Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2022-0995 KEV An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event...
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event...
CVE-2015-5287 KEV The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local...
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local...
CVE-2015-3246 KEV libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the...
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the...
CVE-2021-23758 KEV Ajax.NET Professional Ajax.NET Professional — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CVE-2026-60004 KEV [KEV] Code Injection in gitea (CVE-2026-60004)
code injection in gitea (CVE-2026-60004). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-69836 KEV [KEV] Unsafe Deserialization in Microsoft deserialization (CVE-2026-69836)
vulnerability in Microsoft deserialization (CVE-2026-69836). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2025-62593 KEV [KEV] Cross-Site Request Forgery (CSRF) in Ray-project ray (CVE-2025-62593)
vulnerability in Ray-project ray (CVE-2025-62593). Successful exploitation can lead to full system takeover. Exploitable via ``fetch``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `2.52.0` or later.
CVE-2026-73570 KEV [KEV] OS Command Injection in Synacor zimbra-collaboration-suite (CVE-2026-73570)
OS command injection in Synacor zimbra-collaboration-suite (CVE-2026-73570). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2026-20349 KEV [KEV] Vulnerability in Cisco dos (CVE-2026-20349)
vulnerability in Cisco dos (CVE-2026-20349). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2026-18577 KEV [KEV] Vulnerability in N-able n-central (CVE-2026-18577)
vulnerability in N-able n-central (CVE-2026-18577). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-18556 KEV [KEV] Vulnerability in N-able n-central (CVE-2026-18556)
vulnerability in N-able n-central (CVE-2026-18556). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2026-59310 KEV [KEV] Path Traversal in Broadcom path-traversal (CVE-2026-59310)
path traversal in Broadcom path-traversal (CVE-2026-59310). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-63077 KEV [KEV] Unsafe Deserialization in Jetbrains teamcity (CVE-2026-63077)
vulnerability in Jetbrains teamcity (CVE-2026-63077). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-16232 KEV [KEV] Authentication Bypass in Check point checkpoint (CVE-2026-16232)
authentication bypass in Check point checkpoint (CVE-2026-16232). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-0770 KEV [KEV] Vulnerability in langflow (CVE-2026-0770)
vulnerability in langflow (CVE-2026-0770). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-63030 KEV WordPress Core — WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
CVE-2026-60137 KEV [KEV] SQL Injection in Wordpress sqli (CVE-2026-60137)
SQL injection in Wordpress sqli (CVE-2026-60137). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2026-9198 KEV [KEV] Code Injection in Ibm langflow (CVE-2026-9198)
code injection in Ibm langflow (CVE-2026-9198). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-58644 KEV [KEV] Unsafe Deserialization in Microsoft deserialization (CVE-2026-58644)
vulnerability in Microsoft deserialization (CVE-2026-58644). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-50522 KEV [KEV] Unsafe Deserialization in Microsoft deserialization (CVE-2026-50522)
vulnerability in Microsoft deserialization (CVE-2026-50522). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-15409 KEV [KEV] SSRF (Server-Side Request Forgery) in Sonicwall ssrf (CVE-2026-15409)
SSRF in Sonicwall ssrf (CVE-2026-15409). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-56291 KEV [KEV] Unrestricted File Upload in Balbooa forms (CVE-2026-56291)
vulnerability in Balbooa forms (CVE-2026-56291). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-48282 KEV [KEV] Path Traversal in Adobe path-traversal (CVE-2026-48282)
path traversal in Adobe path-traversal (CVE-2026-48282). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-8452 KEV [KEV] Buffer Overflow in Citrix dos (CVE-2026-8452)
vulnerability in Citrix dos (CVE-2026-8452). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-56290 KEV [KEV] Unrestricted File Upload in Joomlack page-builder-ck (CVE-2026-56290)
vulnerability in Joomlack page-builder-ck (CVE-2026-56290). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2025-67038 KEV An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell...
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell...
