86,884 indexed

CVECVE vulnerabilities

86,884 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 101–150 of 1,734 in KEV · page 3 of 35

IDTitleSummary
CVE-2026-34908Ubiquiti UniFi OS Improper Access Control Vulnerability
KEVCVSS 10.0Ubiquiti
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes…
CVE-2026-34621Adobe Acrobat and Reader Prototype Pollution Vulnerability
KEVCVSS 8.6Adobe
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
KEVCVSS 7.5Apache
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained…
CVE-2026-34197Apache ActiveMQ Improper Input Validation Vulnerability
KEVCVSS 8.8Apache
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CVE-2026-33825Microsoft Defender Insufficient Granularity of Access Control Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
KEVCVSS 9.8Microsoft
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
CVE-2026-33634Aquasecurity Trivy Embedded Malicious Code Vulnerability
KEVCVSS 8.8Aquasecurity
Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, includ…
CVE-2026-33017Langflow Code Injection Vulnerability
KEVCVSS 9.8Langflow
Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
CVE-2026-32202Microsoft Windows Protection Mechanism Failure Vulnerability
KEVCVSS 4.3Microsoft
Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32201Microsoft SharePoint Server Improper Input Validation Vulnerability
KEVCVSS 6.5Microsoft
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-31431Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
KEVCVSS 7.8Linux
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
CVE-2026-3055Citrix NetScaler Out-of-Bounds Read Vulnerability
KEVCVSS 9.8Citrix
Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnera…
CVE-2026-28318SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
KEVCVSS 7.5SolarWinds
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate h…
CVE-2026-25108Soliton Systems K.K FileZen OS Command Injection Vulnerability
KEVCVSS 8.8Soliton Systems K.K
Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP requ…
CVE-2026-25089Fortinet FortiSandbox OS Command Injection Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execu…
CVE-2026-24858Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker …
CVE-2026-24423SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability
KEVCVSS 9.8SmarterTools
SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to…
CVE-2026-2441Google Chromium CSS Use-After-Free Vulnerability
KEVCVSS 8.8Google
Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. …
CVE-2026-24061GNU InetUtils Argument Injection Vulnerability
KEVCVSS 9.8GNU
GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER envi…
CVE-2026-23760SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
KEVCVSS 9.8SmarterTools
SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password…
CVE-2026-22769Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
KEVCVSS 10.0Dell
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to …
CVE-2026-22719Broadcom VMware Aria Operations Command Injection Vulnerability
KEVCVSS 8.1Broadcom
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacke…
CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
KEVCVSS 10.0Oracle
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion…
CVE-2026-21643Fortinet FortiClient EMS SQL Injection Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifi…
CVE-2026-21533Microsoft Windows Improper Privilege Management Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges…
CVE-2026-21525Microsoft Windows NULL Pointer Dereference Vulnerability
KEVCVSS 6.2Microsoft
Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.
CVE-2026-21519Microsoft Windows Type Confusion Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2026-21514Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privilege…
CVE-2026-21513Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
KEVCVSS 8.8Microsoft
Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a …
CVE-2026-21510Microsoft Windows Shell Protection Mechanism Failure Vulnerability
KEVCVSS 8.8Microsoft
Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a net…
CVE-2026-21509Microsoft Office Security Feature Bypass Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow …
CVE-2026-21385Qualcomm Multiple Chipsets Memory Corruption Vulnerability
KEVCVSS 7.8Qualcomm
Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation.
CVE-2026-20963Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
KEVCVSS 9.8Microsoft
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2026-20805Microsoft Windows Information Disclosure Vulnerability
KEVCVSS 5.5Microsoft
Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
CVE-2026-20700Apple Multiple Buffer Overflow Vulnerability
KEVCVSS 7.8Apple
Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow…
CVE-2026-20349Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
KEVCVSS 8.6Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an un…
CVE-2026-20316Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
KEVCVSS 5.3Cisco
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allo…
CVE-2026-20262Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
KEVCVSS 6.5Cisco
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overw…
CVE-2026-20253Splunk Enterprise Missing Authentication for Critical Function Vulnerability
KEVCVSS 9.8Splunk
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitra…
CVE-2026-20245Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
KEVCVSS 7.8Cisco
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an auth…
CVE-2026-20230Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
KEVCVSS 8.6Cisco
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side re…
CVE-2026-20182Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
KEVCVSS 10.0Cisco
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authenticat…
CVE-2026-20133Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
KEVCVSS 7.5Cisco
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view se…
CVE-2026-20131Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
KEVCVSS 10.0Cisco
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data v…
CVE-2026-20128Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
KEVCVSS 7.5Cisco
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user …
CVE-2026-20127Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
KEVCVSS 10.0Cisco
Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerab…
CVE-2026-20122Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
KEVCVSS 5.4Cisco
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected syst…
CVE-2026-20079Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
KEVCVSS 10.0Cisco
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alt…
CVE-2026-20045Cisco Unified Communications Products Code Injection Vulnerability
KEVCVSS 9.8Cisco
Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communicatio…
CVE-2026-19490Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
KEVCVSS 9.8Citrix
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.