CVE Tracker

Every vulnerability in the news, ranked by real-world risk.

CVE-2026-6516 10 Critical 2d ago

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

EPSS 0.0% 1 article
CVE-2026-64812 10 Critical 2d ago

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

EPSS 0.0% 1 article
CVE-2026-64813 10 Critical 2d ago

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

EPSS 0.0% 1 article
CVE-2026-15409 10 Critical KEV 4d ago

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.

EPSS 1.3% 11 articles · 2 incidents
CVE-2026-10520 10 Critical KEV 5d ago

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-lev

EPSS 100% 13 articles · 1 incident
CVE-2026-56451 10 Critical 5d ago

A vulnerability has been identified in Opcenter X (All versions < V2604).

EPSS 0.4% 1 article
CVE-2026-56291 10 Critical KEV 12d ago

Joomla Extension balbooa.com Unauthenticated file upload in Balbooa Forms extension < 2.4.1 The Joomla extension Balbooa Forms is vulnerable to an unauthenticat

EPSS 76% 6 articles · 2 incidents
CVE-2026-48939 10 Critical KEV 12d ago

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code uploa

EPSS 24% 6 articles · 2 incidents
CVE-2026-48282 10 Critical KEV 13d ago

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

EPSS 29% 17 articles · 4 incidents
CVE-2026-13768 10 Critical 15d ago

Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns c

EPSS 0.6% 2 articles · 1 incident
CVE-2026-48908 10 Critical KEV 17d ago

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP co

EPSS 1.6% 10 articles · 3 incidents
CVE-2026-56290 10 Critical KEV 17d ago

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

EPSS 2.9% 10 articles · 3 incidents
CVE-2026-50746 10 Critical 17d ago

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Inje

EPSS 0.9% 3 articles · 1 incident
CVE-2026-48558 10 Critical KEV 20d ago

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow.

EPSS 1.2% 11 articles · 2 incidents
CVE-2026-10134 10 Critical 20d ago

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, messag

EPSS 0.3% 2 articles · 2 incidents
CVE-2026-48276 10 Critical 23d ago

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary

EPSS 0.9% 2 articles · 2 incidents
CVE-2026-48283 10 Critical 23d ago

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary

EPSS 1.6% 2 articles · 2 incidents
CVE-2026-48277 10 Critical 23d ago

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the

EPSS 1.8% 1 article · 1 incident
CVE-2026-48281 10 Critical 23d ago

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the

EPSS 1.8% 1 article · 1 incident
CVE-2026-50242 10 Critical 24d ago

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access

EPSS 0.6% 1 article
CVE-2026-48286 10 Critical 24d ago

Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code

EPSS 0.9% 1 article · 1 incident
CVE-2026-12537 10 Critical 27d ago

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versio

EPSS 0.1% 1 article
CVE-2026-52813 10 Critical 30d ago

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and reposito

EPSS 1.1% 1 article
CVE-2026-46752 10 Critical 30d ago

Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0.

EPSS 0.4% 1 article
CVE-2026-10561 10 Critical 31d ago

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an

EPSS 0.9% 1 article
CVE-2026-34910 10 Critical KEV 31d ago

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

EPSS 79% 9 articles · 2 incidents
CVE-2026-34909 10 Critical KEV 31d ago

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system tha

EPSS 2.3% 8 articles · 2 incidents
CVE-2026-34908 10 Critical KEV 31d ago

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to th

EPSS 58% 9 articles · 2 incidents
CVE-2026-49261 10 Critical 33d ago

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through

EPSS 1.0% 2 articles · 1 incident
CVE-2026-48907 10 Critical KEV 38d ago

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code up

EPSS 80% 6 articles · 1 incident
CVE-2026-48567 10 Critical 45d ago

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

EPSS 1.0% 1 article · 1 incident
CVE-2026-40965 10 Critical 48d ago

Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure.

EPSS 0.3% 1 article
CVE-2026-7312 10 Critical 48d ago

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8

EPSS 0.4% 1 article
CVE-2026-49197 10 Critical 52d ago

Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.

EPSS 0.3% 1 article
CVE-2026-49199 10 Critical 52d ago

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

EPSS 1.3% 1 article
CVE-2026-49200 10 Critical 52d ago

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface.

EPSS 0.5% 1 article
CVE-2026-49201 10 Critical 52d ago

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key.

EPSS 0.3% 1 article
CVE-2026-40933 10 Critical 54d ago

Flowise is a drag & drop user interface to build a customized large language model flow.

EPSS 13% 2 articles
CVE-2026-44962 10 Critical 55d ago

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath querie

EPSS 0.7% 1 article
CVE-2026-46840 10 Critical 58d ago

Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0.

EPSS 0.7% 1 article
CVE-2026-48172 10 Critical KEV Ransomware 58d ago

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

LiteSpeed cPanel Plugin EPSS 19% 6 articles · 1 incident
CVE-2025-57819 10 Critical KEV Ransomware 59d ago

Sangoma FreePBX Authentication Bypass Vulnerability

Sangoma FreePBX EPSS 93% 1 article
CVE-2025-3450 10 Critical 60d ago

An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated netw

EPSS 0.3% 1 article
CVE-2025-43300 10 Critical KEV Ransomware 61d ago

Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, and macOS EPSS 20% 1 article
CVE-2026-20223 10 Critical 65d ago

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources

EPSS 0.8% 2 articles
CVE-2026-45829 10 Critical 67d ago

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary

EPSS 12% 1 article
CVE-2026-2743 10 Critical 67d ago

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT).

EPSS 0.8% 1 article
CVE-2026-20182 10 Critical KEV Ransomware 68d ago

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN EPSS 90% 9 articles
CVE-2026-20131 10 Critical KEV Ransomware 68d ago

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerabilit

Cisco Secure Firewall Management Center (FMC) EPSS 28% 3 articles · 1 incident
CVE-2026-20127 10 Critical KEV Ransomware 72d ago

Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller and Manager EPSS 88% 4 articles
CVE-2025-32975 10 Critical KEV Ransomware 73d ago

Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

Quest KACE Systems Management Appliance (SMA) EPSS 2.4% 6 articles
CVE-2025-32433 10 Critical KEV Ransomware 73d ago

Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

Erlang Erlang/OTP EPSS 99% 1 article · 1 incident
CVE-2026-42826 10 Critical 73d ago

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

EPSS 0.8% 1 article
CVE-2026-26030 10 Critical 79d ago

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemor

EPSS 2.9% 1 article
CVE-2026-25592 10 Critical 79d ago

Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems.

EPSS 2.4% 1 article
CVE-2025-55182 10 Critical KEV Ransomware 79d ago

Meta React Server Components Remote Code Execution Vulnerability

Meta React Server Components EPSS 100% 6 articles · 1 incident
CVE-2026-24908 10 Critical 86d ago

OpenEMR is a free and open source electronic health records and medical practice management application.

EPSS 0.5% 3 articles
CVE-2024-1709 10 Critical KEV Ransomware 88d ago

ConnectWise ScreenConnect Authentication Bypass Vulnerability

ConnectWise ScreenConnect EPSS 100% 1 article
CVE-2025-10035 10 Critical KEV Ransomware 109d ago

Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

Fortra GoAnywhere MFT EPSS 100% 2 articles
CVE-2025-59528 10 Critical 109d ago

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution.

EPSS 90% 3 articles · 1 incident