OFFICIAL SOURCE, DECISION-READY CONTEXT
Known Exploited
Vulnerability Catalog
Daily CISA KEV entries, organized for outside-in technology triage. Source facts remain distinct from BuiltWith observations and analyst decisions.
| CVE | Vendor / product | Vulnerability | Added | Due |
|---|---|---|---|---|
| CVE-2026-16232 | Check Point SmartConsole | Check Point SmartConsole Improper Authentication Vulnerability | Jul 22, 2026 | Jul 25, 2026 |
| CVE-2026-50522 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | Jul 22, 2026 | Jul 25, 2026 |
| CVE-2026-60137 | WordPress Core | WordPress Core SQL Injection Vulnerability | Jul 21, 2026 | Aug 4, 2026 |
| CVE-2026-63030 | WordPress Core | WordPress Core Interpretation Conflict Vulnerability | Jul 21, 2026 | Jul 24, 2026 |
| CVE-2026-0770 | Langflow Langflow | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | Jul 21, 2026 | Jul 24, 2026 |
| CVE-2021-27137 | DD-WRT DD-WRT | DD-WRT Stack-Based Buffer Overflow Vulnerability | Jul 21, 2026 | Jul 24, 2026 |
| CVE-2026-58644 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | Jul 16, 2026 | Jul 19, 2026 |
| CVE-2026-25089 | Fortinet FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | Jul 16, 2026 | Jul 19, 2026 |
| CVE-2026-39808 | Fortinet FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | Jul 16, 2026 | Jul 19, 2026 |
| CVE-2026-46817 | Oracle E-Business Suite | Oracle E-Business Suite Improper Privilege Management Vulnerability | Jul 15, 2026 | Jul 18, 2026 |
| CVE-2023-4346 | KNX Association KNX Protocol Connection Authorization Option 1 | KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability | Jul 15, 2026 | Jul 29, 2026 |
| CVE-2026-56155 | Microsoft Active Directory Federation Services | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | Jul 14, 2026 | Jul 28, 2026 |
| CVE-2026-56164 | Microsoft SharePoint Server | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | Jul 14, 2026 | Jul 17, 2026 |
| CVE-2026-15409 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | Jul 14, 2026 | Jul 17, 2026 |
| CVE-2026-15410 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances Code Injection Vulnerability | Jul 14, 2026 | Jul 17, 2026 |
| CVE-2008-4128 | Cisco IOS | Cisco IOS Cross-Site Request Forgery Vulnerability | Jul 13, 2026 | Jul 16, 2026 |
| CVE-2026-56291 | Balbooa Forms | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | Jul 10, 2026 | Jul 13, 2026 |
| CVE-2026-48939 | iCagenda iCagenda | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | Jul 10, 2026 | Jul 13, 2026 |
| CVE-2026-48908 | JoomShaper SP Page Builder | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | Jul 7, 2026 | Jul 10, 2026 |
| CVE-2026-55255 | Langflow Langflow | Langflow Authorization Bypass Through User-Controlled Key Vulnerability | Jul 7, 2026 | Jul 10, 2026 |
| CVE-2026-56290 | Joomlack Page Builder | Joomlack Page Builder Improper Access Control Vulnerability | Jul 7, 2026 | Jul 10, 2026 |
| CVE-2026-48282 | Adobe ColdFusion | Adobe ColdFusion Path Traversal Vulnerability | Jul 7, 2026 | Jul 10, 2026 |
| CVE-2026-45659 | Microsoft SharePoint Server | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | Jul 1, 2026 | Jul 4, 2026 |
| CVE-2026-48558 | SimpleHelp SimpleHelp | SimpleHelp Authentication Bypass Vulnerability | Jun 29, 2026 | Jul 2, 2026 |
| CVE-2026-12569 | PTC Windchill and FlexPLM | PTC Windchill and FlexPLM Improper Input Validation Vulnerability | Jun 25, 2026 | Jun 28, 2026 |
| CVE-2026-20230 | Cisco Unified Communications Manager | Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability | Jun 25, 2026 | Jun 28, 2026 |
