CVE Tracker

Every vulnerability in the news, ranked by real-world risk.

CVE-2025-66376 7.2 High KEV 22h ago

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML

EPSS 12% 5 articles · 1 incident
CVE-2026-12569 9.3 Critical KEV 1d ago

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM.

EPSS 2.3% 8 articles · 1 incident
CVE-2026-16232 9.1 Critical KEV 2d ago

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login to

EPSS 0.0% 9 articles · 1 incident
CVE-2026-50522 9.8 Critical KEV 2d ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

EPSS 20% 6 articles · 1 incident
CVE-2024-36401 9.8 Critical KEV 3d ago

GeoServer is an open source server that allows users to share and edit geospatial data.

EPSS 100% 1 article
CVE-2026-56164 5.3 Medium KEV 3d ago

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

EPSS 5.6% 11 articles · 2 incidents
CVE-2026-45659 8.8 High KEV Ransomware 3d ago

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server EPSS 9.1% 12 articles · 3 incidents
CVE-2026-58644 9.8 Critical KEV 3d ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

EPSS 1.5% 11 articles · 3 incidents
CVE-2021-27137 8.1 High KEV 3d ago

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker

EPSS 16% 3 articles · 1 incident
CVE-2026-60137 9.1 Critical KEV 3d ago

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow

EPSS 78% 9 articles · 1 incident
CVE-2026-63030 9.8 Critical KEV 3d ago

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Qu

EPSS 98% 11 articles · 1 incident
CVE-2026-0770 9.8 Critical KEV 3d ago

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability.

EPSS 10% 3 articles · 1 incident
CVE-2025-3248 9.8 Critical KEV 3d ago

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.

EPSS 100% 4 articles · 1 incident
CVE-2026-0257 7.8 High KEV 4d ago

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security rest

Palo Alto Networks PAN-OS EPSS 87% 18 articles · 1 incident
CVE-2026-15410 7.2 High KEV 4d ago

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC

EPSS 1.5% 11 articles · 2 incidents
CVE-2026-15409 10 Critical KEV 4d ago

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.

EPSS 1.3% 11 articles · 2 incidents
CVE-2026-10520 10 Critical KEV 5d ago

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-lev

EPSS 100% 13 articles · 1 incident
CVE-2026-25089 9.1 Critical KEV 7d ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSa

EPSS 70% 14 articles · 4 incidents
CVE-2026-39808 9.1 Critical KEV Ransomware 7d ago

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox EPSS 90% 12 articles · 3 incidents
CVE-2023-4346 7.5 High KEV 8d ago

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable t

EPSS 0.9% 3 articles · 1 incident
CVE-2026-46817 9.8 Critical KEV 8d ago

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).

EPSS 1.0% 7 articles · 1 incident
CVE-2026-56155 7.8 High KEV 10d ago

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

EPSS 0.4% 7 articles · 2 incidents
CVE-2008-4128 4.3 Medium KEV 11d ago

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow re

EPSS 24% 4 articles · 1 incident
CVE-2018-0171 7.5 High KEV 11d ago

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload

EPSS 100% 1 article · 1 incident
CVE-2024-42009 9.3 Critical KEV 12d ago

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a craf

EPSS 84% 2 articles · 1 incident
CVE-2025-49113 9.9 Critical KEV 12d ago

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validate

EPSS 95% 1 article · 1 incident
CVE-2026-48939 10 Critical KEV 12d ago

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code uploa

EPSS 24% 6 articles · 2 incidents
CVE-2026-56291 10 Critical KEV 12d ago

Joomla Extension balbooa.com Unauthenticated file upload in Balbooa Forms extension < 2.4.1 The Joomla extension Balbooa Forms is vulnerable to an unauthenticat

EPSS 76% 6 articles · 2 incidents
CVE-2026-55255 8.4 High KEV 13d ago

Langflow is a tool for building and deploying AI-powered agents and workflows.

EPSS 29% 12 articles · 2 incidents
CVE-2026-48282 10 Critical KEV 13d ago

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

EPSS 29% 17 articles · 4 incidents
CVE-2026-48908 10 Critical KEV 17d ago

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP co

EPSS 1.6% 10 articles · 3 incidents
CVE-2026-56290 10 Critical KEV 17d ago

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

EPSS 2.9% 10 articles · 3 incidents
CVE-2026-48558 10 Critical KEV 20d ago

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow.

