRITICAL 9.5 | Patched | 2026-07-27 |
| Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522)
new
KEV
EPSS 85% CVE-2026-50522
web
Patched | CVE-2026-50522 | web | CRITICAL 9.8 | Patched | 2026-07-27 |
| Joomla Helix Ultimate Framework — Unauthenticated Arbitrary File Deletion (CVE-2026-57830)
new CVE-2026-57830
web
Patched | CVE-2026-57830 | web | CRITICAL 9.1 | Patched | 2026-07-27 |
| Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291)
new
KEV
EPSS 15% CVE-2026-56291
web
Unverified | CVE-2026-56291 | web | CRITICAL 9.8 | Unverified | 2026-07-27 |
| Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)
new CVE-2026-53753 (GHSA-qxjp-w3pj-48m7)
web
Patched | CVE-2026-53753 | web | CRITICAL 9.8 | Patched | 2026-07-27 |
| Budibase Unauthenticated NoSQL Operator Injection (CVE-2026-54350)
new CVE-2026-54350 (GHSA-8qv3-p479-cj62)
web
Patched | CVE-2026-54350 | web | CRITICAL 10 | Patched | 2026-07-27 |
| Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)
new CVE-2026-49230
web
Patched | CVE-2026-49230 | web | CRITICAL 9.1 | Patched | 2026-07-27 |
| wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137)
new
KEV
EPSS 97% CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf
web
Patched | CVE-2026-63030 | web | CRITICAL 9.1 | Patched | 2026-07-19 |
| SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558)
new
KEV
EPSS 12% CVE-2026-48558
web
Patched | CVE-2026-48558 | web | CRITICAL 10 | Patched | 2026-07-19 |
| Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230)
new
KEV
EPSS 88% CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW)
network
Patched | CVE-2026-20230 | network | CRITICAL 8.6 | Patched | 2026-07-19 |
| Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282)
new
KEV
EPSS 42% CVE-2026-48282 (Adobe APSB26-68)
web
Patched | CVE-2026-48282 | web | CRITICAL 10 | Patched | 2026-07-19 |
| SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409)
new
KEV
RW
EPSS 84% CVE-2026-15409 (SNWLID-2026-0008)
network
Patched | CVE-2026-15409 | network | CRITICAL 10 | Patched | 2026-07-15 |
| Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
new CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8)
web
Patched | CVE-2026-56271 | web | CRITICAL 9.8 | Patched | 2026-07-12 |
| Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
new CVE-2026-56260 (GHSA-365w-hqf6-vxfg)
web
Patched | CVE-2026-56260 | web | CRITICAL 9.1 | Patched | 2026-07-12 |
| ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950)
new
KEV
EPSS 85% CVE-2023-38950
web
Patched | CVE-2023-38950 | web | HIGH 7.5 | Patched | 2026-07-11 |
| Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)
new
KEV
EPSS 20% CVE-2026-48939
web
Patched | CVE-2026-48939 | web | CRITICAL 9.8 | Patched | 2026-07-11 |
| Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237)
new
KEV
RW
EPSS 98% CVE-2021-42237 (Sitecore advisory SC2021-003-499266)
web
Patched | CVE-2021-42237 | web | CRITICAL 9.8 | Patched | 2026-07-11 |
| LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)
new
KEV
EPSS 89% CVE-2026-42208 (GHSA-r75f-5x8p-qvmc)
web
Patched | CVE-2026-42208 | web | CRITICAL 9.8 | Patched | 2026-07-11 |
| Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)
new CVE-2026-20896 (GHSA-f75j-4cw6-rmx4)
web
Patched | CVE-2026-20896 | web | CRITICAL 9.8 | Patched | 2026-07-11 |
| D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)
new
KEV
EPSS 80% CVE-2022-26258
network
Unverified | CVE-2022-26258 | network | CRITICAL 9.8 | Unverified | 2026-07-11 |
| XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)
new network
Unpatched | — | network | CRITICAL | Unpatched | 2026-07-08 |
| XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893)
new
KEV
EPSS 100% CVE-2025-24893
web
Patched | CVE-2025-24893 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
new CVE-2025-39401
web
Unverified | CVE-2025-39401 | web | CRITICAL 10 | Unverified | 2026-07-06 |
| WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440)
new
EPSS 31% CVE-2025-6440
web
Unverified | CVE-2025-6440 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
new CVE-2025-29009
web
