CVE Tracker

Every vulnerability in the news, ranked by real-world risk.

CVE-2023-1389 8.8 High KEV Ransomware 86d ago

TP-Link Archer AX-21 Command Injection Vulnerability

TP-Link Archer AX21 EPSS 100% 2 articles · 1 incident
CVE-2025-3248 9.8 Critical KEV 3d ago

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.

EPSS 100% 4 articles · 1 incident
CVE-2024-27199 7.3 High KEV Ransomware 95d ago

JetBrains TeamCity Relative Path Traversal Vulnerability

JetBrains TeamCity EPSS 100% 5 articles
CVE-2024-4577 9.8 Critical KEV Ransomware 87d ago

PHP-CGI OS Command Injection Vulnerability

PHP Group PHP EPSS 100% 1 article
CVE-2023-46805 8.2 High KEV Ransomware 110d ago

Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

Ivanti Connect Secure and Policy Secure EPSS 100% 1 article
CVE-2024-1709 10 Critical KEV Ransomware 87d ago

ConnectWise ScreenConnect Authentication Bypass Vulnerability

ConnectWise ScreenConnect EPSS 100% 1 article
CVE-2025-31161 9.8 Critical KEV Ransomware 109d ago

CrushFTP Authentication Bypass Vulnerability

CrushFTP CrushFTP EPSS 100% 1 article
CVE-2024-27198 9.8 Critical KEV Ransomware 109d ago

JetBrains TeamCity Authentication Bypass Vulnerability

JetBrains TeamCity EPSS 100% 1 article
CVE-2026-10520 10 Critical KEV 5d ago

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-lev

EPSS 100% 13 articles · 1 incident
CVE-2025-5777 9.3 Critical KEV Ransomware 96d ago

Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

Citrix NetScaler ADC and Gateway EPSS 100% 1 article
CVE-2024-36401 9.8 Critical KEV 3d ago

GeoServer is an open source server that allows users to share and edit geospatial data.

EPSS 100% 1 article
CVE-2025-10035 10 Critical KEV Ransomware 109d ago

Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

Fortra GoAnywhere MFT EPSS 100% 2 articles
CVE-2025-48703 9 Critical KEV Ransomware 79d ago

CWP Control Web Panel OS Command Injection Vulnerability

CWP Control Web Panel EPSS 100% 1 article
CVE-2025-55182 10 Critical KEV Ransomware 79d ago

Meta React Server Components Remote Code Execution Vulnerability

Meta React Server Components EPSS 100% 6 articles · 1 incident
CVE-2018-0171 7.5 High KEV 11d ago

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload

EPSS 100% 1 article · 1 incident
CVE-2025-29927 9.1 Critical 79d ago

Next.js is a React framework for building full-stack web applications.

EPSS 99% 1 article
CVE-2017-0144 8.8 High KEV Ransomware 74d ago

Microsoft SMBv1 Remote Code Execution Vulnerability

Microsoft SMBv1 EPSS 99% 1 article
CVE-2008-4250 9.8 Critical KEV Ransomware 65d ago

Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows EPSS 99% 4 articles
CVE-2025-32433 10 Critical KEV Ransomware 73d ago

Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

Erlang Erlang/OTP EPSS 99% 1 article · 1 incident
CVE-2024-55591 9.6 Critical KEV Ransomware 73d ago

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy EPSS 98% 1 article · 1 incident
CVE-2026-33017 9.3 Critical KEV Ransomware 29d ago

Langflow Code Injection Vulnerability

Langflow Langflow EPSS 98% 1 article · 1 incident
CVE-2026-41940 9.8 Critical KEV Ransomware 69d ago

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

WebPros cPanel & WHM and WP2 (WordPress Squared) EPSS 98% 18 articles · 1 incident
CVE-2026-63030 9.8 Critical KEV 3d ago

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Qu

EPSS 98% 11 articles · 1 incident
CVE-2026-34197 8.8 High Ransomware 108d ago

Apache ActiveMQ Improper Input Validation Vulnerability

Apache ActiveMQ EPSS 97% 2 articles
CVE-2026-23760 9.3 Critical KEV Ransomware 109d ago

SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability

SmarterTools SmarterMail EPSS 96% 1 article
CVE-2026-31431 7.8 High KEV Ransomware 59d ago

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Linux Kernel EPSS 96% 17 articles · 1 incident
CVE-2026-20253 9.8 Critical KEV 36d ago

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a Postgre

EPSS 96% 8 articles · 1 incident
CVE-2025-54068 9.2 Critical KEV 31d ago

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote co

EPSS 95% 1 article
CVE-2026-39987 9.3 Critical KEV Ransomware 57d ago

Marimo Remote Code Execution Vulnerability

Marimo Marimo EPSS 95% 7 articles
CVE-2025-49113 9.9 Critical KEV 12d ago

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validate

EPSS 95% 1 article · 1 incident
CVE-2026-21643 9.1 Critical KEV Ransomware 103d ago

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS EPSS 94% 7 articles · 1 incident
CVE-2026-35273 9.8 Critical KEV 25d ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management).

