51,518 indexed
CVECVE vulnerabilities
51,518 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 51–100 of 1,656 in KEV · page 2 of 34
| ID | Title | Summary |
|---|---|---|
| CVE-2026-32201 | Microsoft SharePoint Server Improper Input Validation Vulnerability KEVCVSS 6.5Microsoft | Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-31431 | Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability KEVCVSS 7.8Linux | Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. |
| CVE-2026-3055 | Citrix NetScaler Out-of-Bounds Read Vulnerability KEVCVSS 9.8Citrix | Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnera… |
| CVE-2026-28318 | SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability KEVCVSS 7.5SolarWinds | SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate h… |
| CVE-2026-25108 | Soliton Systems K.K FileZen OS Command Injection Vulnerability KEVCVSS 8.8Soliton Systems K.K | Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP requ… |
| CVE-2026-25089 | Fortinet FortiSandbox OS Command Injection Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execu… |
| CVE-2026-24858 | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker … |
| CVE-2026-24423 | SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability KEVCVSS 9.8SmarterTools | SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to… |
| CVE-2026-2441 | Google Chromium CSS Use-After-Free Vulnerability KEVCVSS 8.8Google | Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. … |
| CVE-2026-24061 | GNU InetUtils Argument Injection Vulnerability KEVCVSS 9.8GNU | GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER envi… |
| CVE-2026-23760 | SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability KEVCVSS 9.8SmarterTools | SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password… |
| CVE-2026-22769 | Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability KEVCVSS 10.0Dell | Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to … |
| CVE-2026-22719 | Broadcom VMware Aria Operations Command Injection Vulnerability KEVCVSS 8.1Broadcom | Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacke… |
| CVE-2026-21643 | Fortinet FortiClient EMS SQL Injection Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifi… |
| CVE-2026-21533 | Microsoft Windows Improper Privilege Management Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges… |
| CVE-2026-21525 | Microsoft Windows NULL Pointer Dereference Vulnerability KEVCVSS 6.2Microsoft | Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. |
| CVE-2026-21519 | Microsoft Windows Type Confusion Vulnerability KEVCVSS 7.8Microsoft | Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. |
| CVE-2026-21514 | Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability KEVCVSS 7.8Microsoft | Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privilege… |
| CVE-2026-21513 | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability KEVCVSS 8.8Microsoft | Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a … |
| CVE-2026-21510 | Microsoft Windows Shell Protection Mechanism Failure Vulnerability KEVCVSS 8.8Microsoft | Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a net… |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability KEVCVSS 7.8Microsoft | Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow … |
| CVE-2026-21385 | Qualcomm Multiple Chipsets Memory Corruption Vulnerability KEVCVSS 7.8Qualcomm | Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. |
| CVE-2026-20963 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability KEVCVSS 9.8Microsoft | Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. |
| CVE-2026-20805 | Microsoft Windows Information Disclosure Vulnerability KEVCVSS 5.5Microsoft | Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally. |
| CVE-2026-20700 | Apple Multiple Buffer Overflow Vulnerability KEVCVSS 7.8Apple | Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow… |
| CVE-2026-20316 | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability KEVCVSS 5.3Cisco | Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allo… |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability KEVCVSS 6.5Cisco | Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overw… |
| CVE-2026-20253 | Splunk Enterprise Missing Authentication for Critical Function Vulnerability KEVCVSS 9.8Splunk | Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitra… |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability KEVCVSS 7.8Cisco | Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an auth… |
| CVE-2026-20230 | Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability KEVCVSS 8.6Cisco | Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side re… |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability KEVCVSS 10.0Cisco | Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authenticat… |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability KEVCVSS 7.5Cisco | Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view se… |
| CVE-2026-20131 | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability KEVCVSS 10.0Cisco | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data v… |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability KEVCVSS 7.5Cisco | Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user … |
| CVE-2026-20127 | Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability KEVCVSS 10.0Cisco | Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerab… |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability KEVCVSS 5.4Cisco | Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected syst… |
| CVE-2026-20045 | Cisco Unified Communications Products Code Injection Vulnerability KEVCVSS 9.8Cisco | Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communicatio… |
| CVE-2026-1731 | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability KEVCVSS 9.8BeyondTrust | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthe… |
| CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability KEVCVSS 10.0Arista | Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionali… |
| CVE-2026-16232 | Check Point SmartConsole Improper Authentication Vulnerability KEVCVSS 9.1Check Point | Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login … |
| CVE-2026-1603 | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability KEVCVSS 7.5Ivanti | Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated atta… |
| CVE-2026-15410 | SonicWall SMA1000 Appliances Code Injection Vulnerability KEVCVSS 7.2SonicWall | SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as ad… |
| CVE-2026-15409 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability KEVCVSS 10.0SonicWall | SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the ap… |
| CVE-2026-1340 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability KEVCVSS 9.8Ivanti | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. |
| CVE-2026-1281 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability KEVCVSS 9.8Ivanti | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. |
| CVE-2026-12569 | PTC Windchill and FlexPLM Improper Input Validation Vulnerability KEVCVSS 9.8PTC | PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending… |
| CVE-2026-11645 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability KEVCVSS 8.8Google | Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … |
| CVE-2026-10520 | Ivanti Sentry OS Command Injection Vulnerability KEVCVSS 10.0Ivanti | Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve r… |
| CVE-2026-0770 | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability KEVCVSS 9.8Langflow | Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected … |
| CVE-2026-0300 | Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability KEVCVSS 9.8Palo Alto Networks | Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an una… |