Patched | CVE-2025-29009 | web | CRITICAL 10 | Patched | 2026-07-06 |
| WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
new CVE-2025-12057
web
Unverified | CVE-2025-12057 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass & Admin Credential Log Leak (CVE-2025-13315)
new
EPSS 33% CVE-2025-13315
network
Unpatched | CVE-2025-13315 | network | CRITICAL 9.8 | Unpatched | 2026-07-06 |
| TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)
new CVE-2025-12539
web
Patched | CVE-2025-12539 | web | CRITICAL 10 | Patched | 2026-07-06 |
| StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)
new
EPSS 39% CVE-2025-7441
web
Unpatched | CVE-2025-7441 | web | CRITICAL 9.8 | Unpatched | 2026-07-06 |
| StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)
new
EPSS 15% CVE-2025-48148
web
Unverified | CVE-2025-48148 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Sneeit Framework <= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389)
new
EPSS 76% CVE-2025-6389
web
Unverified | CVE-2025-6389 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)
new CVE-2025-4334
web
Unverified | CVE-2025-4334 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
new CVE-2025-53580
web
Patched | CVE-2025-53580 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)
new CVE-2025-6758
web
Unverified | CVE-2025-6758 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953)
new
KEV
EPSS 94% CVE-2025-11953
network
Patched | CVE-2025-11953 | network | CRITICAL 9.8 | Patched | 2026-07-06 |
| Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132)
new
EPSS 53% CVE-2025-49132
web
Patched | CVE-2025-49132 | web | CRITICAL 10 | Patched | 2026-07-06 |
| Kubio AI Page Builder <= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294)
new
EPSS 78% CVE-2025-2294
web
Unverified | CVE-2025-2294 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
new CVE-2025-12674
web
Unverified | CVE-2025-12674 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| JAY Login & Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)
new CVE-2025-14440
web
Unverified | CVE-2025-14440 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
new CVE-2025-22777
web
Patched | CVE-2025-22777 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
new CVE-2025-13342
web
Patched | CVE-2025-13342 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819)
new
KEV
EPSS 88% CVE-2025-57819
web
Patched | CVE-2025-57819 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)
new CVE-2025-14156
web
Unverified | CVE-2025-14156 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
new CVE-2025-49071
web
Unverified | CVE-2025-49071 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528)
new
EPSS 87% CVE-2025-59528
web
Patched | CVE-2025-59528 | web | CRITICAL 10 | Patched | 2026-07-06 |
| camel-coap Header Injection → RCE Self-Contained Reproducer (CVE-2026-33453)
new CVE-2026-33453
web
Unverified | CVE-2026-33453 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| "Grocery" PHP Application `search_products_itname.php` `sitem_name` Boolean-Based SQL Injection (CVE-2025-65354)
new CVE-2025-65354
web
Unpatched | CVE-2025-65354 | web | CRITICAL 9.8 | Unpatched | 2026-07-06 |
| ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474)
new
EPSS 25% CVE-2026-34474
network
Unverified | CVE-2026-34474 | network | HIGH | Unverified | 2026-07-05 |
| ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)
new CVE-2026-34472
network
Unverified | CVE-2026-34472 | network | CRITICAL | Unverified | 2026-07-05 |
| ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)
new CVE-2026-34473
network
Unverified | CVE-2026-34473 | network | HIGH | Unverified | 2026-07-05 |
| ZAI-Shell — Unauthenticated Remote Code Execution via P2P Terminal Sharing (CVE-2026-25807)
new CVE-2026-25807
network
Patched | CVE-2026-25807 | network | CRITICAL | Patched | 2026-07-05 |
| XWiki Unauthenticated XAR Import Leading to RCE — CVE-2026-33137
new CVE-2026-33137
web
Patched | CVE-2026-33137 | web | CRITICAL 9.3 | Patched | 2026-07-05 |
| Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)
new CVE-2026-39912
web