| CVE-2025-67038 | Lantronix EDS5000 | Lantronix EDS5000 Code Injection Vulnerability | Jun 23, 2026 | Jun 26, 2026 |
| CVE-2026-34910 | Ubiquiti UniFi OS | Ubiquiti UniFi OS Improper Input Validation Vulnerability | Jun 23, 2026 | Jun 26, 2026 |
| CVE-2026-34909 | Ubiquiti UniFi OS | Ubiquiti UniFi OS Path Traversal Vulnerability | Jun 23, 2026 | Jun 26, 2026 |
| CVE-2026-34908 | Ubiquiti UniFi OS | Ubiquiti UniFi OS Improper Access Control Vulnerability | Jun 23, 2026 | Jun 26, 2026 |
| CVE-2026-20253 | Splunk Enterprise | Splunk Enterprise Missing Authentication for Critical Function Vulnerability | Jun 18, 2026 | Jun 21, 2026 |
| CVE-2026-48907 | Widget Factory Joomla Content Editor | Widget Factory Joomla Content Editor Improper Access Control Vulnerability | Jun 16, 2026 | Jun 19, 2026 |
| CVE-2026-54420 | LiteSpeed cPanel Plugin | LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability | Jun 15, 2026 | Jun 18, 2026 |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability | Jun 15, 2026 | Jun 29, 2026 |
| CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools | Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability | Jun 12, 2026 | Jun 15, 2026 |
| CVE-2026-10520 | Ivanti Sentry | Ivanti Sentry OS Command Injection Vulnerability | Jun 11, 2026 | Jun 14, 2026 |
| CVE-2026-11645 | Google Chromium V8 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | Jun 9, 2026 | Jun 23, 2026 |
| CVE-2026-7473 | Arista Extensible Operating System | Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability | Jun 9, 2026 | Jun 23, 2026 |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability | Jun 9, 2026 | Jun 23, 2026 |
| CVE-2026-42271 | BerriAI LiteLLM | BerriAI LiteLLM Command Injection Vulnerability | Jun 8, 2026 | Jun 22, 2026 |
| CVE-2026-50751 | Check Point Security Gateway | Check Point Security Gateway Improper Authentication Vulnerability | Jun 8, 2026 | Jun 11, 2026 |
| CVE-2026-28318 | SolarWinds Serv-U | SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability | Jun 5, 2026 | Jun 19, 2026 |
| CVE-2026-45247 | Mirasvit Mirasvit Full Page Cache Warmer | Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability | Jun 3, 2026 | Jun 6, 2026 |
| CVE-2022-0492 | Linux Kernel | Linux Kernel Improper Authentication Vulnerability | Jun 2, 2026 | Jun 5, 2026 |
| CVE-2025-48595 | Android Framework | Android Framework Integer Overflow Vulnerability | Jun 2, 2026 | Jun 5, 2026 |
| CVE-2024-21182 | Oracle WebLogic Server | Oracle WebLogic Server Unspecified Vulnerability | Jun 1, 2026 | Jun 4, 2026 |
| CVE-2026-0257 | Palo Alto Networks PAN-OS | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | May 29, 2026 | Jun 1, 2026 |
| CVE-2026-48027 | Nx Nx Console | Nx Console Embedded Malicious Code Vulnerability | May 27, 2026 | Jun 10, 2026 |
| CVE-2026-45321 | TanStack TanStack | TanStack Unspecified Vulnerability | May 27, 2026 | Jun 10, 2026 |
| CVE-2026-8398 | Daemon Daemon Tools Lite | Daemon Tools Lite Embedded Malicious Code Vulnerability | May 27, 2026 | May 30, 2026 |
| CVE-2026-48172 | LiteSpeed cPanel Plugin | LiteSpeed cPanel Plugin Privilege Escalation Vulnerability | May 26, 2026 | May 29, 2026 |
| CVE-2026-9082 | Drupal Core | Drupal Core SQL Injection Vulnerability | May 22, 2026 | May 27, 2026 |
| CVE-2025-34291 | Langflow Langflow | Langflow Origin Validation Error Vulnerability | May 21, 2026 | Jun 4, 2026 |
