86,884 indexed
CVECVE vulnerabilities
86,884 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1–50 of 1,734 in KEV · page 1 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2026-9586 | Sangoma Switchvox SQL Injection Vulnerability KEVCVSS 9.8Sangoma | Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backen… |
| CVE-2026-94127 | F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability KEVCVSS 9.8F5 | F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerabilit… |
| CVE-2026-93952 | Arista VeloCloud Orchestrator Improper Input Validation Vulnerability KEVCVSS 10.0Arista | Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal … |
| CVE-2026-93616 | Check Point Multiple Products Path Traversal Vulnerability KEVCVSS 9.8Check Point | Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal v… |
| CVE-2026-9198 | IBM Langflow Code Injection Vulnerability KEVCVSS 9.8IBM | Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. |
| CVE-2026-9082 | Drupal Core SQL Injection Vulnerability KEVCVSS 9.8Drupal | Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with… |
| CVE-2026-88779 | CVE-2026-88779 KEVCVSS 7.5citrix | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37… |
| CVE-2026-88772 | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability KEVCVSS 8.1Citrix | Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow fo… |
| CVE-2026-88771 | Citrix NetScaler Improper Input Validation Vulnerability KEVCVSS 9.8Citrix | Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary… |
| CVE-2026-87902 | WordPress Core Remote File Inclusion Vulnerability KEVCVSS 8.1WordPress | WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen r… |
| CVE-2026-87886 | Acronis Backup Incorrect Default Permissions Vulnerability KEVCVSS 7.8Acronis | Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalatio… |
| CVE-2026-87491 | Google Chromium V8 Out of Bounds Write Vulnerability KEVCVSS 8.8Google | Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … |
| CVE-2026-86950 | Apple Multiple Products Out-of-Bounds Write Vulnerability KEVCVSS 8.8Apple | Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. |
| CVE-2026-86218 | N-able N-central Static Code Injection Vulnerability KEVCVSS 9.8N-able | N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. |
| CVE-2026-86060 | MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability KEVCVSS 9.8MikroTik | MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS… |
| CVE-2026-85880 | Microsoft Windows Heap-Based Buffer Overflow Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. |
| CVE-2026-85706 | GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability KEVCVSS 10.0GitLab | GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an i… |
| CVE-2026-85102 | Check Point Multiple Products Improper Certificate Validation Vulnerability KEVCVSS 9.8Check Point | Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerabilit… |
| CVE-2026-85046 | Google Chromium V8 Type Confusion Vulnerability KEVCVSS 8.8Google | Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. … |
| CVE-2026-84869 | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability KEVCVSS 9.9ConnectWise | ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and exe… |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability KEVCVSS 9.8Citrix | Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to… |
| CVE-2026-8398 | Daemon Tools Lite Embedded Malicious Code Vulnerability KEVCVSS 9.8Daemon | Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability. |
| CVE-2026-83549 | SonicWall SMA1000 Appliances OS Command Injection Vulnerability KEVCVSS 7.8SonicWall | SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbit… |
| CVE-2026-83548 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability KEVCVSS 10.0SonicWall | SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized acces… |
| CVE-2026-82329 | JFrog Artifactory Improper Authentication Vulnerability KEVCVSS 9.8JFrog | JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access … |
| CVE-2026-82078 | PaperCut NG/MF Unsafe Reflection Vulnerability KEVCVSS 9.1PaperCut | PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java byt… |
| CVE-2026-81963 | Microsoft Windows Link Following Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM. |
| CVE-2026-81578 | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability KEVCVSS 9.8PaperCut | PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system c… |
| CVE-2026-8037 | Progress LoadMaster Command Injection Vulnerability KEVCVSS 9.6Progress | Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster applian… |
| CVE-2026-76504 | Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability KEVCVSS 9.8Cisco | Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with priv… |
| CVE-2026-76461 | Cisco Secure Email Gateway SQL Injection Vulnerability KEVCVSS 9.8Cisco | Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to exec… |
| CVE-2026-76460 | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability KEVCVSS 10.0Cisco | Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could al… |
| CVE-2026-75650 | Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability KEVCVSS 10.0Adobe | Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attac… |
| CVE-2026-7473 | Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability KEVCVSS 5.8Arista | Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwa… |
| CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability KEVCVSS 8.9Synacor | Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP re… |
| CVE-2026-72898 | Metabase SQL Injection Vulnerability KEVCVSS 10.0Metabase | Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, … |
| CVE-2026-7273 | Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability KEVCVSS 8.8Zyxel | Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to … |
| CVE-2026-72530 | TrueConf Server Code Injection Vulnerability KEVCVSS 9.0TrueConf | TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a special… |
| CVE-2026-72529 | TrueConf Server Missing Authentication for Critical Function Vulnerability KEVCVSS 9.8TrueConf | TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via … |
| CVE-2026-71362 | Adobe Commerce and Magento Incorrect Authorization Vulnerability KEVCVSS 9.1Adobe | Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated acces… |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability KEVCVSS 7.2Ivanti | Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access … |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability KEVCVSS 7.0Microsoft | Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locall… |
| CVE-2026-67279 | Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability KEVCVSS 6.5MikroTik | Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel an… |
| CVE-2026-67277 | MikroTik RouterOS Missing Authentication for Critical Function Vulnerability KEVCVSS 8.2MikroTik | MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btes… |
| CVE-2026-66384 | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability KEVCVSS 5.3JFrog | JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data out… |
| CVE-2026-65660 | Microsoft SharePoint Code Injection Vulnerability KEVCVSS 8.8Microsoft | Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. |
| CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability KEVCVSS 9.8Apple | Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid crede… |
| CVE-2026-64849 | CVE-2026-64849 KEVCVSS 9.3lfprojects | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the una… |
| CVE-2026-63077 | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability KEVCVSS 9.8JetBrains | JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling prot… |
| CVE-2026-63030 | WordPress Core Interpretation Conflict Vulnerability KEVCVSS 9.8WordPress | WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This … |