CVE Tracker
Every vulnerability in the news, ranked by real-world risk.
Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
ConnectWise ScreenConnect Authentication Bypass Vulnerability
Microsoft SMBv1 Remote Code Execution Vulnerability
TP-Link Archer AX-21 Command Injection Vulnerability
JetBrains TeamCity Authentication Bypass Vulnerability
Microsoft Windows Buffer Overflow Vulnerability
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
JetBrains TeamCity Relative Path Traversal Vulnerability
TP-Link Multiple Routers Command Injection Vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
CrushFTP Authentication Bypass Vulnerability
Microsoft Internet Explorer Use-After-Free Vulnerability
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
Microsoft Internet Explorer Use-After-Free Vulnerability
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution.
Linux Kernel Heap Out-of-Bounds Write Vulnerability
Meta React Server Components Remote Code Execution Vulnerability
ConnectWise ScreenConnect Path Traversal Vulnerability
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Linux Kernel Privilege Escalation Vulnerability
Marimo Remote Code Execution Vulnerability
Linux Kernel Improper Privilege Management Vulnerability
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
Adobe Acrobat Use-After-Free Vulnerability
Sangoma FreePBX Authentication Bypass Vulnerability
Sangoma FreePBX OS Command Injection Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Fortinet FortiClient EMS SQL Injection Vulnerability
CWP Control Web Panel OS Command Injection Vulnerability
PaperCut NG/MF Improper Authentication Vulnerability
BerriAI LiteLLM SQL Injection Vulnerability
Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security rest
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
SimpleHelp Path Traversal Vulnerability
Microsoft Windows Protection Mechanism Failure Vulnerability
Microsoft DirectX NULL Byte Overwrite Vulnerability
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
SimpleHelp Missing Authorization Vulnerability
Fortinet FortiClient EMS Improper Access Control Vulnerability
Langflow Origin Validation Error Vulnerability
Nx Console Embedded Malicious Code Vulnerability
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function.
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from
Aquasecurity Trivy Embedded Malicious Code Vulnerability
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Rout
D-Link DIR-823X Command Injection Vulnerability
Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
TanStack Unspecified Vulnerability
Daemon Tools Lite Embedded Malicious Code Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files.