CVE Tracker

Every vulnerability in the news, ranked by real-world risk.

CVE-2026-48567 10 Critical 13h ago

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

EPSS 0.1% 1 article · 1 incident
CVE-2026-10520 10 Critical 13h ago

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-lev

EPSS 0.2% 4 articles · 2 incidents
CVE-2026-40965 10 Critical 3d ago

Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure.

EPSS 0.1% 1 article
CVE-2026-7312 10 Critical 3d ago

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8

EPSS 0.0% 1 article
CVE-2026-49197 10 Critical 7d ago

Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.

EPSS 0.1% 1 article
CVE-2026-49199 10 Critical 7d ago

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

EPSS 0.2% 1 article
CVE-2026-49200 10 Critical 7d ago

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface.

EPSS 0.1% 1 article
CVE-2026-49201 10 Critical 7d ago

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key.

EPSS 0.0% 1 article
CVE-2026-40933 10 Critical 9d ago

Flowise is a drag & drop user interface to build a customized large language model flow.

EPSS 0.1% 2 articles
CVE-2026-44962 10 Critical 9d ago

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath querie

EPSS 0.0% 1 article
CVE-2026-46840 10 Critical 12d ago

Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0.

EPSS 0.1% 1 article
CVE-2026-48172 10 Critical KEV Ransomware 13d ago

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

LiteSpeed cPanel Plugin EPSS 0.0% 6 articles · 1 incident
CVE-2025-57819 10 Critical KEV Ransomware 14d ago

Sangoma FreePBX Authentication Bypass Vulnerability

Sangoma FreePBX EPSS 77% 1 article
CVE-2025-3450 10 Critical 15d ago

An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated netw

EPSS 0.1% 1 article
CVE-2025-43300 10 Critical KEV Ransomware 16d ago

Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, and macOS EPSS 4.4% 1 article
CVE-2026-20223 10 Critical 20d ago

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources

EPSS 0.1% 2 articles
CVE-2026-45829 10 Critical 22d ago

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary

EPSS 0.2% 1 article
CVE-2026-2743 10 Critical 22d ago

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT).

EPSS 0.2% 1 article
CVE-2026-20182 10 Critical KEV Ransomware 23d ago

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN EPSS 84% 9 articles
CVE-2026-20131 10 Critical KEV Ransomware 23d ago

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerabilit

Cisco Secure Firewall Management Center (FMC) EPSS 1.7% 3 articles · 1 incident
CVE-2026-20127 10 Critical KEV Ransomware 26d ago

Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller and Manager EPSS 55% 4 articles
CVE-2025-32975 10 Critical KEV Ransomware 28d ago

Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

Quest KACE Systems Management Appliance (SMA) EPSS 39% 6 articles
CVE-2025-32433 10 Critical KEV Ransomware 28d ago

Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

Erlang Erlang/OTP EPSS 0.0% 1 article · 1 incident
CVE-2026-42826 10 Critical 28d ago

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

EPSS 0.1% 1 article
CVE-2026-26030 10 Critical 34d ago

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemor

EPSS 0.1% 1 article
CVE-2026-25592 10 Critical 34d ago

Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems.

EPSS 0.1% 1 article
CVE-2025-55182 10 Critical KEV Ransomware 34d ago

Meta React Server Components Remote Code Execution Vulnerability

Meta React Server Components EPSS 85% 6 articles · 1 incident
CVE-2026-24908 10 Critical 41d ago

OpenEMR is a free and open source electronic health records and medical practice management application.

EPSS 0.0% 3 articles
CVE-2024-1709 10 Critical KEV Ransomware 42d ago

ConnectWise ScreenConnect Authentication Bypass Vulnerability

ConnectWise ScreenConnect EPSS 94% 1 article
CVE-2025-10035 10 Critical KEV Ransomware 64d ago

Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

Fortra GoAnywhere MFT EPSS 62% 2 articles
CVE-2025-59528 10 Critical 64d ago

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution.

EPSS 85% 3 articles · 1 incident
CVE-2024-41110 10 Critical 64d ago

Moby is an open-source project created by Docker for software containerization.

EPSS 3.3% 1 article
CVE-2026-10523 9.9 Critical 17h ago

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to c

EPSS 0.3% 2 articles · 2 incidents
CVE-2025-23121 9.9 Critical 1d ago

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

EPSS 1.3% 1 article · 1 incident
CVE-2026-44748 9.9 Critical 1d ago

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modifi

EPSS 0.0% 2 articles · 1 incident
CVE-2025-14771 9.9 Critical 2d ago

Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

EPSS 0.1% 1 article
CVE-2026-47744 9.9 Critical 3d ago

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to ta

EPSS 0.0% 1 article
CVE-2026-41283 9.9 Critical 6d ago

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed.

EPSS 0.3% 1 article
CVE-2026-7374 9.9 Critical 13d ago

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to

EPSS 0.1% 1 article
CVE-2026-42898 9.9 Critical 28d ago

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

EPSS 0.1% 4 articles
CVE-2026-33109 9.9 Critical 28d ago

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

EPSS 0.1% 2 articles
CVE-2026-42823 9.9 Critical 29d ago

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

EPSS 0.1% 1 article
CVE-2024-57726 9.9 Critical KEV Ransomware 46d ago

SimpleHelp Missing Authorization Vulnerability

SimpleHelp SimpleHelp EPSS 39% 5 articles
CVE-2025-20333 9.9 Critical KEV Ransomware 47d ago

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense EPSS 27% 3 articles
CVE-2026-1731 9.9 Critical KEV Ransomware 50d ago

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) EPSS 80% 4 articles
CVE-2026-38526 9.9 Critical 50d ago

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary cod

EPSS 0.0% 1 article
CVE-2026-27681 9.9 Critical 56d ago

Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL st

EPSS 0.1% 2 articles
CVE-2026-20253 9.8 Critical 16m ago
EPSS 0.0% 1 article · 1 incident
CVE-2026-45447 9.8 Critical 1d ago

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.

EPSS 0.1% 2 articles · 1 incident
CVE-2026-35075 9.8 Critical 1d ago

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

EPSS 0.1% 1 article
CVE-2026-47291 9.8 Critical 1d ago

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

EPSS 0.2% 2 articles · 1 incident
CVE-2026-45657 9.8 Critical 1d ago

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

EPSS 0.1% 1 article
CVE-2026-44815 9.8 Critical 1d ago

Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

EPSS 0.1% 1 article
CVE-2026-27671 9.8 Critical 1d ago

Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker ca

EPSS 0.0% 2 articles · 1 incident
CVE-2026-47065 9.8 Critical 2d ago

ZDRES-232: resolveProxyClass Not Overridden acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed.

EPSS 0.1% 1 article · 1 incident
CVE-2026-3300 9.8 Critical 2d ago

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12.

EPSS 0.3% 4 articles · 1 incident
CVE-2026-7198 9.8 Critical 3d ago

CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content th

EPSS 0.3% 1 article
CVE-2026-45247 9.8 Critical KEV 6d ago

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achi

Mirasvit Mirasvit Full Page Cache Warmer EPSS 6.1% 6 articles · 1 incident
CVE-2026-8206 9.8 Critical 7d ago

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions

EPSS 0.2% 2 articles
CVE-2026-7786 9.8 Critical 8d ago

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in

EPSS 0.1% 1 article