EPSS 1.2% 11 articles · 2 incidents
CVE-2026-20230 8.6 High KEV 23d ago

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could

EPSS 81% 16 articles · 2 incidents
CVE-2026-33825 7.8 High KEV Ransomware 24d ago

Microsoft Defender Insufficient Granularity of Access Control Vulnerability

Microsoft Defender EPSS 6.7% 17 articles · 2 incidents
CVE-2026-35273 9.8 Critical KEV 25d ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management).

EPSS 94% 18 articles · 2 incidents
CVE-2025-8088 8.4 High KEV 26d ago

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files.

RARLAB WinRAR EPSS 81% 6 articles · 2 incidents
CVE-2026-33017 9.3 Critical KEV Ransomware 29d ago

Langflow Code Injection Vulnerability

Langflow Langflow EPSS 98% 1 article · 1 incident
CVE-2026-20245 7.8 High KEV 29d ago

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Cataly

Cisco Catalyst SD-WAN Manager EPSS 25% 17 articles · 2 incidents
CVE-2025-67038 9.8 Critical KEV 30d ago

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails.

EPSS 0.9% 11 articles · 1 incident
CVE-2025-54068 9.2 Critical KEV 31d ago

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote co

EPSS 95% 1 article
CVE-2026-34910 10 Critical KEV 31d ago

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

EPSS 79% 9 articles · 2 incidents
CVE-2026-34909 10 Critical KEV 31d ago

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system tha

EPSS 2.3% 8 articles · 2 incidents
CVE-2026-34908 10 Critical KEV 31d ago

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to th

EPSS 58% 9 articles · 2 incidents
CVE-2024-40766 9.3 Critical KEV 33d ago

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and

EPSS 18% 1 article
CVE-2026-20253 9.8 Critical KEV 36d ago

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a Postgre

EPSS 96% 8 articles · 1 incident
CVE-2024-20399 6 Medium KEV 37d ago

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as

EPSS 4.3% 1 article
CVE-2026-48907 10 Critical KEV 38d ago

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code up

EPSS 80% 6 articles · 1 incident
CVE-2026-54420 8.5 High KEV 39d ago

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access

EPSS 1.3% 7 articles · 1 incident
CVE-2026-20262 6.5 Medium KEV 39d ago

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overw

EPSS 7.7% 9 articles · 2 incidents
CVE-2026-42271 8.7 High KEV 41d ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format.

BerriAI LiteLLM EPSS 80% 22 articles · 2 incidents
CVE-2026-11645 8.8 High KEV 41d ago

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H

Google Chromium V8 EPSS 1.7% 13 articles · 3 incidents
CVE-2026-50751 9.3 Critical KEV 41d ago

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to by

Check Point Security Gateway EPSS 83% 41 articles · 7 incidents
CVE-2026-42897 8.1 High KEV Ransomware 45d ago

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft Microsoft EPSS 5.6% 11 articles
CVE-2026-7473 6.9 Medium KEV 45d ago

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Rout

Arista Extensible Operating System EPSS 1.1% 8 articles · 3 incidents
CVE-2026-41091 7.8 High KEV Ransomware 46d ago

Microsoft Defender Link Following Vulnerability

Microsoft Defender EPSS 8.4% 7 articles · 1 incident
CVE-2026-28318 7.5 High KEV 47d ago

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate.

SolarWinds Serv-U EPSS 8.4% 11 articles · 1 incident
CVE-2026-45247 9.8 Critical KEV 51d ago

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achi

Mirasvit Mirasvit Full Page Cache Warmer EPSS 28% 6 articles · 1 incident
CVE-2025-48595 8.4 High KEV 52d ago

In multiple locations, there is a possible way to achieve code execution due to an integer overflow.

Android Framework EPSS 1.7% 10 articles · 1 incident
CVE-2022-0492 7.8 High KEV 52d ago

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function.

Linux Kernel EPSS 5.5% 6 articles · 1 incident