CVE Tracker

Every vulnerability in the news, ranked by real-world risk.

CVE-2026-50751 9.3 Critical KEV 15m ago
Check Point Security Gateway EPSS 0.0% 40 articles · 2 incidents
CVE-2025-8088 8.4 High KEV 13h ago

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files.

RARLAB WinRAR EPSS 12% 4 articles · 1 incident
CVE-2026-7473 6.9 Medium KEV 17h ago

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Rout

Arista Extensible Operating System EPSS 22% 8 articles · 2 incidents
CVE-2026-20245 7.8 High KEV 17h ago

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Cataly

Cisco Catalyst SD-WAN Manager EPSS 0.3% 10 articles · 2 incidents
CVE-2026-11645 8.8 High KEV 17h ago

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H

Google Chromium V8 EPSS 5.5% 13 articles · 2 incidents
CVE-2026-41091 7.8 High KEV Ransomware 1d ago

Microsoft Defender Link Following Vulnerability

Microsoft Defender EPSS 8.2% 7 articles
CVE-2026-42271 8.7 High KEV 1d ago
BerriAI LiteLLM EPSS 0.0% 22 articles · 2 incidents
CVE-2026-28318 7.5 High KEV 2d ago

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate.

SolarWinds Serv-U EPSS 7.8% 11 articles · 1 incident
CVE-2026-0257 7.8 High KEV 5d ago

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security rest

Palo Alto Networks PAN-OS EPSS 59% 16 articles · 1 incident
CVE-2026-45247 9.8 Critical KEV 6d ago

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achi

Mirasvit Mirasvit Full Page Cache Warmer EPSS 6.1% 6 articles · 1 incident
CVE-2025-48595 8.4 High KEV 7d ago

In multiple locations, there is a possible way to achieve code execution due to an integer overflow.

Android Framework EPSS 0.5% 10 articles · 1 incident
CVE-2022-0492 7.8 High KEV 7d ago

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function.

Linux Kernel EPSS 28% 6 articles · 1 incident
CVE-2024-21182 7.5 High KEV 8d ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).

Oracle WebLogic Server EPSS 90% 9 articles
CVE-2026-35616 9.1 Critical KEV Ransomware 10d ago

Fortinet FortiClient EMS Improper Access Control Vulnerability

Fortinet FortiClient EMS EPSS 35% 11 articles
CVE-2026-39987 9.3 Critical KEV Ransomware 12d ago

Marimo Remote Code Execution Vulnerability

Marimo Marimo EPSS 81% 7 articles
CVE-2026-48027 9.3 Critical KEV Ransomware 13d ago

Nx Console Embedded Malicious Code Vulnerability

Nx Nx Console EPSS 32% 8 articles
CVE-2026-45321 9.6 Critical KEV Ransomware 13d ago

TanStack Unspecified Vulnerability

TanStack TanStack EPSS 17% 9 articles
CVE-2026-8398 9.8 Critical KEV Ransomware 13d ago

Daemon Tools Lite Embedded Malicious Code Vulnerability

Daemon Daemon Tools Lite EPSS 14% 7 articles
CVE-2026-48172 10 Critical KEV Ransomware 13d ago

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

LiteSpeed cPanel Plugin EPSS 0.0% 6 articles · 1 incident
CVE-2025-64328 8.6 High KEV Ransomware 14d ago

Sangoma FreePBX OS Command Injection Vulnerability

Sangoma FreePBX EPSS 75% 1 article
CVE-2025-57819 10 Critical KEV Ransomware 14d ago

Sangoma FreePBX Authentication Bypass Vulnerability

Sangoma FreePBX EPSS 77% 1 article
CVE-2026-31431 7.8 High KEV Ransomware 14d ago

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Linux Kernel EPSS 0.0% 17 articles · 1 incident
CVE-2025-55177 5.4 Medium KEV Ransomware 16d ago

Meta Platforms WhatsApp Incorrect Authorization Vulnerability

Meta Platforms WhatsApp EPSS 0.8% 1 article
CVE-2025-43300 10 Critical KEV Ransomware 16d ago

Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, and macOS EPSS 4.4% 1 article
CVE-2026-9082 9.8 Critical KEV Ransomware 16d ago

Drupal Core SQL Injection Vulnerability

Drupal Core EPSS 0.0% 8 articles · 1 incident
CVE-2026-34926 6.7 Medium KEV Ransomware 19d ago

Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

Trend Micro Apex One EPSS 1.0% 4 articles
CVE-2025-34291 9.4 Critical KEV Ransomware 19d ago

Langflow Origin Validation Error Vulnerability

Langflow Langflow EPSS 33% 3 articles
CVE-2009-3459 8.8 High KEV Ransomware 20d ago

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader EPSS 88% 4 articles
CVE-2009-1537 8.8 High KEV Ransomware 20d ago

Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft DirectX EPSS 53% 4 articles
CVE-2010-0249 8.8 High KEV Ransomware 20d ago

