86,884 indexed

CVECVE vulnerabilities

86,884 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 151–200 of 1,734 in KEV · page 4 of 35

IDTitleSummary
CVE-2026-18577N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
KEVCVSS 8.1N-able
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This …
CVE-2026-18556N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
KEVCVSS 7.4N-able
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
CVE-2026-1731BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
KEVCVSS 9.8BeyondTrust
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthe…
CVE-2026-16812Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
KEVCVSS 10.0Arista
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionali…
CVE-2026-16232Check Point SmartConsole Improper Authentication Vulnerability
KEVCVSS 9.8Check Point
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login …
CVE-2026-1603Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
KEVCVSS 7.5Ivanti
Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated atta…
CVE-2026-15410SonicWall SMA1000 Appliances Code Injection Vulnerability
KEVCVSS 7.2SonicWall
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as ad…
CVE-2026-15409SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
KEVCVSS 10.0SonicWall
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the ap…
CVE-2026-1340Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
KEVCVSS 9.8Ivanti
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-1281Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
KEVCVSS 9.8Ivanti
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-12569PTC Windchill and FlexPLM Improper Input Validation Vulnerability
KEVCVSS 9.8PTC
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending…
CVE-2026-11645Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
KEVCVSS 8.8Google
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …
CVE-2026-10520Ivanti Sentry OS Command Injection Vulnerability
KEVCVSS 10.0Ivanti
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve r…
CVE-2026-104286Fortinet FortiMail Path Traversal Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated atta…
CVE-2026-102490Zammad GmbH Zammad Improper Privilege Management Vulnerability
KEVCVSS 9.8Zammad GmbH
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerabil…
CVE-2026-102489Zammad GmbH Zammad Session Fixation Vulnerability
KEVCVSS 9.8Zammad GmbH
Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with …
CVE-2026-0770Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
KEVCVSS 9.8Langflow
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected …
CVE-2026-0300Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
KEVCVSS 9.8Palo Alto Networks
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an una…
CVE-2026-0257Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
KEVCVSS 9.1Palo Alto Networks
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized V…
CVE-2025-9377TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
KEVCVSS 7.2TP-Link
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could …
CVE-2025-9242WatchGuard Firebox Out-of-Bounds Write Vulnerability
KEVCVSS 9.8WatchGuard
WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary c…
CVE-2025-8876N-able N-Central Command Injection Vulnerability
KEVCVSS 8.8N-able
N-able N-Central contains a command injection vulnerability via improper sanitization of user input.
CVE-2025-8875N-able N-Central Insecure Deserialization Vulnerability
KEVCVSS 7.8N-able
N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.
CVE-2025-8110Gogs Path Traversal Vulnerability
KEVCVSS 8.8Gogs
Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
CVE-2025-8088RARLAB WinRAR Path Traversal Vulnerability
KEVCVSS 8.8RARLAB
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary …
CVE-2025-7775Citrix NetScaler Memory Overflow Vulnerability
KEVCVSS 9.8Citrix
Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.
CVE-2025-68686Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
KEVCVSS 5.9Fortinet
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypa…
CVE-2025-68645Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
KEVCVSS 8.8Synacor
Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/r…
CVE-2025-68613n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
KEVCVSS 8.8n8n
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code e…
CVE-2025-68461RoundCube Webmail Cross-site Scripting Vulnerability
KEVCVSS 6.1Roundcube
RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
CVE-2025-67038Lantronix EDS5000 Code Injection Vulnerability
KEVCVSS 9.8Lantronix
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected comm…
CVE-2025-66644Array Networks ArrayOS AG OS Command Injection Vulnerability
KEVCVSS 9.8Array Networks
Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.
CVE-2025-66376Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
KEVCVSS 7.2Synacor
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CS…
CVE-2025-6558Google Chromium ANGLE and GPU Improper Input Validation Vulnerability
KEVCVSS 8.8Google
Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a…
CVE-2025-6554Google Chromium V8 Type Confusion Vulnerability
KEVCVSS 8.1Google
Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vul…
CVE-2025-6543Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
KEVCVSS 9.8Citrix
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured…
CVE-2025-64446Fortinet FortiWeb Path Traversal Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system …
CVE-2025-64328Sangoma FreePBX OS Command Injection Vulnerability
KEVCVSS 7.2Sangoma
Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticate…
CVE-2025-62593Ray-Project Ray Code Injection Vulnerability
KEVCVSS 8.8Ray-Project
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to th…
CVE-2025-62221Microsoft Windows Use After Free Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.
CVE-2025-62215Microsoft Windows Race Condition Vulnerability
KEVCVSS 7.0Microsoft
Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful expl…
CVE-2025-6218RARLAB WinRAR Path Traversal Vulnerability
KEVCVSS 7.8RARLAB
RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
CVE-2025-6205Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability
KEVCVSS 9.1Dassault Systèmes
Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application.
CVE-2025-6204Dassault Systèmes DELMIA Apriso Code Injection Vulnerability
KEVCVSS 8.0Dassault Systèmes
Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.
CVE-2025-61932Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability
KEVCVSS 9.8Motex
Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary …
CVE-2025-61884Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
KEVCVSS 7.5Oracle
Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remo…
CVE-2025-61882Oracle E-Business Suite Unspecified Vulnerability
KEVCVSS 9.8Oracle
Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with…
CVE-2025-61757Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
KEVCVSS 9.8Oracle
Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity…
CVE-2025-60710Microsoft Windows Link Following Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows contains a link following vulnerability that allows for privilege escalation
CVE-2025-59718Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unaut…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.