| CVE-2026-34926 | Trend Micro Apex One | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | May 21, 2026 | Jun 4, 2026 |
| CVE-2008-4250 | Microsoft Windows | Microsoft Windows Buffer Overflow Vulnerability | May 20, 2026 | Jun 3, 2026 |
| CVE-2009-1537 | Microsoft DirectX | Microsoft DirectX NULL Byte Overwrite Vulnerability | May 20, 2026 | Jun 3, 2026 |
| CVE-2009-3459 | Adobe Acrobat and Reader | Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability | May 20, 2026 | Jun 3, 2026 |
| CVE-2010-0249 | Microsoft Internet Explorer | Microsoft Internet Explorer Use-After-Free Vulnerability | May 20, 2026 | Jun 3, 2026 |
| CVE-2010-0806 | Microsoft Internet Explorer | Microsoft Internet Explorer Use-After-Free Vulnerability | May 20, 2026 | Jun 3, 2026 |
| CVE-2026-41091 | Microsoft Defender | Microsoft Defender Link Following Vulnerability | May 20, 2026 | Jun 3, 2026 |
| CVE-2026-45498 | Microsoft Defender | Microsoft Defender Denial of Service Vulnerability | May 20, 2026 | Jun 3, 2026 |
| CVE-2026-42897 | Microsoft Microsoft | Microsoft Exchange Server Cross-Site Scripting Vulnerability | May 15, 2026 | May 29, 2026 |
| CVE-2026-20182 | Cisco Catalyst SD-WAN | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | May 14, 2026 | May 17, 2026 |
| CVE-2026-42208 | BerriAI LiteLLM | BerriAI LiteLLM SQL Injection Vulnerability | May 8, 2026 | May 11, 2026 |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability | May 7, 2026 | May 10, 2026 |
| CVE-2026-0300 | Palo Alto Networks PAN-OS | Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability | May 6, 2026 | May 9, 2026 |
| CVE-2026-31431 | Linux Kernel | Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability | May 1, 2026 | May 15, 2026 |
| CVE-2026-41940 | WebPros cPanel & WHM and WP2 (WordPress Squared) | WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability | Apr 30, 2026 | May 3, 2026 |
| CVE-2024-1708 | ConnectWise ScreenConnect | ConnectWise ScreenConnect Path Traversal Vulnerability | Apr 28, 2026 | May 12, 2026 |
| CVE-2026-32202 | Microsoft Windows | Microsoft Windows Protection Mechanism Failure Vulnerability | Apr 28, 2026 | May 12, 2026 |
| CVE-2025-29635 | D-Link DIR-823X | D-Link DIR-823X Command Injection Vulnerability | Apr 24, 2026 | May 8, 2026 |
| CVE-2024-7399 | Samsung MagicINFO 9 Server | Samsung MagicINFO 9 Server Path Traversal Vulnerability | Apr 24, 2026 | May 8, 2026 |
| CVE-2024-57728 | SimpleHelp SimpleHelp | SimpleHelp Path Traversal Vulnerability | Apr 24, 2026 | May 8, 2026 |
| CVE-2024-57726 | SimpleHelp SimpleHelp | SimpleHelp Missing Authorization Vulnerability | Apr 24, 2026 | May 8, 2026 |
| CVE-2026-39987 | Marimo Marimo | Marimo Remote Code Execution Vulnerability | Apr 23, 2026 | May 7, 2026 |
| CVE-2026-33825 | Microsoft Defender | Microsoft Defender Insufficient Granularity of Access Control Vulnerability | Apr 22, 2026 | May 6, 2026 |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manger | Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability | Apr 20, 2026 | Apr 23, 2026 |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | Apr 20, 2026 | Apr 23, 2026 |
| CVE-2025-2749 | Kentico Kentico Xperience | Kentico Xperience Path Traversal Vulnerability | Apr 20, 2026 | May 4, 2026 |
| CVE-2023-27351 | PaperCut NG/MF | PaperCut NG/MF Improper Authentication Vulnerability | Apr 20, 2026 | May 4, 2026 |
| CVE-2025-48700 | Synacor Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability | Apr 20, 2026 | Apr 23, 2026 |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability | Apr 20, 2026 | Apr 23, 2026 |
