CVE Tracker

Vulnerabilities in the news. Explore recent activity, known exploitation, severity, and EPSS.

CVE-2026-85706 Unrated KEV 4h ago

GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

GitLab Community Edition and Enterprise Edition EPSS unavailable 4 articles
CVE-2026-42018 7.5 High KEV 4h ago

JFrog Artifactory Improper Authentication Vulnerability

jfrog artifactory EPSS 0.3% 3 articles
CVE-2026-42016 8.1 High KEV 4h ago

JFrog Artifactory Incorrect Authorization Vulnerability

jfrog artifactory EPSS 0.3% 3 articles
CVE-2026-84869 9.9 Critical KEV 4h ago

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect EPSS 0.4% 1 article
CVE-2026-40933 10 Critical 7h ago

Flowise is a drag & drop user interface to build a customized large language model flow.

FlowiseAI Flowise EPSS 13% 3 articles
CVE-2026-87719 Unrated 7h ago
EPSS unavailable 3 articles
CVE-2026-80352 9.8 Critical 10h ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.

Apache Software Foundation Apache Camel K EPSS 0.3% 1 article
CVE-2026-80351 9.8 Critical 10h ago

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K.

Apache Software Foundation Apache Camel K EPSS 0.4% 1 article
CVE-2026-80354 8.1 High 10h ago

Authorization bypass through User-Controlled key vulnerability in Apache Camel K.

Apache Software Foundation Apache Camel K EPSS 0.2% 1 article
CVE-2026-89094 9.9 Critical 10h ago

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

Forgejo Forgejo EPSS 0.5% 1 article
CVE-2026-89049 9.9 Critical 10h ago

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Ama

AWS Amazon SSM Agent EPSS 0.4% 1 article
CVE-2026-14894 9.8 Critical 10h ago

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the sub

WebRehab Super Forms – Drag & Drop Form Builder EPSS 5.3% 3 articles
CVE-2026-85102 9.8 Critical 13h ago

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arb

checkpoint Quantum Security Gateway EPSS 0.3% 3 articles
CVE-2026-85103 9.8 Critical 13h ago

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Sec

checkpoint Quantum Security Gateway EPSS 0.4% 3 articles
CVE-2026-20316 5.3 Medium KEV 14h ago

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

Cisco Secure Firewall Management Center (FMC) EPSS 11% 8 articles
CVE-2026-20079 10 Critical KEV 14h ago

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

Cisco Cisco Secure Firewall Management Center (FMC) EPSS 75% 12 articles
CVE-2026-81467 9.8 Critical 15h ago

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerab

Dell ThinOS 10 EPSS unavailable 1 article
CVE-2026-81048 9.6 Critical 15h ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability.

Dell ThinOS 10 EPSS unavailable 1 article
CVE-2026-81046 9.4 Critical 15h ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability.

Dell ThinOS 10 EPSS unavailable 1 article
CVE-2026-81468 9.1 Critical 15h ago

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerab

Dell ThinOS 10 EPSS unavailable 1 article
CVE-2026-81052 6.8 Medium 15h ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability.

Dell ThinOS 10 EPSS unavailable 1 article
CVE-2026-81051 6.6 Medium 15h ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability.

Dell ThinOS 10 EPSS unavailable 1 article
CVE-2026-88062 9.5 Critical 15h ago

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers.

diegosouzapw OmniRoute EPSS unavailable 1 article
CVE-2026-56711 8.8 High 15h ago

VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result.

VideoLAN VLC media player EPSS 0.3% 1 article
CVE-2026-73324 6.9 Medium 15h ago

VLC media player copies an RTSP response line into a fixed buffer without guaranteeing termination and then treats that buffer as a C string.