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer EPSS 89% 4 articles
CVE-2010-0806 8.8 High KEV Ransomware 20d ago

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer EPSS 87% 4 articles
CVE-2008-4250 9.8 Critical KEV Ransomware 20d ago

Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows EPSS 92% 4 articles
CVE-2026-45498 4 Medium KEV Ransomware 20d ago

Microsoft Defender Denial of Service Vulnerability

Microsoft Defender EPSS 3.5% 4 articles
CVE-2026-33825 7.8 High KEV Ransomware 22d ago

Microsoft Defender Insufficient Granularity of Access Control Vulnerability

Microsoft Defender EPSS 0.0% 15 articles · 1 incident
CVE-2026-0300 9.3 Critical KEV Ransomware 22d ago

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Palo Alto Networks PAN-OS EPSS 4.9% 14 articles · 1 incident
CVE-2026-42897 8.1 High KEV Ransomware 23d ago

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft Microsoft EPSS 7.9% 10 articles
CVE-2026-20182 10 Critical KEV Ransomware 23d ago

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN EPSS 84% 9 articles
CVE-2026-20131 10 Critical KEV Ransomware 23d ago

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerabilit

Cisco Secure Firewall Management Center (FMC) EPSS 1.7% 3 articles · 1 incident
CVE-2025-62221 7.8 High KEV Ransomware 23d ago

Microsoft Windows Use After Free Vulnerability

Microsoft Windows EPSS 1.5% 1 article
CVE-2026-41940 9.8 Critical KEV Ransomware 24d ago

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

WebPros cPanel & WHM and WP2 (WordPress Squared) EPSS 0.0% 18 articles · 1 incident
CVE-2026-20127 10 Critical KEV Ransomware 26d ago

Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller and Manager EPSS 55% 4 articles
CVE-2025-32975 10 Critical KEV Ransomware 28d ago

Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

Quest KACE Systems Management Appliance (SMA) EPSS 39% 6 articles
CVE-2025-33073 8.8 High KEV Ransomware 28d ago

Microsoft Windows SMB Client Improper Access Control Vulnerability

Microsoft Windows EPSS 0.0% 1 article · 1 incident
CVE-2024-55591 9.6 Critical KEV Ransomware 28d ago

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy EPSS 0.0% 1 article · 1 incident
CVE-2025-32433 10 Critical KEV Ransomware 28d ago

Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

Erlang Erlang/OTP EPSS 0.0% 1 article · 1 incident
CVE-2017-0144 8.8 High KEV Ransomware 29d ago

Microsoft SMBv1 Remote Code Execution Vulnerability

Microsoft SMBv1 EPSS 94% 1 article
CVE-2022-26923 8.8 High KEV Ransomware 30d ago

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Microsoft Active Directory EPSS 92% 1 article
CVE-2026-6973 7.2 High KEV Ransomware 30d ago

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) EPSS 4.8% 7 articles
CVE-2026-42208 9.3 Critical KEV Ransomware 30d ago

BerriAI LiteLLM SQL Injection Vulnerability

BerriAI LiteLLM EPSS 63% 8 articles · 1 incident
CVE-2026-1340 9.8 Critical KEV Ransomware 33d ago

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) EPSS 74% 4 articles
CVE-2026-1281 9.8 Critical KEV Ransomware 33d ago

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) EPSS 82% 1 article
CVE-2025-48703 9 Critical KEV Ransomware 34d ago

CWP Control Web Panel OS Command Injection Vulnerability

CWP Control Web Panel EPSS 70% 1 article
CVE-2025-55182 10 Critical KEV Ransomware 34d ago

Meta React Server Components Remote Code Execution Vulnerability

Meta React Server Components EPSS 85% 6 articles · 1 incident
CVE-2022-0847 7.8 High KEV Ransomware 34d ago

Linux Kernel Privilege Escalation Vulnerability

Linux Kernel EPSS 81% 1 article
CVE-2019-13272 7.8 High KEV Ransomware 34d ago

Linux Kernel Improper Privilege Management Vulnerability

Linux Kernel EPSS 80% 1 article
CVE-2026-21509 7.8 High KEV Ransomware 34d ago

Microsoft Office Security Feature Bypass Vulnerability

Microsoft Office EPSS 12% 3 articles
CVE-2026-21514 7.8 High KEV Ransomware 34d ago

Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability

Microsoft Office EPSS 5.4% 1 article
CVE-2021-22555 8.3 High KEV Ransomware 34d ago

Linux Kernel Heap Out-of-Bounds Write Vulnerability

Linux Kernel EPSS 85% 1 article
CVE-2026-21513 8.8 High KEV Ransomware 34d ago

Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

Microsoft Windows EPSS 28% 5 articles · 1 incident
CVE-2021-30900 7.8 High KEV Ransomware 38d ago

Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, and macOS EPSS 0.5% 1 article