| CVE-2025-32975 | Quest KACE Systems Management Appliance (SMA) | Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability | Apr 20, 2026 | May 4, 2026 |
| CVE-2024-27199 | JetBrains TeamCity | JetBrains TeamCity Relative Path Traversal Vulnerability | Apr 20, 2026 | May 4, 2026 |
| CVE-2026-34197 | Apache ActiveMQ | Apache ActiveMQ Improper Input Validation Vulnerability | Apr 16, 2026 | Apr 30, 2026 |
| CVE-2009-0238 | Microsoft Office | Microsoft Office Remote Code Execution | Apr 14, 2026 | Apr 28, 2026 |
| CVE-2026-32201 | Microsoft SharePoint Server | Microsoft SharePoint Server Improper Input Validation Vulnerability | Apr 14, 2026 | Apr 28, 2026 |
| CVE-2012-1854 | Microsoft Visual Basic for Applications (VBA) | Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability | Apr 13, 2026 | Apr 27, 2026 |
| CVE-2025-60710 | Microsoft Windows | Microsoft Windows Link Following Vulnerability | Apr 13, 2026 | Apr 27, 2026 |
| CVE-2023-21529 | Microsoft Exchange Server | Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability | Apr 13, 2026 | Apr 27, 2026 |
| CVE-2023-36424 | Microsoft Windows | Microsoft Windows Out-of-Bounds Read Vulnerability | Apr 13, 2026 | Apr 27, 2026 |
| CVE-2020-9715 | Adobe Acrobat | Adobe Acrobat Use-After-Free Vulnerability | Apr 13, 2026 | Apr 27, 2026 |
| CVE-2026-21643 | Fortinet FortiClient EMS | Fortinet FortiClient EMS SQL Injection Vulnerability | Apr 13, 2026 | Apr 16, 2026 |
| CVE-2026-34621 | Adobe Acrobat and Reader | Adobe Acrobat and Reader Prototype Pollution Vulnerability | Apr 13, 2026 | Apr 27, 2026 |
| CVE-2026-1340 | Ivanti Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | Apr 8, 2026 | Apr 11, 2026 |
| CVE-2026-35616 | Fortinet FortiClient EMS | Fortinet FortiClient EMS Improper Access Control Vulnerability | Apr 6, 2026 | Apr 9, 2026 |
| CVE-2026-3502 | TrueConf Client | TrueConf Client Download of Code Without Integrity Check Vulnerability | Apr 2, 2026 | Apr 16, 2026 |
| CVE-2026-5281 | Google Dawn | Google Dawn Use-After-Free Vulnerability | Apr 1, 2026 | Apr 15, 2026 |
| CVE-2026-3055 | Citrix NetScaler | Citrix NetScaler Out-of-Bounds Read Vulnerability | Mar 30, 2026 | Apr 2, 2026 |
| CVE-2025-53521 | F5 BIG-IP | F5 BIG-IP Stack-Based Buffer Overflow Vulnerability | Mar 27, 2026 | Mar 30, 2026 |
| CVE-2026-33634 | Aquasecurity Trivy | Aquasecurity Trivy Embedded Malicious Code Vulnerability | Mar 26, 2026 | Apr 9, 2026 |
| CVE-2026-33017 | Langflow Langflow | Langflow Code Injection Vulnerability | Mar 25, 2026 | Apr 8, 2026 |
| CVE-2025-32432 | Craft CMS Craft CMS | Craft CMS Code Injection Vulnerability | Mar 20, 2026 | Apr 3, 2026 |
| CVE-2025-54068 | Laravel Livewire | Laravel Livewire Code Injection Vulnerability | Mar 20, 2026 | Apr 3, 2026 |
| CVE-2025-43510 | Apple Multiple Products | Apple Multiple Products Improper Locking Vulnerability | Mar 20, 2026 | Apr 3, 2026 |
| CVE-2025-43520 | Apple Multiple Products | Apple Multiple Products Classic Buffer Overflow Vulnerability | Mar 20, 2026 | Apr 3, 2026 |
| CVE-2025-31277 | Apple Multiple Products | Apple Multiple Products Buffer Overflow Vulnerability | Mar 20, 2026 | Apr 3, 2026 |
| CVE-2026-20131 | Cisco Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability | Mar 19, 2026 | Mar 22, 2026 |
| CVE-2025-66376 | Synacor Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability | Mar 18, 2026 | Apr 1, 2026 |
| CVE-2026-20963 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | Mar 18, 2026 | Mar 21, 2026 |