EPSS 94% 18 articles · 2 incidents
CVE-2025-57819 10 Critical KEV Ransomware 59d ago

Sangoma FreePBX Authentication Bypass Vulnerability

Sangoma FreePBX EPSS 93% 1 article
CVE-2026-43284 8.8 High 59d ago

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from

EPSS 93% 7 articles · 1 incident
CVE-2026-43500 7.8 High 59d ago

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handl

EPSS 93% 7 articles · 1 incident
CVE-2024-7399 8.8 High KEV Ransomware 91d ago

Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung MagicINFO 9 Server EPSS 92% 5 articles
CVE-2010-0249 8.8 High KEV Ransomware 65d ago

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer EPSS 92% 4 articles
CVE-2026-20182 10 Critical KEV Ransomware 68d ago

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN EPSS 90% 9 articles
CVE-2025-59528 10 Critical 109d ago

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution.

EPSS 90% 3 articles · 1 incident
CVE-2026-39808 9.1 Critical KEV Ransomware 7d ago

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox EPSS 90% 12 articles · 3 incidents
CVE-2022-0847 7.8 High KEV Ransomware 79d ago

Linux Kernel Privilege Escalation Vulnerability

Linux Kernel EPSS 89% 1 article
CVE-2026-35616 9.1 Critical KEV Ransomware 55d ago

Fortinet FortiClient EMS Improper Access Control Vulnerability

Fortinet FortiClient EMS EPSS 89% 11 articles
CVE-2025-26399 9.8 Critical KEV Ransomware 96d ago

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds Web Help Desk EPSS 88% 1 article
CVE-2026-20127 10 Critical KEV Ransomware 72d ago

Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller and Manager EPSS 88% 4 articles
CVE-2026-1731 9.9 Critical KEV Ransomware 95d ago

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) EPSS 88% 4 articles
CVE-2024-1708 8.4 High KEV Ransomware 87d ago

ConnectWise ScreenConnect Path Traversal Vulnerability

ConnectWise ScreenConnect EPSS 88% 4 articles · 1 incident
CVE-2025-29635 7.2 High KEV Ransomware 91d ago

D-Link DIR-823X Command Injection Vulnerability

D-Link DIR-823X EPSS 87% 7 articles · 1 incident
CVE-2026-0257 7.8 High KEV 4d ago

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security rest

Palo Alto Networks PAN-OS EPSS 87% 18 articles · 1 incident
CVE-2026-42208 9.3 Critical KEV Ransomware 75d ago

BerriAI LiteLLM SQL Injection Vulnerability

BerriAI LiteLLM EPSS 87% 8 articles · 1 incident
CVE-2009-3459 8.8 High KEV Ransomware 65d ago

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader EPSS 87% 4 articles
CVE-2024-3721 6.5 Medium 96d ago

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical.

EPSS 86% 3 articles
CVE-2022-41678 Unrated 108d ago

Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.

EPSS 86% 1 article
CVE-2025-20362 6.5 Medium KEV Ransomware 92d ago

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense EPSS 86% 3 articles
CVE-2026-9082 9.8 Critical KEV Ransomware 61d ago

Drupal Core SQL Injection Vulnerability

Drupal Core EPSS 85% 8 articles · 1 incident
CVE-2025-64328 8.6 High KEV Ransomware 59d ago

Sangoma FreePBX OS Command Injection Vulnerability

Sangoma FreePBX EPSS 85% 1 article
CVE-2024-42009 9.3 Critical KEV 12d ago

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a craf

EPSS 84% 2 articles · 1 incident
CVE-2026-1340 9.8 Critical KEV Ransomware 79d ago

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) EPSS 84% 4 articles
CVE-2026-3055 9.3 Critical KEV Ransomware 116d ago

Citrix NetScaler Out-of-Bounds Read Vulnerability

Citrix NetScaler EPSS 84% 2 articles · 1 incident
CVE-2022-26923 8.8 High KEV Ransomware 75d ago

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Microsoft Active Directory EPSS 83% 1 article
CVE-2026-50751 9.3 Critical KEV 41d ago

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to by

Check Point Security Gateway EPSS 83% 41 articles · 7 incidents