CVE-2026-12569 KEV [KEV] Vulnerability in Ptc deserialization (CVE-2026-12569)
vulnerability in Ptc deserialization (CVE-2026-12569). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-48558 KEV [KEV] Vulnerability in Simplehelp simple-help (CVE-2026-48558)
vulnerability in Simplehelp simple-help (CVE-2026-48558). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-10520 KEV [KEV] OS Command Injection in Ivanti standalone-sentry (CVE-2026-10520)
OS command injection in Ivanti standalone-sentry (CVE-2026-10520). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-8037 KEV [KEV] Command Injection in Progress connection-manager-for-objectscale (CVE-2026-8037)
command injection in Progress connection-manager-for-objectscale (CVE-2026-8037). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-20230 KEV [KEV] SSRF (Server-Side Request Forgery) in Cisco ssrf (CVE-2026-20230)
SSRF in Cisco ssrf (CVE-2026-20230). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
CVE-2024-21182 KEV Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...
CVE-2026-45247 KEV [KEV] Unsafe Deserialization in Mirasvit full-page-cache-warmer (CVE-2026-45247)
vulnerability in Mirasvit full-page-cache-warmer (CVE-2026-45247). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-45659 KEV [KEV] Unsafe Deserialization in Microsoft deserialization (CVE-2026-45659)
vulnerability in Microsoft deserialization (CVE-2026-45659). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-34909 KEV [KEV] Path Traversal in Ubiquiti path-traversal (CVE-2026-34909)
path traversal in Ubiquiti path-traversal (CVE-2026-34909). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-34926 KEV [KEV] Vulnerability in Trend micro path-traversal (CVE-2026-34926)
vulnerability in Trend micro path-traversal (CVE-2026-34926). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2026-48172 KEV [KEV] Vulnerability in Litespeed privilege-escalation (CVE-2026-48172)
vulnerability in Litespeed privilege-escalation (CVE-2026-48172). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-9082 KEV [KEV] SQL Injection in drupal/core (CVE-2026-9082)
SQL injection in drupal/core (CVE-2026-9082). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `11.3.10` or later.
CVE-2026-45498 KEV Microsoft Defender Denial of Service Vulnerability
Microsoft Defender Denial of Service Vulnerability
CVE-2026-42897 KEV [KEV] Cross-Site Scripting (XSS) in Microsoft exchange-server (CVE-2026-42897)
cross-site scripting in Microsoft exchange-server (CVE-2026-42897). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2026-0257 KEV [KEV] Vulnerability in Palo alto networks paloaltonetworks (CVE-2026-0257)
vulnerability in Palo alto networks paloaltonetworks (CVE-2026-0257). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2026-6973 KEV [KEV] Vulnerability in Ivanti endpoint-manager-mobile-epmm (CVE-2026-6973)
vulnerability in Ivanti endpoint-manager-mobile-epmm (CVE-2026-6973). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2026-0300 KEV [KEV] Out-of-Bounds Write in Palo alto networks palo-alto-networks (CVE-2026-0300)
out-of-bounds write in Palo alto networks palo-alto-networks (CVE-2026-0300). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2026-31431 KEV [KEV] Vulnerability in Linux redhat (CVE-2026-31431)
vulnerability in Linux redhat (CVE-2026-31431). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-41940 KEV [KEV] Vulnerability in Webpros cpanel-whm-and-wp2-wordpress-squared (CVE-2026-41940)
vulnerability in Webpros cpanel-whm-and-wp2-wordpress-squared (CVE-2026-41940). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-1708 KEV [KEV] Path Traversal in Connectwise screenconnect (CVE-2024-1708)
path traversal in Connectwise screenconnect (CVE-2024-1708). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-57728 KEV [KEV] Path Traversal in Simplehelp path-traversal (CVE-2024-57728)
path traversal in Simplehelp path-traversal (CVE-2024-57728). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-7399 KEV [KEV] Path Traversal in Samsung magicinfo-9-server (CVE-2024-7399)
path traversal in Samsung magicinfo-9-server (CVE-2024-7399). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-29635 KEV [KEV] Command Injection in D-link dir-823x (CVE-2025-29635)
command injection in D-link dir-823x (CVE-2025-29635). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-57726 KEV [KEV] Vulnerability in Simplehelp auth (CVE-2024-57726)
vulnerability in Simplehelp auth (CVE-2024-57726). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →