86,884 indexed
CVECVE vulnerabilities
86,884 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 151–200 of 1,734 in KEV · page 4 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2026-18577 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability KEVCVSS 8.1N-able | N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This … |
| CVE-2026-18556 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability KEVCVSS 7.4N-able | N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. |
| CVE-2026-1731 | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability KEVCVSS 9.8BeyondTrust | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthe… |
| CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability KEVCVSS 10.0Arista | Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionali… |
| CVE-2026-16232 | Check Point SmartConsole Improper Authentication Vulnerability KEVCVSS 9.8Check Point | Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login … |
| CVE-2026-1603 | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability KEVCVSS 7.5Ivanti | Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated atta… |
| CVE-2026-15410 | SonicWall SMA1000 Appliances Code Injection Vulnerability KEVCVSS 7.2SonicWall | SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as ad… |
| CVE-2026-15409 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability KEVCVSS 10.0SonicWall | SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the ap… |
| CVE-2026-1340 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability KEVCVSS 9.8Ivanti | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. |
| CVE-2026-1281 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability KEVCVSS 9.8Ivanti | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. |
| CVE-2026-12569 | PTC Windchill and FlexPLM Improper Input Validation Vulnerability KEVCVSS 9.8PTC | PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending… |
| CVE-2026-11645 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability KEVCVSS 8.8Google | Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … |
| CVE-2026-10520 | Ivanti Sentry OS Command Injection Vulnerability KEVCVSS 10.0Ivanti | Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve r… |
| CVE-2026-104286 | Fortinet FortiMail Path Traversal Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated atta… |
| CVE-2026-102490 | Zammad GmbH Zammad Improper Privilege Management Vulnerability KEVCVSS 9.8Zammad GmbH | Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerabil… |
| CVE-2026-102489 | Zammad GmbH Zammad Session Fixation Vulnerability KEVCVSS 9.8Zammad GmbH | Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with … |
| CVE-2026-0770 | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability KEVCVSS 9.8Langflow | Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected … |
| CVE-2026-0300 | Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability KEVCVSS 9.8Palo Alto Networks | Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an una… |
| CVE-2026-0257 | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability KEVCVSS 9.1Palo Alto Networks | Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized V… |
| CVE-2025-9377 | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability KEVCVSS 7.2TP-Link | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could … |
| CVE-2025-9242 | WatchGuard Firebox Out-of-Bounds Write Vulnerability KEVCVSS 9.8WatchGuard | WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary c… |
| CVE-2025-8876 | N-able N-Central Command Injection Vulnerability KEVCVSS 8.8N-able | N-able N-Central contains a command injection vulnerability via improper sanitization of user input. |
| CVE-2025-8875 | N-able N-Central Insecure Deserialization Vulnerability KEVCVSS 7.8N-able | N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution. |
| CVE-2025-8110 | Gogs Path Traversal Vulnerability KEVCVSS 8.8Gogs | Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution. |
| CVE-2025-8088 | RARLAB WinRAR Path Traversal Vulnerability KEVCVSS 8.8RARLAB | RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary … |
| CVE-2025-7775 | Citrix NetScaler Memory Overflow Vulnerability KEVCVSS 9.8Citrix | Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service. |
| CVE-2025-68686 | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability KEVCVSS 5.9Fortinet | Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypa… |
| CVE-2025-68645 | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability KEVCVSS 8.8Synacor | Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/r… |
| CVE-2025-68613 | n8n Improper Control of Dynamically-Managed Code Resources Vulnerability KEVCVSS 8.8n8n | n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code e… |
| CVE-2025-68461 | RoundCube Webmail Cross-site Scripting Vulnerability KEVCVSS 6.1Roundcube | RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document. |
| CVE-2025-67038 | Lantronix EDS5000 Code Injection Vulnerability KEVCVSS 9.8Lantronix | Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected comm… |
| CVE-2025-66644 | Array Networks ArrayOS AG OS Command Injection Vulnerability KEVCVSS 9.8Array Networks | Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands. |
| CVE-2025-66376 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability KEVCVSS 7.2Synacor | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CS… |
| CVE-2025-6558 | Google Chromium ANGLE and GPU Improper Input Validation Vulnerability KEVCVSS 8.8Google | Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a… |
| CVE-2025-6554 | Google Chromium V8 Type Confusion Vulnerability KEVCVSS 8.1Google | Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vul… |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability KEVCVSS 9.8Citrix | Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured… |
| CVE-2025-64446 | Fortinet FortiWeb Path Traversal Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system … |
| CVE-2025-64328 | Sangoma FreePBX OS Command Injection Vulnerability KEVCVSS 7.2Sangoma | Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticate… |
| CVE-2025-62593 | Ray-Project Ray Code Injection Vulnerability KEVCVSS 8.8Ray-Project | Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to th… |
| CVE-2025-62221 | Microsoft Windows Use After Free Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally. |
| CVE-2025-62215 | Microsoft Windows Race Condition Vulnerability KEVCVSS 7.0Microsoft | Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful expl… |
| CVE-2025-6218 | RARLAB WinRAR Path Traversal Vulnerability KEVCVSS 7.8RARLAB | RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user. |
| CVE-2025-6205 | Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability KEVCVSS 9.1Dassault Systèmes | Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application. |
| CVE-2025-6204 | Dassault Systèmes DELMIA Apriso Code Injection Vulnerability KEVCVSS 8.0Dassault Systèmes | Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code. |
| CVE-2025-61932 | Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability KEVCVSS 9.8Motex | Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary … |
| CVE-2025-61884 | Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability KEVCVSS 7.5Oracle | Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remo… |
| CVE-2025-61882 | Oracle E-Business Suite Unspecified Vulnerability KEVCVSS 9.8Oracle | Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with… |
| CVE-2025-61757 | Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability KEVCVSS 9.8Oracle | Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity… |
| CVE-2025-60710 | Microsoft Windows Link Following Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows contains a link following vulnerability that allows for privilege escalation |
| CVE-2025-59718 | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unaut… |