VideoLAN VLC media player EPSS 0.3% 1 article
CVE-2026-81578 8.8 High KEV 16h ago

PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

PaperCut NG/MF EPSS 1.6% 21 articles
CVE-2026-82078 9.4 Critical KEV 16h ago

PaperCut NG/MF Unsafe Reflection Vulnerability

PaperCut NG/MF EPSS 1.7% 20 articles
CVE-2026-82329 9.8 Critical KEV 17h ago

JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory EPSS 7.7% 7 articles
CVE-2026-15409 10 Critical KEV Ransomware 17h ago

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances EPSS 84% 17 articles
CVE-2021-38003 8.8 High KEV 17h ago

Google Chromium V8 Memory Corruption Vulnerability

Google Chromium V8 EPSS 39% 1 article
CVE-2026-63695 Unrated 21h ago
EPSS unavailable 1 article
CVE-2026-63696 Unrated 21h ago
EPSS unavailable 1 article
CVE-2026-61418 Unrated 21h ago
EPSS unavailable 1 article
CVE-2026-61417 Unrated 21h ago
EPSS unavailable 1 article
CVE-2026-65638 9.2 Critical 21h ago

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF servic

WebPros ConfigServer Security & Firewall EPSS unavailable 1 article
CVE-2026-65639 9.5 Critical 21h ago

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execu

WebPros ConfigServer Security & Firewall EPSS unavailable 1 article
CVE-2026-16338 Unrated 21h ago
EPSS unavailable 1 article
CVE-2026-82107 9.6 Critical 21h ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to

IBM DataStage on Cloud Pak for Data EPSS unavailable 1 article
CVE-2026-82100 9.6 Critical 21h ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data EPSS unavailable 1 article
CVE-2026-81551 8.8 High 21h ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path

IBM DataStage on Cloud Pak for Data EPSS unavailable 1 article
CVE-2026-88285 9.4 Critical 21h ago

GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issu

GeoVision Inc. GV-LPC2011/LPC2211 EPSS 0.3% 1 article
CVE-2026-70416 Unrated 21h ago
EPSS unavailable 1 article
CVE-2025-43936 Unrated 21h ago
EPSS unavailable 1 article
CVE-2026-26947 Unrated 21h ago
EPSS unavailable 1 article
CVE-2025-36591 Unrated 21h ago
EPSS unavailable 1 article
CVE-2026-76104 Unrated 21h ago
EPSS unavailable 1 article
CVE-2026-88765 Unrated 23h ago
EPSS unavailable 1 article
CVE-2026-28576 10 Critical 23h ago

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection.

Android Android EPSS 0.1% 1 article
CVE-2026-67277 8.8 High KEV 1d ago

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

Mikrotik RouterOS EPSS 0.4% 3 articles
CVE-2026-86060 9.2 Critical KEV 1d ago

MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

Mikrotik RouterOS EPSS 0.4% 5 articles
CVE-2026-19490 9.3 Critical KEV 1d ago

Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

NetScaler ADC EPSS 6.0% 7 articles
CVE-2026-87491 Unrated KEV 1d ago

Google Chromium V8 Out of Bounds Write Vulnerability

Google Chrome EPSS 0.8% 8 articles
CVE-2025-25249 7.4 High KEV 1d ago

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

Fortinet Multiple Products EPSS 1.7% 4 articles
CVE-2026-28662 Unrated 1d ago

In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow.

Google Android EPSS 0.1% 2 articles
CVE-2026-85046 8.8 High KEV 1d ago

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 EPSS 1.3% 24 articles
CVE-2026-85880 7.8 High KEV 1d ago

Microsoft Windows Heap-Based Buffer Overflow Vulnerability

Microsoft Windows EPSS 0.6% 19 articles
CVE-2026-69414 7.8 High 1d ago

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".

Microsoft Microsoft Malware Protection Engine EPSS 0.6% 7 articles
CVE-2026-42271 8.7 High KEV 1d ago

BerriAI LiteLLM Command Injection Vulnerability

BerriAI LiteLLM EPSS 84% 24 articles
CVE-2026-59822 8.8 High KEV 1d ago

BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI LiteLLM EPSS 0.9% 1 article
CVE-2026-59821 2.1 Low 1d ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format.

BerriAI litellm EPSS 0.7% 1 article