Patched | CVE-2026-39912 | web | CRITICAL 9.1 | Patched | 2026-07-05 |
| WPvivid Backup & Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357)
new
EPSS 33% CVE-2026-1357
web
Unverified | CVE-2026-1357 | web | CRITICAL | Unverified | 2026-07-05 |
| WP Zendesk for Contact Form 7 Unauthenticated PHP Object Injection (CVE-2026-49105)
new CVE-2026-49105
web
Unverified | CVE-2026-49105 | web | HIGH 8.1 | Unverified | 2026-07-05 |
| WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)
new CVE-2026-40791
web
Patched | CVE-2026-40791 | web | HIGH 7.2 | Patched | 2026-07-05 |
| WP Photo Album Plus Unauthenticated SQL Injection — CVE-2026-6379
new CVE-2026-6379
web
Patched | CVE-2026-6379 | web | CRITICAL 8.6 | Patched | 2026-07-05 |
| WP Insightly Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49085)
new CVE-2026-49085
web
Unverified | CVE-2026-49085 | web | HIGH 8.1 | Unverified | 2026-07-05 |
| WordPress Download Manager 3.3.5.2 — Unauthenticated IDOR (CVE-2026-39676)
new CVE-2026-39676
web
Unverified | CVE-2026-39676 | web | MEDIUM | Unverified | 2026-07-05 |
| WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180
new CVE-2026-3180
web
Unverified | CVE-2026-3180 | web | HIGH | Unverified | 2026-07-05 |
| WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844)
new
EPSS 28% CVE-2026-3844
web
Unverified | CVE-2026-3844 | web | CRITICAL | Unverified | 2026-07-05 |
| WordPress "Form Maker" Plugin Unauthenticated SQL Injection — CVE-2026-3359
new CVE-2026-3359
web
Unverified | CVE-2026-3359 | web | CRITICAL | Unverified | 2026-07-05 |
| WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
new CVE-2026-27542 (bundled with CVE-2026-27540)
web
Unverified | CVE-2026-27542 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| Veno File Manager Unauthenticated User Enumeration (CVE-2026-37064)
new CVE-2026-37064
web
Unverified | CVE-2026-37064 | web | MEDIUM | Unverified | 2026-07-05 |
| Veno File Manager Incorrect Access Control — Application Log Extraction (CVE-2026-37067)
new CVE-2026-37067
web
Unverified | CVE-2026-37067 | web | MEDIUM | Unverified | 2026-07-05 |
| Veno File Manager Absolute Path Disclosure (CVE-2026-37069)
new CVE-2026-37069
web
Unverified | CVE-2026-37069 | web | LOW | Unverified | 2026-07-05 |
| Veno File Manager 4.4.9 — Unauthenticated LFI to Superadmin Takeover (CVE-2026-37072)
new CVE-2026-37072
web
Unverified | CVE-2026-37072 | web | CRITICAL | Unverified | 2026-07-05 |
| Veno File Manager 4.4.9 — Unauthenticated Email Hijack via SMTP Relay (CVE-2026-37073)
new CVE-2026-37073
web
Unverified | CVE-2026-37073 | web | MEDIUM | Unverified | 2026-07-05 |
| User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)
new CVE-2026-4882
web
Unverified | CVE-2026-4882 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| User Registration & Membership Unauthenticated Admin Privilege Escalation (CVE-2026-1492)
new
EPSS 24% CVE-2026-1492
web
Unverified | CVE-2026-1492 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| UpdraftPlus WordPress Plugin — Unauthenticated RPC Key Bypass to Admin Creation & RCE (CVE-2026-10795)
new CVE-2026-10795
web
Unverified | CVE-2026-10795 | web | CRITICAL | Unverified | 2026-07-05 |
| Unauthenticated SSRF in Ech0 via /api/website/title (CVE-2026-35037)
new CVE-2026-35037
web
Patched | CVE-2026-35037 | web | HIGH | Patched | 2026-07-05 |
| Unauthenticated NaN Injection via MAVLink PARAM_SET in ArduPilot ArduPlane (CVE-2026-36522)
new CVE-2026-36522
network
Unverified | CVE-2026-36522 | network | CRITICAL 9.1 | Unverified | 2026-07-05 |
| Typebot Unauthenticated Preview-Chat SSRF — CVE-2026-33712
new CVE-2026-33712
web
Patched | CVE-2026-33712 | web | HIGH | Patched | 2026-07-05 |
| The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)
new CVE-2026-49772
web
Patched | CVE-2026-49772 | web | CRITICAL 9.3 | Patched | 2026-07-05 |
| Spring AI SimpleVectorStore SpEL Injection RCE (CVE-2026-22738)
new CVE-2026-22738
web
Patched | CVE-2026-22738 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Sparx Enterprise Architect / Pro Cloud Server Unauthenticated Binary-Protocol SQL Injection (CVE-2026-42096)
new CVE-2026-42096
network
Unverified | CVE-2026-42096 | network | CRITICAL | Unverified | 2026-07-05 |
| Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056)
new
EPSS 12% CVE-2026-1056
web
Unverified | CVE-2026-1056 | web | CRITICAL | Unverified | 2026-07-05 |
| SmarterMail Unauthenticated Admin Password Reset (CVE-2026-0001 / WT-2026-0001)
new CVE-2026-0001 (tracked publicly as WT-2026-0001)
web
Patched | CVE-2026-0001 | web | CRITICAL 9 | Patched | 2026-07-05 |
| SmarterMail ConnectToHub Unauthenticated SSRF Leading to Remote Command Execution — CVE-2026-24423
new
KEV
RW
EPSS 88% CVE-2026-24423
web
Unverified | CVE-2026-24423 | web | CRITICAL | Unverified | 2026-07-05 |
| Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912
new CVE-2026-11912
web
Patched | CVE-2026-11912 | web | HIGH 7.5 | Patched | 2026-07-05 |
| School Management System 1.0 — Reflected XSS in register.php (CVE-2026-37750)
new CVE-2026-37750
web
Unverified | CVE-2026-37750 | web | MEDIUM 6.1 | Unverified | 2026-07-05 |
| Schema & Structured Data for WP & AMP Unauthenticated Unrestricted File Upload (CVE-2026-9067)
new CVE-2026-9067
web
Unverified | CVE-2026-9067 | web | HIGH 8.1 | Unverified | 2026-07-05 |
| Saleor GraphQL IDOR — Unauthenticated Order PII Exfiltration (CVE-2026-24136)
new CVE-2026-24136
web
Patched | CVE-2026-24136 | web | HIGH 7.5 | Patched | 2026-07-05 |
| Rocket.Chat OAuth2 NoSQL Injection Privilege Escalation — CVE-2026-29198
new CVE-2026-29198
web
Patched | CVE-2026-29198 | web | CRITICAL | Patched | 2026-07-05 |
| Responsive Filemanager 9.14.0 — Unauthenticated RCE via Duplicate File (CVE-2026-39023)
new CVE-2026-39023
web
Unpatched | CVE-2026-39023 | web | CRITICAL | Unpatched | 2026-07-05 |
| rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)
new CVE-2026-41179
web
Patched | CVE-2026-41179 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| ProjeQtor Unauthenticated Login SQL Injection (CVE-2026-41462)
new CVE-2026-41462
web
Patched | CVE-2026-41462 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| ProFTPD mod_sql Pre-Auth SQL Injection Leading to RCE (CVE-2026-42167)
new CVE-2026-42167
network
Patched | CVE-2026-42167 | network | HIGH 8.1 | Patched | 2026-07-05 |
| Prodigy Commerce WordPress Plugin — Unauthenticated Local File Inclusion (CVE-2026-0926)
new CVE-2026-0926
web
Unverified | CVE-2026-0926 | web | HIGH | Unverified | 2026-07-05 |
| Plunk SSRF via Unvalidated AWS SNS SubscriptionConfirmation — CVE-2026-32096
new CVE-2026-32096
cloud
Patched | CVE-2026-32096 | cloud | CRITICAL 9.3 | Patched | 2026-07-05 |
| Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
new CVE-2026-4885
web
Unverified | CVE-2026-4885 | web | CRITICAL | Unverified | 2026-07-05 |
| phpVMS Unauthenticated Legacy Importer Database Wipe (CVE-2026-42569)
new CVE-2026-42569
web
Patched | CVE-2026-42569 | web | CRITICAL | Patched | 2026-07-05 |
| Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
new CVE-2026-26198 (GHSA-xxh2-68g9-8jqr)
web
Patched | CVE-2026-26198 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| OpenXDMoD `user_interface.php` Report Title Command Injection (CVE-2026-45777)
new CVE-2026-45777
web
Patched | CVE-2026-45777 | web | CRITICAL | Patched | 2026-07-05 |
| OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)
new CVE-2026-41900 (GHSA-8h25-q488-4hxw)
cloud
Patched | CVE-2026-41900 | cloud | HIGH 8.6 | Patched | 2026-07-05 |
| Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519
new CVE-2026-53519 (GHSA-5c25-7vpj-9mqh)
web
Patched | CVE-2026-53519 | web | INFO | Patched | 2026-07-05 |
| MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483)
new
EPSS 11% CVE-2026-27483
web
Patched | CVE-2026-27483 | web | CRITICAL | Patched | 2026-07-05 |
| MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356)
new
EPSS 14% CVE-2026-36356
network
Unverified | CVE-2026-36356 | network | CRITICAL | Unverified | 2026-07-05 |
| mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825)
new
EPSS 13% CVE-2026-27825 (read-side twin of GHSA-xjgw-4wvw-rgm4)
web
Patched | CVE-2026-27825 | web | CRITICAL 9.3 | Patched | 2026-07-05 |
