51,518 indexed

CVECVE vulnerabilities

51,518 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 51–100 of 1,656 in KEV · page 2 of 34

IDTitleSummary
CVE-2026-32201Microsoft SharePoint Server Improper Input Validation Vulnerability
KEVCVSS 6.5Microsoft
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-31431Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
KEVCVSS 7.8Linux
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
CVE-2026-3055Citrix NetScaler Out-of-Bounds Read Vulnerability
KEVCVSS 9.8Citrix
Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnera…
CVE-2026-28318SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
KEVCVSS 7.5SolarWinds
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate h…
CVE-2026-25108Soliton Systems K.K FileZen OS Command Injection Vulnerability
KEVCVSS 8.8Soliton Systems K.K
Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP requ…
CVE-2026-25089Fortinet FortiSandbox OS Command Injection Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execu…
CVE-2026-24858Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker …
CVE-2026-24423SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability
KEVCVSS 9.8SmarterTools
SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to…
CVE-2026-2441Google Chromium CSS Use-After-Free Vulnerability
KEVCVSS 8.8Google
Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. …
CVE-2026-24061GNU InetUtils Argument Injection Vulnerability
KEVCVSS 9.8GNU
GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER envi…
CVE-2026-23760SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
KEVCVSS 9.8SmarterTools
SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password…
CVE-2026-22769Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
KEVCVSS 10.0Dell
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to …
CVE-2026-22719Broadcom VMware Aria Operations Command Injection Vulnerability
KEVCVSS 8.1Broadcom
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacke…
CVE-2026-21643Fortinet FortiClient EMS SQL Injection Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifi…
CVE-2026-21533Microsoft Windows Improper Privilege Management Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges…
CVE-2026-21525Microsoft Windows NULL Pointer Dereference Vulnerability
KEVCVSS 6.2Microsoft
Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.
CVE-2026-21519Microsoft Windows Type Confusion Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2026-21514Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privilege…
CVE-2026-21513Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
KEVCVSS 8.8Microsoft
Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a …
CVE-2026-21510Microsoft Windows Shell Protection Mechanism Failure Vulnerability
KEVCVSS 8.8Microsoft
Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a net…
CVE-2026-21509Microsoft Office Security Feature Bypass Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow …
CVE-2026-21385Qualcomm Multiple Chipsets Memory Corruption Vulnerability
KEVCVSS 7.8Qualcomm
Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation.
CVE-2026-20963Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
KEVCVSS 9.8Microsoft
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2026-20805Microsoft Windows Information Disclosure Vulnerability
KEVCVSS 5.5Microsoft
Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
CVE-2026-20700Apple Multiple Buffer Overflow Vulnerability
KEVCVSS 7.8Apple
Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow…
CVE-2026-20316Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
KEVCVSS 5.3Cisco
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allo…
CVE-2026-20262Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
KEVCVSS 6.5Cisco
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overw…
CVE-2026-20253Splunk Enterprise Missing Authentication for Critical Function Vulnerability
KEVCVSS 9.8Splunk
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitra…
CVE-2026-20245Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
KEVCVSS 7.8Cisco
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an auth…
CVE-2026-20230Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
KEVCVSS 8.6Cisco
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side re…
CVE-2026-20182Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
KEVCVSS 10.0Cisco
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authenticat…
CVE-2026-20133Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
KEVCVSS 7.5Cisco
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view se…
CVE-2026-20131Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
KEVCVSS 10.0Cisco
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data v…
CVE-2026-20128Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
KEVCVSS 7.5Cisco
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user …
CVE-2026-20127Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
KEVCVSS 10.0Cisco
Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerab…
CVE-2026-20122Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
KEVCVSS 5.4Cisco
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected syst…
CVE-2026-20045Cisco Unified Communications Products Code Injection Vulnerability
KEVCVSS 9.8Cisco
Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communicatio…
CVE-2026-1731BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
KEVCVSS 9.8BeyondTrust
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthe…
CVE-2026-16812Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
KEVCVSS 10.0Arista
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionali…
CVE-2026-16232Check Point SmartConsole Improper Authentication Vulnerability
KEVCVSS 9.1Check Point
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login …
CVE-2026-1603Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
KEVCVSS 7.5Ivanti
Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated atta…
CVE-2026-15410SonicWall SMA1000 Appliances Code Injection Vulnerability
KEVCVSS 7.2SonicWall
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as ad…
CVE-2026-15409SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
KEVCVSS 10.0SonicWall
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the ap…
CVE-2026-1340Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
KEVCVSS 9.8Ivanti
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-1281Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
KEVCVSS 9.8Ivanti
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-12569PTC Windchill and FlexPLM Improper Input Validation Vulnerability
KEVCVSS 9.8PTC
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending…
CVE-2026-11645Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
KEVCVSS 8.8Google
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …
CVE-2026-10520Ivanti Sentry OS Command Injection Vulnerability
KEVCVSS 10.0Ivanti
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve r…
CVE-2026-0770Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
KEVCVSS 9.8Langflow
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected …
CVE-2026-0300Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
KEVCVSS 9.8Palo Alto Networks
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an una…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.