CVE Tracker

Every vulnerability in the news, ranked by real-world risk.

CVE-2025-66376 7.2 High KEV 20h ago

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML

EPSS 12% 5 articles · 1 incident
CVE-2026-8085 7 High 22h ago

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component.

EPSS 0.2% 1 article
CVE-2026-8312 7 High 22h ago

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component.

EPSS 0.2% 1 article
CVE-2026-8313 7 High 22h ago

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component.

EPSS 0.2% 1 article
CVE-2026-8314 7 High 22h ago

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component.

EPSS 0.2% 1 article
CVE-2026-16723 9 Critical 1d ago

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83.

EPSS 0.4% 1 article
CVE-2025-29827 9.9 Critical 1d ago

Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

EPSS 1.2% 1 article
CVE-2026-16242 9.4 Critical 1d ago

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes.

EPSS 0.4% 1 article
CVE-2026-61884 Critical 1d ago

The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credentials during the login process.

EPSS 0.0% 1 article
CVE-2026-55985 Unrated 1d ago
EPSS 0.0% 1 article
CVE-2026-50454 7.8 High 1d ago

Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

EPSS 0.4% 1 article
CVE-2026-12569 9.3 Critical KEV 1d ago

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM.

EPSS 2.3% 8 articles · 1 incident
CVE-2026-6516 10 Critical 2d ago

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

EPSS 0.0% 1 article
CVE-2026-16232 9.1 Critical KEV 2d ago

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login to

EPSS 0.0% 9 articles · 1 incident
CVE-2026-16807 Unrated 2d ago

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

EPSS 0.0% 1 article
CVE-2026-16806 Unrated 2d ago

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

EPSS 0.0% 1 article
CVE-2026-16805 Unrated 2d ago

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

EPSS 0.0% 1 article
CVE-2026-16804 Unrated 2d ago

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a san

EPSS 0.0% 1 article
CVE-2026-50522 9.8 Critical KEV 2d ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

EPSS 20% 6 articles · 1 incident
CVE-2026-14890 9.1 Critical 2d ago

SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deseri

EPSS 0.7% 1 article
CVE-2026-64645 Unrated 2d ago
EPSS 0.0% 1 article
CVE-2026-64649 Unrated 2d ago
EPSS 0.0% 1 article
CVE-2026-64642 Unrated 2d ago
EPSS 0.0% 1 article
CVE-2026-57239 8.2 High 2d ago

The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate th

EPSS 0.1% 1 article
CVE-2026-57308 9.8 Critical 2d ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope.

EPSS 0.4% 1 article
CVE-2026-62183 9.8 Critical 2d ago

Improper Privilege Management vulnerability in Apache Syncope. When: the all-Java user workflow adapter is configured, or the Flowable user workflow adapter is

EPSS 0.3% 1 article
CVE-2026-64812 10 Critical 2d ago

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

EPSS 0.0% 1 article
CVE-2026-64813 10 Critical 2d ago

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

EPSS 0.0% 1 article
CVE-2026-62144 9.1 Critical 2d ago

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to exec

EPSS 0.0% 2 articles · 1 incident
CVE-2026-62145 7.5 High 2d ago

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

EPSS 0.0% 2 articles · 1 incident
CVE-2026-48294 7.4 High 2d ago

Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability.

EPSS 0.7% 3 articles · 1 incident
CVE-2026-13321 8.6 High 3d ago

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone.

EPSS 0.0% 1 article · 1 incident
CVE-2026-65048 9.3 Critical 3d ago

Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset

EPSS 0.3% 1 article
CVE-2026-65049 9.3 Critical 3d ago

Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to tri

EPSS 0.2% 1 article
CVE-2026-65050 7.1 High 3d ago

Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-tabl

EPSS 0.3% 1 article
CVE-2026-65052 8.7 High 3d ago

Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitr

EPSS 0.3% 1 article
CVE-2026-8933 7.8 High 3d ago

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure

EPSS 0.0% 3 articles · 1 incident
CVE-2024-36401 9.8 Critical KEV 3d ago

GeoServer is an open source server that allows users to share and edit geospatial data.

EPSS 100% 1 article
CVE-2026-64600 Unrated 3d ago

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc}

EPSS 0.0% 1 article · 1 incident
CVE-2026-45659 8.8 High KEV Ransomware 3d ago

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server EPSS 9.1% 12 articles · 3 incidents
CVE-2026-56164 5.3 Medium KEV 3d ago

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

EPSS 5.6% 11 articles · 2 incidents
CVE-2026-58644 9.8 Critical KEV 3d ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

EPSS 1.5% 11 articles · 3 incidents
CVE-2021-27137 8.1 High KEV 3d ago

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker

EPSS 16% 3 articles · 1 incident
CVE-2026-63030 9.8 Critical KEV 3d ago

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Qu

EPSS 98% 11 articles · 1 incident
CVE-2026-60137 9.1 Critical KEV 3d ago

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow

EPSS 78% 9 articles · 1 incident
CVE-2026-0770 9.8 Critical KEV 3d ago

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability.

EPSS 10% 3 articles · 1 incident
CVE-2026-60206 9.9 Critical 3d ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).

EPSS 0.0% 1 article · 1 incident
CVE-2025-3248 9.8 Critical KEV 3d ago

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.

EPSS 100% 4 articles · 1 incident
CVE-2026-28307 9.1 Critical 4d ago

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group.

EPSS 0.0% 1 article
CVE-2026-28308 9.1 Critical 4d ago

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution.

EPSS 0.0% 1 article
CVE-2026-28321 9.1 Critical 4d ago

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privil

EPSS 0.0% 1 article
CVE-2026-0257 7.8 High KEV 4d ago

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security rest

Palo Alto Networks PAN-OS EPSS 87% 18 articles · 1 incident
CVE-2026-57821 8.1 High 4d ago

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0.

EPSS 0.8% 1 article
CVE-2026-56287 8.1 High 4d ago

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0.

EPSS 0.7% 1 article
CVE-2026-35152 8.8 High 4d ago

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0.

EPSS 3.5% 1 article
CVE-2026-42980 7.8 High 4d ago

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

EPSS 5.7% 1 article
CVE-2026-13385 9.5 Critical 4d ago

An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user t

EPSS 0.1% 1 article
CVE-2026-6875 9.5 Critical 4d ago

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform.

EPSS 0.5% 5 articles · 1 incident
CVE-2026-53359 8.8 High 4d ago

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM

EPSS 0.1% 5 articles · 1 incident
CVE-2026-15409 10 Critical KEV 4d ago

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.

EPSS 1.3% 11 articles · 2 incidents