| MagicMirror² Unauthenticated SSRF via `/cors` Endpoint (CVE-2026-42281)
new CVE-2026-42281
web
Patched | CVE-2026-42281 | web | CRITICAL 9.2 | Patched | 2026-07-05 |
| Langflow Unauthenticated Remote Code Execution via `validate/code` Endpoint (CVE-2026-0770)
new
KEV
EPSS 63% CVE-2026-0770
web
Patched | CVE-2026-0770 | web | CRITICAL | Patched | 2026-07-05 |
| Langflow Remote Code Execution — CVE-2026-27966
new
EPSS 34% CVE-2026-27966
web
Patched | CVE-2026-27966 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)
new CVE-2026-0920
web
Unverified | CVE-2026-0920 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)
new CVE-2026-8206
web
Unverified | CVE-2026-8206 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| Kan SSRF via Attachment Download Endpoint — CVE-2026-32255
new
EPSS 21% CVE-2026-32255 (GHSA-qrx8-9hc6-jvqg)
web
Patched | CVE-2026-32255 | web | HIGH 8.6 | Patched | 2026-07-05 |
| Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627
new CVE-2026-21627
web
Patched | CVE-2026-21627 | web | CRITICAL 9.5 | Patched | 2026-07-05 |
| JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)
new CVE-2026-49048 (Advisory ID JOOMCCK-2026-001)
web
Unpatched | CVE-2026-49048 | web | CRITICAL 8.7 | Unpatched | 2026-07-05 |
| JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
new CVE-2026-49079
web
Unverified | CVE-2026-49079 | web | HIGH 7.5 | Unverified | 2026-07-05 |
| InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)
new CVE-2026-23491
web
Patched | CVE-2026-23491 | web | CRITICAL | Patched | 2026-07-05 |
| Integration for Keap/Infusionsoft Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49104)
new CVE-2026-49104
web
Unverified | CVE-2026-49104 | web | HIGH 8.1 | Unverified | 2026-07-05 |
| Integration for ActiveCampaign Unauthenticated PHP Object Injection via Unsafe Deserialization (CVE-2026-9691)
new CVE-2026-9691
web
Unpatched | CVE-2026-9691 | web | HIGH 8.1 | Unpatched | 2026-07-05 |
| Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
new CVE-2026-10580
web
Unverified | CVE-2026-10580 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| Gravity Forms Unauthenticated Reflected XSS via `gform_get_config` `form_ids` Parameter (CVE-2026-4406)
new CVE-2026-4406
web
Patched | CVE-2026-4406 | web | MEDIUM 6.1 | Patched | 2026-07-05 |
| Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)
new CVE-2026-42589
web
Patched | CVE-2026-42589 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Gitea Container Registry Anonymous Auth Bypass (CVE-2026-27771)
new CVE-2026-27771
web
Patched | CVE-2026-27771 | web | CRITICAL | Patched | 2026-07-05 |
| Ghost CMS Content API — Unauthenticated Blind SQL Injection (CVE-2026-26980)
new
EPSS 70% CVE-2026-26980
web
Patched | CVE-2026-26980 | web | CRITICAL | Patched | 2026-07-05 |
| FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895)
new
EPSS 11% CVE-2026-25895
web
Patched | CVE-2026-25895 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| FOSSBilling Unauthenticated API Key Config Disclosure & Password Reset Token Reuse — CVE-2026-53647
new CVE-2026-53647 (also documents chained CVE-2026-53646)
web
Patched | CVE-2026-53647 | web | MEDIUM 6.9 | Patched | 2026-07-05 |
| FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808)
new
KEV
EPSS 93% CVE-2026-39808
network
Unverified | CVE-2026-39808 | network | CRITICAL 9.8 | Unverified | 2026-07-05 |
| Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089)
new
KEV
EPSS 76% CVE-2026-25089
network
Patched | CVE-2026-25089 | network | CRITICAL 9.8 | Patched | 2026-07-05 |
| Flowise NVIDIA NIM Endpoint Authentication Bypass — CVE-2026-30824
new
EPSS 36% CVE-2026-30824
web
Patched | CVE-2026-30824 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337
new CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx))
web
Unverified | CVE-2026-54337 | web | INFO | Unverified | 2026-07-05 |
| Everest Forms Pro Unauthenticated PHP Code Injection via Calculation Addon (CVE-2026-3300)
new
EPSS 39% CVE-2026-3300
web
Unverified | CVE-2026-3300 | web | CRITICAL | Unverified | 2026-07-05 |
| EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657
new CVE-2026-1657
web
Patched | CVE-2026-1657 | web | MEDIUM | Patched | 2026-07-05 |
| Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)
new CVE-2026-40776 / Patchstack PSID 85de025d71e7
web
Patched | CVE-2026-40776 / Patchstack PSID 85de025d71e7 | web | HIGH 7.5 | Patched | 2026-07-05 |
| Easy Elements for Elementor Unauthenticated Privilege Escalation via `custom_meta` Overwrite (CVE-2026-9018)
new CVE-2026-9018
web
Patched | CVE-2026-9018 | web | HIGH 8.8 | Patched | 2026-07-05 |
| Divi Form Builder <= 5.1.2 Unauthenticated Privilege Escalation via Role Injection (CVE-2026-5118)
new CVE-2026-5118
web
Unverified | CVE-2026-5118 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| dedoc/scramble Laravel API-Doc Generator Unauthenticated eval() RCE (CVE-2026-44262)
new CVE-2026-44262 / [GHSA-4rm2-28vj-fj39](https://github.com/advisories/GHSA-4rm2-28vj-fj39)
web
Patched | CVE-2026-44262 / [GHSA-4rm2-28vj-fj39] | web | CRITICAL | Patched | 2026-07-05 |
| Contact Form by Supsystic <= 1.7.36 Unauthenticated SSTI to RCE (CVE-2026-4257)
new
EPSS 41% CVE-2026-4257
web
Unverified | CVE-2026-4257 | web | CRITICAL | Unverified | 2026-07-05 |
| CodeAstro Simple Attendance Management System 1.0 — SQL Injection Auth Bypass (CVE-2026-37749)
new CVE-2026-37749
web
Unverified | CVE-2026-37749 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| Chamilo LMS Unauthenticated install.ajax.php SSRF + Open Mail Relay — CVE-2026-33715
new CVE-2026-33715 / GHSA-mxc9-9335-45mc
web
Unverified | CVE-2026-33715 / GHSA-mxc9-9335-45mc | web | HIGH 7.5 | Unverified | 2026-07-05 |
| Business Directory Plugin for WordPress — Unauthenticated Time-Based Blind SQL Injection (CVE-2026-2576)
new CVE-2026-2576
web
Patched | CVE-2026-2576 | web | HIGH 7.5 | Patched | 2026-07-05 |
| Branda White Label & Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551
new CVE-2026-11551
web
Patched | CVE-2026-11551 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)
new CVE-2026-6960
web
Unverified | CVE-2026-6960 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| Avada Builder Unauthenticated RCE via call_user_func() Allowlist Bypass (CVE-2026-6279)
new CVE-2026-6279
web
Unverified | CVE-2026-6279 | web | CRITICAL | Unverified | 2026-07-05 |
| Apache Tomcat Tribes EncryptInterceptor Fail-Open Unauthenticated RCE (CVE-2026-34486)
new
KEV
EPSS 99% CVE-2026-34486
web
Patched | CVE-2026-34486 | web | CRITICAL | Patched | 2026-07-05 |
| Apache Camel camel-coap Header Injection to Remote Code Execution (CVE-2026-33453)
new CVE-2026-33453
web
Patched | CVE-2026-33453 | web | CRITICAL 10 | Patched | 2026-07-05 |
| Advanced Custom Fields: Extended Unauthenticated Privilege Escalation via `_acf_post_id` Validation Bypass (CVE-2026-8809)
new CVE-2026-8809
web
Unverified | CVE-2026-8809 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| AdForest WordPress Theme OTP Login Authentication Bypass — CVE-2026-1729
new CVE-2026-1729
web
Unverified | CVE-2026-1729 | web | CRITICAL | Unverified | 2026-07-05 |
| Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248)
new
KEV
RW
EPSS 100% CVE-2025-3248
web
Patched | CVE-2025-3248 | web | CRITICAL 9.8 | Patched | 2026-07-03 |
| Citrix NetScaler ADC/Gateway Pre-Auth SAML Memory Overread — "CitrixBleed"-style Leak (CVE-2026-8451)
new
EPSS 16% CVE-2026-8451
network
Unverified | CVE-2026-8451 | network | HIGH 7.5 | Unverified | 2026-07-03 |
| Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247)
new
KEV
EPSS 28% CVE-2026-45247
web
Unverified | CVE-2026-45247 | web | CRITICAL 9.3 | Unverified | 2026-07-01 |
| Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907)
new
KEV
EPSS 78% CVE-2026-48907
web
Patched | CVE-2026-48907 | web | CRITICAL 10 | Patched | 2026-07-01 |
| PAN-OS GlobalProtect Authentication Bypass via Forged Cookie (CVE-2026-0257)
new
KEV
RW
EPSS 94% CVE-2026-0257
web
Unverified | CVE-2026-0257 | web | HIGH 7.8 | Unverified | 2026-07-01 |
| SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)
new
KEV
EPSS 15% CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p)
web
Patched | CVE-2026-48908 | web | CRITICAL 10 | Patched | 2026-06-30 |
| libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)
new CVE-2026-55200
network
Patched | CVE-2026-55200 | network | CRITICAL 9.8 | Patched | 2026-06-30 |
| GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061)
new
KEV
EPSS 98% CVE-2026-24061
network
Patched | CVE-2026-24061 | network | CRITICAL 9.8 | Patched | 2026-06-30 |
| GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)
new CVE-2026-12485
network
Patched | CVE-2026-12485 | network | CRITICAL 10 | Patched | 2026-06-30 |
| Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253)
new
KEV
EPSS 97% CVE-2026-20253
web
Patched | CVE-2026-20253 | web | CRITICAL | Patched | 2026-06-28 |
| Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751)
new
KEV
RW
EPSS 84% CVE-2026-50751
network
Patched | CVE-2026-50751 | network | CRITICAL 9.3 | Patched | 2026-06-28 |
| Netlogon CLDAP Stack Buffer Overflow (CVE-2026-41089)
new
EPSS 80% CVE-2026-41089
network
Patched | CVE-2026-41089 | network | CRITICAL 9.8 | Patched | 2026-06-04 |
| Drupal Core PostgreSQL SQL Injection (CVE-2026-9082)
new
KEV
EPSS 88% CVE-2026-9082 / SA-CORE-2026-004
web
Patched | CVE-2026-9082 / SA-CORE-2026-004 | web | CRITICAL | Patched | 2026-05-30 |
| TossUp — TerraMaster TOS Unauthenticated Redis Root RCE + NFS LPE
new N/A (vendor confirmed TOS4 is EOL; no fix planned)
network
Unpatched | N/A | network | CRITICAL | Unpatched | 2026-05-18 |
| Chrome WebGPU Use-After-Free (CVE-2026-5281)
new
KEV CVE-2026-5281
web
Unverified | CVE-2026-5281 | web | HIGH 8.8 | Unverified | 2026-05-18 |
| ToolShell - SharePoint Unauthenticated RCE Chain
new
KEV
RW
EPSS 100% CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706
web
Patched | CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706 | web | CRITICAL | Patched | 2026-05-17 |
| React2Shell - Next.js RSC Unauthenticated RCE
new
KEV
RW
EPSS 100% CVE-2025-55182
web
Patched | CVE-2025-55182 | web | CRITICAL 10 | Patched | 2026-05-17 |
| Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400)
new
KEV
RW
EPSS 100% CVE-2024-3400
web
Patched | CVE-2024-3400 | web | CRITICAL 10 | Patched | 2026-05-17 |
| Next.js x-nextjs-data Cache Poisoning (CVE-2026-44572)
new CVE-2026-44572
web
Patched | CVE-2026-44572 | web | LOW 3.1 | Patched | 2026-05-17 |
| Next.js WebSocket Upgrade SSRF (Self-Hosted) (CVE-2026-44578)
new
EPSS 39% CVE-2026-44578
web
Patched | CVE-2026-44578 | web | HIGH 8.6 | Patched | 2026-05-17 |
| Next.js RSC Server-Action DoS via Flight Deserialization (CVE-2026-23870)
new CVE-2026-23870
web
Patched | CVE-2026-23870 | web | HIGH 7.5 | Patched | 2026-05-17 |
| Next.js RSC Response Cache Poisoning (CVE-2026-44576)
new CVE-2026-44576
web
Patched | CVE-2026-44576 | web | MEDIUM 5.4 | Patched | 2026-05-17 |
| Next.js RSC Cache-Busting Weak Hash Collision (CVE-2026-44582)
new CVE-2026-44582
web
Patched | CVE-2026-44582 | web | LOW 3.7 | Patched | 2026-05-17 |
| Next.js Image Optimization API OOM DoS (Self-Hosted) (CVE-2026-44577)
new CVE-2026-44577
web
Patched | CVE-2026-44577 | web | MEDIUM 5.9 | Patched | 2026-05-17 |
| Next.js i18n Middleware Bypass (CVE-2026-44573)
new CVE-2026-44573
web
Patched | CVE-2026-44573 | web | HIGH 7.5 | Patched | 2026-05-17 |
| Next.js Dynamic Route Injection Auth Bypass (CVE-2026-44574)
new CVE-2026-44574
web
Patched | CVE-2026-44574 | web | HIGH 8.1 | Patched | 2026-05-17 |
| Next.js CSP Nonce Cache-Poisoned XSS (CVE-2026-44581)
new CVE-2026-44581
web
Patched | CVE-2026-44581 | web | MEDIUM 4.7 | Patched | 2026-05-17 |
| Next.js Cache Components Connection Exhaustion DoS (CVE-2026-44579)
new CVE-2026-44579
web
Patched | CVE-2026-44579 | web | HIGH 7.5 | Patched | 2026-05-17 |
| Next.js beforeInteractive Script XSS (CVE-2026-44580)
new CVE-2026-44580
web
Patched | CVE-2026-44580 | web | MEDIUM 6.1 | Patched | 2026-05-17 |
| Next.js App Router Segment-Prefetch Middleware Bypass (CVE-2026-44575)
new CVE-2026-44575
web
Patched | CVE-2026-44575 | web | HIGH 7.5 | Patched | 2026-05-17 |
| Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897)
