51,518 indexed
CVECVE vulnerabilities
51,518 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1–50 of 1,656 in KEV · page 1 of 34
| ID | Title | Summary |
|---|---|---|
| CVE-2026-9082 | Drupal Core SQL Injection Vulnerability KEVCVSS 9.8Drupal | Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with… |
| CVE-2026-8398 | Daemon Tools Lite Embedded Malicious Code Vulnerability KEVCVSS 9.8Daemon | Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability. |
| CVE-2026-7473 | Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability KEVCVSS 5.8Arista | Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwa… |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability KEVCVSS 7.2Ivanti | Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access … |
| CVE-2026-63030 | WordPress Core Interpretation Conflict Vulnerability KEVCVSS 9.8WordPress | WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This … |
| CVE-2026-60137 | WordPress Core SQL Injection Vulnerability KEVCVSS 5.9WordPress | WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CV… |
| CVE-2026-58644 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability KEVCVSS 9.8Microsoft | Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. |
| CVE-2026-56291 | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability KEVCVSS 9.8Balbooa | Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow … |
| CVE-2026-56290 | Joomlack Page Builder Improper Access Control Vulnerability KEVCVSS 9.8Joomlack | Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload. |
| CVE-2026-56164 | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability KEVCVSS 5.3Microsoft | Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a ne… |
| CVE-2026-56155 | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability KEVCVSS 7.8Microsoft | Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to eleva… |
| CVE-2026-55255 | Langflow Authorization Bypass Through User-Controlled Key Vulnerability KEVCVSS 8.4Langflow | Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to ano… |
| CVE-2026-54420 | LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability KEVCVSS 8.5LiteSpeed | LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hostin… |
| CVE-2026-5281 | Google Dawn Use-After-Free Vulnerability KEVCVSS 8.8Google | Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via … |
| CVE-2026-50751 | Check Point Security Gateway Improper Authentication Vulnerability KEVCVSS 9.3Check Point | Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to byp… |
| CVE-2026-50522 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability KEVCVSS 9.8Microsoft | Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. |
| CVE-2026-48939 | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability KEVCVSS 9.8iCagenda | iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ul… |
| CVE-2026-48908 | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability KEVCVSS 9.8JoomShaper | JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary file… |
| CVE-2026-48907 | Widget Factory Joomla Content Editor Improper Access Control Vulnerability KEVCVSS 9.8Widget Factory | Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation … |
| CVE-2026-48558 | SimpleHelp Authentication Bypass Vulnerability KEVCVSS 10.0SimpleHelp | SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted d… |
| CVE-2026-48282 | Adobe ColdFusion Path Traversal Vulnerability KEVCVSS 10.0Adobe | Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. |
| CVE-2026-48172 | LiteSpeed cPanel Plugin Privilege Escalation Vulnerability KEVCVSS 9.8LiteSpeed | LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user acco… |
| CVE-2026-48027 | Nx Console Embedded Malicious Code Vulnerability KEVNx | Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched … |
| CVE-2026-46817 | Oracle E-Business Suite Improper Privilege Management Vulnerability KEVCVSS 9.8Oracle | Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to comprom… |
| CVE-2026-45659 | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability KEVCVSS 8.8Microsoft | Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. |
| CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability KEVCVSS 4.0Microsoft | Microsoft Defender contains an unspecified vulnerability that allows for denial of service. |
| CVE-2026-45321 | TanStack Unspecified Vulnerability KEVCVSS 9.6TanStack | TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealin… |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability KEVCVSS 9.8Mirasvit | Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code ex… |
| CVE-2026-42897 | Microsoft Exchange Server Cross-Site Scripting Vulnerability KEVCVSS 8.1Microsoft | Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction condition… |
| CVE-2026-42271 | BerriAI LiteLLM Command Injection Vulnerability KEVCVSS 8.8BerriAI | BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to r… |
| CVE-2026-42208 | BerriAI LiteLLM SQL Injection Vulnerability KEVCVSS 9.8BerriAI | BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to una… |
| CVE-2026-41940 | WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability KEVCVSS 9.8WebPros | WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated… |
| CVE-2026-41091 | Microsoft Defender Link Following Vulnerability KEVCVSS 7.8Microsoft | Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. |
| CVE-2026-39987 | Marimo Remote Code Execution Vulnerability KEVCVSS 9.8Marimo | Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system com… |
| CVE-2026-39808 | Fortinet FortiSandbox OS Command Injection Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via … |
| CVE-2026-3910 | Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability KEVCVSS 8.8Google | Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to exec… |
| CVE-2026-3909 | Google Skia Out-of-Bounds Write Vulnerability KEVCVSS 8.8Google | Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. Th… |
| CVE-2026-35616 | Fortinet FortiClient EMS Improper Access Control Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands … |
| CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability KEVCVSS 9.8Oracle | Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to… |
| CVE-2026-3502 | TrueConf Client Download of Code Without Integrity Check Vulnerability KEVCVSS 7.8TrueConf | TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute… |
| CVE-2026-34926 | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability KEVCVSS 6.7Trend Micro | Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the… |
| CVE-2026-34910 | Ubiquiti UniFi OS Improper Input Validation Vulnerability KEVCVSS 10.0Ubiquiti | Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injecti… |
| CVE-2026-34909 | Ubiquiti UniFi OS Path Traversal Vulnerability KEVCVSS 10.0Ubiquiti | Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying syst… |
| CVE-2026-34908 | Ubiquiti UniFi OS Improper Access Control Vulnerability KEVCVSS 10.0Ubiquiti | Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes… |
| CVE-2026-34621 | Adobe Acrobat and Reader Prototype Pollution Vulnerability KEVCVSS 8.6Adobe | Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. |
| CVE-2026-34197 | Apache ActiveMQ Improper Input Validation Vulnerability KEVCVSS 8.8Apache | Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. |
| CVE-2026-33825 | Microsoft Defender Insufficient Granularity of Access Control Vulnerability KEVCVSS 7.8Microsoft | Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. |
| CVE-2026-33634 | Aquasecurity Trivy Embedded Malicious Code Vulnerability KEVCVSS 8.8Aquasecurity | Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, includ… |
| CVE-2026-33017 | Langflow Code Injection Vulnerability KEVCVSS 9.8Langflow | Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication. |
| CVE-2026-32202 | Microsoft Windows Protection Mechanism Failure Vulnerability KEVCVSS 4.3Microsoft | Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. |