CVE Tracker

Vulnerabilities in the news. Explore recent activity, known exploitation, severity, and EPSS.

CVE-2026-40933 10 Critical 8h ago

Flowise is a drag & drop user interface to build a customized large language model flow.

FlowiseAI Flowise EPSS 13% 3 articles
CVE-2026-20079 10 Critical KEV 15h ago

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

Cisco Cisco Secure Firewall Management Center (FMC) EPSS 75% 12 articles
CVE-2026-15409 10 Critical KEV Ransomware 18h ago

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances EPSS 84% 17 articles
CVE-2026-28576 10 Critical 1d ago

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection.

Android Android EPSS 0.1% 1 article
CVE-2026-86218 10 Critical KEV 1d ago

N-able N-central Static Code Injection Vulnerability

N-able N-central EPSS 0.7% 8 articles
CVE-2026-75650 10 Critical KEV 1d ago

Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Adobe Adobe Commerce EPSS 2.1% 6 articles
CVE-2026-44756 10 Critical 2d ago

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library.

SAP_SE SAP Extended Passport (EPP) Processing EPSS 0.3% 4 articles
CVE-2026-85061 10 Critical 2d ago

MapLibre GL JS is an interactive vector tile map library for web browsers.

maplibre maplibre-gl-js EPSS 0.3% 1 article
CVE-2026-72898 10 Critical KEV 3d ago

Metabase SQL Injection Vulnerability

Metabase Metabase EPSS 94% 7 articles
CVE-2026-83548 10 Critical KEV 3d ago

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances EPSS 4.7% 9 articles
CVE-2024-3400 10 Critical KEV Ransomware 4d ago

Palo Alto Networks PAN-OS Command Injection Vulnerability

Palo Alto Networks PAN-OS EPSS 100% 1 article
CVE-2026-75754 10 Critical 7d ago

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized

ASUS Control Center Enterprise (ACC) EPSS 0.2% 1 article
CVE-2026-76657 10 Critical 10d ago

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent

Hewlett Packard Enterprise (HPE) Fabric Composer EPSS 0.4% 1 article
CVE-2026-76658 10 Critical 10d ago

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrati

Hewlett Packard Enterprise (HPE) Fabric Composer EPSS 0.4% 1 article
CVE-2026-18885 10 Critical 11d ago

ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform.

ServiceNow ServiceNow AI Platform EPSS 0.4% 1 article
CVE-2026-18886 10 Critical 11d ago

ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform.

ServiceNow ServiceNow AI Platform EPSS 0.2% 1 article
CVE-2026-74820 10 Critical 11d ago

ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform.

ServiceNow ServiceNow AI Platform EPSS 0.2% 1 article
CVE-2026-82222 10 Critical 11d ago

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.

Liquid Web / StellarWP GiveWP EPSS 1.5% 1 article
CVE-2026-21962 10 Critical KEV 11d ago

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in EPSS 42% 10 articles
CVE-2026-77537 10 Critical 16d ago

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command In

Ubiquiti Inc UniFi Protect Application EPSS 0.9% 1 article
CVE-2026-77550 10 Critical 16d ago

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS

Ubiquiti Inc UniFi OS Server EPSS 0.5% 1 article
CVE-2026-77554 10 Critical 16d ago

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injec

Ubiquiti Inc UniFi Talk Application EPSS 1.0% 1 article
CVE-2026-69836 10 Critical KEV 21d ago

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Microsoft Microsoft Entra EPSS 1.6% 3 articles
CVE-2026-69502 10 Critical 21d ago

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Microsoft Azure SQL Database EPSS 0.6% 1 article
CVE-2026-20030 10 Critical 22d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal sec

Cisco Cisco Crosswork Planning EPSS 0.5% 1 article
CVE-2026-20315 10 Critical 22d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive intern

Cisco Cisco Secure Workload EPSS 0.4% 1 article
CVE-2026-20317 10 Critical 22d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive intern

Cisco Cisco Secure Workload EPSS 0.4% 1 article
CVE-2026-18051 10 Critical 23d ago

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attack

EPSS 0.4% 1 article
CVE-2026-19188 10 Critical 25d ago

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product.

