86,884 indexed
CVECVE vulnerabilities
86,884 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 101–150 of 1,734 in KEV · page 3 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2026-34908 | Ubiquiti UniFi OS Improper Access Control Vulnerability KEVCVSS 10.0Ubiquiti | Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes… |
| CVE-2026-34621 | Adobe Acrobat and Reader Prototype Pollution Vulnerability KEVCVSS 8.6Adobe | Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. |
| CVE-2026-34486 | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability KEVCVSS 7.5Apache | Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained… |
| CVE-2026-34197 | Apache ActiveMQ Improper Input Validation Vulnerability KEVCVSS 8.8Apache | Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. |
| CVE-2026-33825 | Microsoft Defender Insufficient Granularity of Access Control Vulnerability KEVCVSS 7.8Microsoft | Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. |
| CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability KEVCVSS 9.8Microsoft | Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution. |
| CVE-2026-33634 | Aquasecurity Trivy Embedded Malicious Code Vulnerability KEVCVSS 8.8Aquasecurity | Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, includ… |
| CVE-2026-33017 | Langflow Code Injection Vulnerability KEVCVSS 9.8Langflow | Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication. |
| CVE-2026-32202 | Microsoft Windows Protection Mechanism Failure Vulnerability KEVCVSS 4.3Microsoft | Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-32201 | Microsoft SharePoint Server Improper Input Validation Vulnerability KEVCVSS 6.5Microsoft | Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-31431 | Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability KEVCVSS 7.8Linux | Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. |
| CVE-2026-3055 | Citrix NetScaler Out-of-Bounds Read Vulnerability KEVCVSS 9.8Citrix | Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnera… |
| CVE-2026-28318 | SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability KEVCVSS 7.5SolarWinds | SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate h… |
| CVE-2026-25108 | Soliton Systems K.K FileZen OS Command Injection Vulnerability KEVCVSS 8.8Soliton Systems K.K | Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP requ… |
| CVE-2026-25089 | Fortinet FortiSandbox OS Command Injection Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execu… |
| CVE-2026-24858 | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker … |
| CVE-2026-24423 | SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability KEVCVSS 9.8SmarterTools | SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to… |
| CVE-2026-2441 | Google Chromium CSS Use-After-Free Vulnerability KEVCVSS 8.8Google | Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. … |
| CVE-2026-24061 | GNU InetUtils Argument Injection Vulnerability KEVCVSS 9.8GNU | GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER envi… |
| CVE-2026-23760 | SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability KEVCVSS 9.8SmarterTools | SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password… |
| CVE-2026-22769 | Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability KEVCVSS 10.0Dell | Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to … |
| CVE-2026-22719 | Broadcom VMware Aria Operations Command Injection Vulnerability KEVCVSS 8.1Broadcom | Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacke… |
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability KEVCVSS 10.0Oracle | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion… |
| CVE-2026-21643 | Fortinet FortiClient EMS SQL Injection Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifi… |
| CVE-2026-21533 | Microsoft Windows Improper Privilege Management Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges… |
| CVE-2026-21525 | Microsoft Windows NULL Pointer Dereference Vulnerability KEVCVSS 6.2Microsoft | Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. |
| CVE-2026-21519 | Microsoft Windows Type Confusion Vulnerability KEVCVSS 7.8Microsoft | Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. |
| CVE-2026-21514 | Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability KEVCVSS 7.8Microsoft | Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privilege… |
| CVE-2026-21513 | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability KEVCVSS 8.8Microsoft | Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a … |
| CVE-2026-21510 | Microsoft Windows Shell Protection Mechanism Failure Vulnerability KEVCVSS 8.8Microsoft | Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a net… |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability KEVCVSS 7.8Microsoft | Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow … |
| CVE-2026-21385 | Qualcomm Multiple Chipsets Memory Corruption Vulnerability KEVCVSS 7.8Qualcomm | Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. |
| CVE-2026-20963 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability KEVCVSS 9.8Microsoft | Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. |
| CVE-2026-20805 | Microsoft Windows Information Disclosure Vulnerability KEVCVSS 5.5Microsoft | Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally. |
| CVE-2026-20700 | Apple Multiple Buffer Overflow Vulnerability KEVCVSS 7.8Apple | Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow… |
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability KEVCVSS 8.6Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an un… |
| CVE-2026-20316 | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability KEVCVSS 5.3Cisco | Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allo… |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability KEVCVSS 6.5Cisco | Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overw… |
| CVE-2026-20253 | Splunk Enterprise Missing Authentication for Critical Function Vulnerability KEVCVSS 9.8Splunk | Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitra… |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability KEVCVSS 7.8Cisco | Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an auth… |
| CVE-2026-20230 | Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability KEVCVSS 8.6Cisco | Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side re… |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability KEVCVSS 10.0Cisco | Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authenticat… |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability KEVCVSS 7.5Cisco | Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view se… |
| CVE-2026-20131 | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability KEVCVSS 10.0Cisco | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data v… |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability KEVCVSS 7.5Cisco | Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user … |
| CVE-2026-20127 | Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability KEVCVSS 10.0Cisco | Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerab… |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability KEVCVSS 5.4Cisco | Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected syst… |
| CVE-2026-20079 | Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability KEVCVSS 10.0Cisco | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alt… |
| CVE-2026-20045 | Cisco Unified Communications Products Code Injection Vulnerability KEVCVSS 9.8Cisco | Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communicatio… |
| CVE-2026-19490 | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability KEVCVSS 9.8Citrix | Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance … |