CVE Tracker

Every vulnerability in the news, ranked by real-world risk.

CVE-2026-50751 9.3 Critical KEV 1h ago
Check Point Security Gateway EPSS 0.0% 37 articles · 2 incidents
CVE-2026-24180 7.3 High 1h ago
EPSS 0.0% 1 article
CVE-2026-24181 7.3 High 1h ago
EPSS 0.0% 1 article
CVE-2026-45034 Unrated 1h ago
EPSS 0.0% 1 article
CVE-2026-41729 8.1 High 1h ago
EPSS 0.0% 1 article
CVE-2026-41717 8.1 High 1h ago
EPSS 0.0% 1 article
CVE-2026-41716 7.5 High 1h ago
EPSS 0.0% 1 article
CVE-2026-10795 Unrated 2h ago
EPSS 0.0% 1 article
CVE-2026-5027 8.8 High 11h ago

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary loca

EPSS 0.0% 1 article
CVE-2026-49160 7.5 High 12h ago

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

EPSS 1.2% 7 articles · 1 incident
CVE-2026-48567 10 Critical 12h ago

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

EPSS 0.1% 1 article · 1 incident
CVE-2026-10520 10 Critical 12h ago

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-lev

EPSS 0.2% 4 articles · 2 incidents
CVE-2025-8088 8.4 High KEV 12h ago

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files.

RARLAB WinRAR EPSS 12% 4 articles · 1 incident
CVE-2026-50507 6.8 Medium 14h ago

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

EPSS 0.1% 4 articles · 1 incident
CVE-2026-45586 7.8 High 14h ago

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privilege

EPSS 0.1% 5 articles · 1 incident
CVE-2026-10523 9.9 Critical 16h ago

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to c

EPSS 0.3% 2 articles · 2 incidents
CVE-2026-20245 7.8 High KEV 16h ago

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Cataly

Cisco Catalyst SD-WAN Manager EPSS 0.3% 10 articles · 2 incidents
CVE-2026-11645 8.8 High KEV 16h ago

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H

Google Chromium V8 EPSS 5.5% 13 articles · 2 incidents
CVE-2026-7473 6.9 Medium KEV 16h ago

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Rout

Arista Extensible Operating System EPSS 22% 8 articles · 2 incidents
CVE-2026-25089 9.1 Critical 18h ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSa

EPSS 2.0% 2 articles · 1 incident
CVE-2026-45447 9.8 Critical 1d ago

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.

EPSS 0.1% 2 articles · 1 incident
CVE-2026-34183 Unrated 1d ago

Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames.

EPSS 0.0% 1 article · 1 incident
CVE-2026-35075 9.8 Critical 1d ago

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

EPSS 0.1% 1 article
CVE-2026-35083 8.8 High 1d ago

A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.

EPSS 0.1% 1 article
CVE-2026-35084 8.8 High 1d ago

A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.

EPSS 0.1% 1 article
CVE-2026-35085 8.8 High 1d ago

A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.

EPSS 0.1% 1 article
CVE-2026-47761 8.7 High 1d ago

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin.

EPSS 0.0% 1 article
CVE-2026-47760 8.7 High 1d ago

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in

EPSS 0.0% 1 article
CVE-2026-47759 8.7 High 1d ago

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-m

EPSS 0.0% 1 article
CVE-2026-47762 8.7 High 1d ago

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments.

EPSS 0.0% 1 article
CVE-2026-49980 Unrated 1d ago
EPSS 0.0% 1 article · 1 incident
CVE-2026-44963 9.4 Critical 1d ago

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

EPSS 0.6% 2 articles · 2 incidents
CVE-2026-41091 7.8 High KEV Ransomware 1d ago

Microsoft Defender Link Following Vulnerability

Microsoft Defender EPSS 8.2% 7 articles
CVE-2026-47291 9.8 Critical 1d ago

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

EPSS 0.2% 2 articles · 1 incident
CVE-2026-45657 9.8 Critical 1d ago

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

EPSS 0.1% 1 article
CVE-2026-44815 9.8 Critical 1d ago

Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

EPSS 0.1% 1 article
CVE-2025-23121 9.9 Critical 1d ago

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

EPSS 1.3% 1 article · 1 incident
CVE-2026-48710 6.5 Medium 1d ago

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `re

EPSS 0.4% 1 article
CVE-2026-42271 8.7 High KEV 1d ago
BerriAI LiteLLM EPSS 0.0% 22 articles · 2 incidents
CVE-2026-23111 7.8 High 1d ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catc

EPSS 0.0% 2 articles · 1 incident
CVE-2026-41720 7.4 High 1d ago

Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired with an empty or null password.

EPSS 0.0% 1 article
CVE-2026-41840 5.9 Medium 1d ago

Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests.

EPSS 0.0% 1 article
CVE-2026-41842 7.5 High 1d ago

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.

EPSS 0.0% 1 article
CVE-2026-44748 9.9 Critical 1d ago

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modifi

EPSS 0.0% 2 articles · 1 incident
CVE-2026-27671 9.8 Critical 1d ago

Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker ca

EPSS 0.0% 2 articles · 1 incident
CVE-2026-40128 9 Critical 1d ago

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion

EPSS 0.1% 2 articles · 1 incident
CVE-2026-22732 9.1 Critical 1d ago

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be writt

EPSS 0.0% 1 article · 1 incident
CVE-2026-50752 7.4 High 1d ago

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to b

EPSS 0.0% 4 articles · 1 incident
CVE-2026-47065 9.8 Critical 2d ago

ZDRES-232: resolveProxyClass Not Overridden acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed.

EPSS 0.1% 1 article · 1 incident
CVE-2026-47321 Unrated 2d ago
EPSS 0.0% 1 article · 1 incident
CVE-2026-44182 Unrated 2d ago
EPSS 0.0% 1 article
CVE-2026-44181 Unrated 2d ago
EPSS 0.0% 1 article
CVE-2026-44180 Unrated 2d ago
EPSS 0.0% 1 article
CVE-2025-14771 9.9 Critical 2d ago

Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

EPSS 0.1% 1 article
CVE-2025-14772 8.8 High 2d ago

Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

EPSS 0.0% 1 article
CVE-2025-14774 7.4 High 2d ago

Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

EPSS 0.0% 1 article
CVE-2026-34355 7.5 High 2d ago

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.

EPSS 0.2% 1 article · 1 incident
CVE-2026-34356 7.5 High 2d ago

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server:

EPSS 0.2% 1 article · 1 incident
CVE-2026-8913 8.5 High 2d ago

A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within

EPSS 0.4% 1 article · 1 incident
CVE-2026-8037 9.6 Critical 2d ago

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on th

EPSS 0.4% 1 article · 1 incident