Haiwell Haiwell IoT Cloud HMI Gateway EPSS 1.9% 1 article
CVE-2026-58231 10 Critical 25d ago

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking s

SAP_SE SAP Commerce Cloud (Data Hub Adapter) EPSS 1.7% 5 articles
CVE-2026-58115 10 Critical 30d ago

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed).

Siemens SIMATIC IoT2050 Advanced EPSS 0.7% 1 article
CVE-2026-5430 10 Critical 35d ago

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported.

WSO2 WSO2 Universal Gateway EPSS 0.2% 2 articles
CVE-2026-63508 10 Critical 35d ago

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

Microsoft Microsoft Planetary Computer Pro (GeoCatalog) EPSS 0.5% 1 article
CVE-2026-56162 10 Critical 35d ago

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Microsoft Azure SQL Database EPSS 0.7% 1 article
CVE-2026-65667 10 Critical 35d ago

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

Microsoft Microsoft Teams EPSS 0.6% 1 article
CVE-2026-41679 10 Critical 36d ago

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business.

paperclipai paperclip EPSS 19% 1 article
CVE-2026-16498 10 Critical 38d ago

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may al

HashiCorp Tooling EPSS 0.5% 1 article
CVE-2026-48331 10 Critical 38d ago

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation.

Adobe Adobe Campaign Classic EPSS 0.5% 1 article
CVE-2026-48323 10 Critical 38d ago

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrar

Adobe Adobe Campaign Classic EPSS 0.7% 1 article
CVE-2026-48330 10 Critical 38d ago

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could res

Adobe Adobe Campaign Classic EPSS 0.7% 1 article
CVE-2026-16812 10 Critical KEV 39d ago

Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Arista VeloCloud Orchestrator EPSS 1.6% 7 articles
CVE-2026-48449 10 Critical 41d ago

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current

Adobe Adobe Campaign Classic EPSS 1.0% 1 article
CVE-2026-21858 10 Critical 43d ago

n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server

n8n-io n8n EPSS 78% 3 articles
CVE-2025-68613 10 Critical KEV 43d ago

n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

n8n n8n EPSS 99% 7 articles
CVE-2026-59726 10 Critical 43d ago

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /

ruvnet ruflo EPSS 6.9% 2 articles
CVE-2026-42933 10 Critical 45d ago

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, whic

Pronetiqs Panduit Intravue EPSS 0.5% 1 article
CVE-2026-6516 10 Critical 49d ago

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

Zohocorp ManageEngine ADAudit Plus EPSS 4.9% 1 article
CVE-2026-64812 10 Critical 50d ago

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

JetBrains IntelliJ IDEA EPSS 0.5% 1 article
CVE-2026-64813 10 Critical 50d ago

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

JetBrains IntelliJ IDEA EPSS 0.5% 1 article
CVE-2026-10520 10 Critical KEV 53d ago

Ivanti Sentry OS Command Injection Vulnerability

Ivanti Sentry EPSS 100% 13 articles
CVE-2026-56451 10 Critical 53d ago

A vulnerability has been identified in Opcenter X (All versions < V2604).

Siemens Opcenter X EPSS 0.5% 1 article
CVE-2026-56291 10 Critical KEV 60d ago

Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

Balbooa Forms EPSS 15% 6 articles
CVE-2026-48939 10 Critical KEV 60d ago

iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

iCagenda iCagenda EPSS 20% 6 articles
CVE-2026-48282 10 Critical KEV 60d ago

Adobe ColdFusion Path Traversal Vulnerability

Adobe ColdFusion EPSS 42% 17 articles
CVE-2026-13768 10 Critical 63d ago

Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns c

Gardyn Gardyn Home Firmware EPSS 0.7% 2 articles
CVE-2026-48908 10 Critical KEV 64d ago

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder EPSS 15% 10 articles
CVE-2026-56290 10 Critical KEV 64d ago

Joomlack Page Builder Improper Access Control Vulnerability

Joomlack Page Builder EPSS 30% 10 articles
CVE-2026-50746 10 Critical 65d ago

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Inje

Ubiquiti Inc UniFi Connect Application EPSS 1.7% 3 articles
CVE-2026-48558 10 Critical KEV 67d ago

SimpleHelp Authentication Bypass Vulnerability

SimpleHelp SimpleHelp EPSS 30% 11 articles
CVE-2026-10134 10 Critical 67d ago

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, messag

IBM Langflow OSS EPSS 0.6% 2 articles