new
KEV
RW
EPSS 100% CVE-2024-23897
web
Patched | CVE-2024-23897 | web | CRITICAL 9.8 | Patched | 2026-05-17 |
| Ivanti Connect Secure Pre-Auth RCE (Stack Overflow)
new
KEV
RW
EPSS 100% CVE-2025-0282
network
Unverified | CVE-2025-0282 | network | CRITICAL 9 | Unverified | 2026-05-17 |
| IngressNightmare - Kubernetes Ingress-NGINX Unauthenticated RCE
new
EPSS 100% CVE-2025-1974 (primary); also CVE-2025-1097, CVE-2025-1098, CVE-2025-24514
cloud
Unverified | CVE-2025-1974 | cloud | CRITICAL 9.8 | Unverified | 2026-05-17 |
| Fortinet FortiManager FortiJump Unauthenticated RCE (CVE-2024-47575)
new
KEV
EPSS 95% CVE-2024-47575
network
Unverified | CVE-2024-47575 | network | CRITICAL 9.8 | Unverified | 2026-05-17 |
| Fortinet FortiCloud SSO Authentication Bypass
new
KEV
EPSS 69% CVE-2025-59718, CVE-2025-59719 (Advisory: FG-IR-25-647)
network
Unverified | CVE-2025-59718, CVE-2025-59719 | network | CRITICAL 9.8 | Unverified | 2026-05-17 |
| Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433
new
KEV
EPSS 99% CVE-2025-32433
network
Patched | CVE-2025-32433 | network | CRITICAL 10 | Patched | 2026-05-17 |
| Confluence SSTI RCE - CVE-2023-22527
new
KEV
RW
EPSS 100% CVE-2023-22527
web
Patched | CVE-2023-22527 | web | CRITICAL 10 | Patched | 2026-05-17 |
| Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918
new
EPSS 50% CVE-2026-23918
web
Patched | CVE-2026-23918 | web | CRITICAL | Patched | 2026-05-17 |
| Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298)
new
EPSS 81% CVE-2025-21298
binary
Patched | CVE-2025-21298 | binary | CRITICAL 9.8 | Patched | 2026-05-16 |
| VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079)
new
KEV
EPSS 22% CVE-2024-37079
network
Patched | CVE-2024-37079 | network | CRITICAL 9.8 | Patched | 2026-05-16 |
| Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)
new
KEV
EPSS 98% CVE-2025-0108
web
Patched | CVE-2025-0108 | web | CRITICAL 9.1 | Patched | 2026-05-16 |
| OpenSSH regreSSHion Signal-Handler Race Unauthenticated RCE (CVE-2024-6387)
new
EPSS 100% CVE-2024-6387
network
Patched | CVE-2024-6387 | network | HIGH 8.1 | Patched | 2026-05-16 |
| Fortinet FortiOS SSL VPN Unauthenticated RCE (CVE-2024-21762)
new
KEV
RW
EPSS 84% CVE-2024-21762
web
Patched | CVE-2024-21762 | web | CRITICAL 9.6 | Patched | 2026-05-16 |
| Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591)
new
KEV
RW
EPSS 98% CVE-2024-55591 (Fortinet FG-IR-24-535)
web
Unverified | CVE-2024-55591 | web | CRITICAL 9.6 | Unverified | 2026-05-16 |
| cPanel & WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940)
new
KEV
RW
EPSS 99% CVE-2026-41940
web
Patched | CVE-2026-41940 | web | CRITICAL 10 | Patched | 2026-05-16 |
| Citrix NetScaler CitrixBleed 2 Session Token Disclosure (CVE-2025-5777)
new
KEV
RW
EPSS 100% CVE-2025-5777
web
Patched | CVE-2025-5777 | web | CRITICAL 9.3 | Patched | 2026-05-16 |
| Chrome CSSFontFeatureValuesMap Use-After-Free (CVE-2026-2441)
new
KEV
EPSS 22% CVE-2026-2441
web
Unpatched | CVE-2026-2441 | web | HIGH 8.8 | Unpatched | 2026-05-16 |
| Next.js Corrupt Middleware Auth Bypass (CVE-2025-29927)
new
EPSS 99% CVE-2025-29927
web
Patched | CVE-2025-29927 | web | CRITICAL 9.1 | Patched | 2026-05-15 |
| LDAP Nightmare — Windows LDAP Client RCE/DoS (CVE-2024-49113)
new
EPSS 83% CVE-2024-49113
network
Patched | CVE-2024-49113 | network | CRITICAL | Patched | 2026-05-15 |
| HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166)
new
KEV
EPSS 100% CVE-2021-31166
network
Patched | CVE-2021-31166 | network | CRITICAL 9.8 | Patched | 2026-05-15 |
| BlueDucky — Unauthenticated Peering Leading to Code Execution (CVE-2023-45866)
new CVE-2023-45866
network
Patched | CVE-2023-45866 | network | HIGH 8.8 | Patched | 2026-05-15 |
| NGINX Rift — Heap Buffer Overflow RCE (CVE-2026-42945)
new
EPSS 68% CVE-2026-42945
web
Unverified | CVE-2026-42945 | web | CRITICAL 9.8 | Unverified | 2026-05-14 |
| Dirty Frag: Linux XFRM/RxRPC Page Cache Write Chain LPE
new
EPSS 93% CVE-2026-43500, CVE-2026-43284
binary
Patched | CVE-2026-43500, CVE-2026-43284 | binary | CRITICAL 7.8 | Patched | 2026-05-14 |