| CVE-2025-47813 | Wing FTP Server Wing FTP Server | Wing FTP Server Information Disclosure Vulnerability | Mar 16, 2026 | Mar 30, 2026 |
| CVE-2026-3910 | Google Chromium V8 | Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability | Mar 13, 2026 | Mar 27, 2026 |
| CVE-2026-3909 | Google Skia | Google Skia Out-of-Bounds Write Vulnerability | Mar 13, 2026 | Mar 27, 2026 |
| CVE-2025-68613 | n8n n8n | n8n Improper Control of Dynamically-Managed Code Resources Vulnerability | Mar 11, 2026 | Mar 25, 2026 |
| CVE-2021-22054 | Omnissa Workspace One UEM | Omnissa Workspace ONE Server-Side Request Forgery | Mar 9, 2026 | Mar 23, 2026 |
| CVE-2025-26399 | SolarWinds Web Help Desk | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | Mar 9, 2026 | Mar 12, 2026 |
| CVE-2026-1603 | Ivanti Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability | Mar 9, 2026 | Mar 23, 2026 |
| CVE-2017-7921 | Hikvision Multiple Products | Hikvision Multiple Products Improper Authentication Vulnerability | Mar 5, 2026 | Mar 26, 2026 |
| CVE-2021-22681 | Rockwell Multiple Products | Rockwell Multiple Products Insufficient Protected Credentials Vulnerability | Mar 5, 2026 | Mar 26, 2026 |
| CVE-2023-43000 | Apple Multiple Products | Apple Multiple products Use-After-Free Vulnerability | Mar 5, 2026 | Mar 26, 2026 |
| CVE-2021-30952 | Apple Multiple Products | Apple Multiple Products Integer Overflow or Wraparound Vulnerability | Mar 5, 2026 | Mar 26, 2026 |
| CVE-2023-41974 | Apple iOS and iPadOS | Apple iOS and iPadOS Use-After-Free Vulnerability | Mar 5, 2026 | Mar 26, 2026 |
| CVE-2026-22719 | Broadcom VMware Aria Operations | Broadcom VMware Aria Operations Command Injection Vulnerability | Mar 3, 2026 | Mar 24, 2026 |
| CVE-2026-21385 | Qualcomm Multiple Chipsets | Qualcomm Multiple Chipsets Memory Corruption Vulnerability | Mar 3, 2026 | Mar 24, 2026 |
| CVE-2022-20775 | Cisco SD-WAN | Cisco SD-WAN Path Traversal Vulnerability | Feb 25, 2026 | Feb 27, 2026 |
| CVE-2026-20127 | Cisco Catalyst SD-WAN Controller and Manager | Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability | Feb 25, 2026 | Feb 27, 2026 |
| CVE-2026-25108 | Soliton Systems K.K FileZen | Soliton Systems K.K FileZen OS Command Injection Vulnerability | Feb 24, 2026 | Mar 17, 2026 |
| CVE-2025-49113 | Roundcube Webmail | RoundCube Webmail Deserialization of Untrusted Data Vulnerability | Feb 20, 2026 | Mar 13, 2026 |
| CVE-2025-68461 | Roundcube Webmail | RoundCube Webmail Cross-site Scripting Vulnerability | Feb 20, 2026 | Mar 13, 2026 |
| CVE-2021-22175 | GitLab GitLab | GitLab Server-Side Request Forgery (SSRF) Vulnerability | Feb 18, 2026 | Mar 11, 2026 |
| CVE-2026-22769 | Dell RecoverPoint for Virtual Machines (RP4VMs) | Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability | Feb 18, 2026 | Feb 21, 2026 |
| CVE-2020-7796 | Synacor Zimbra Collaboration Suite | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability | Feb 17, 2026 | Mar 10, 2026 |
| CVE-2024-7694 | TeamT5 ThreatSonar Anti-Ransomware | TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability | Feb 17, 2026 | Mar 10, 2026 |
| CVE-2008-0015 | Microsoft Windows | Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability | Feb 17, 2026 | Mar 10, 2026 |
| CVE-2026-2441 | Google Chromium | Google Chromium CSS Use-After-Free Vulnerability | Feb 17, 2026 | Mar 10, 2026 |
| CVE-2026-1731 | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability | Feb 13, 2026 | Feb 16, 2026 |
| CVE-2026-20700 | Apple Multiple Products | Apple Multiple Buffer Overflow Vulnerability | Feb 12, 2026 | Mar 5, 2026 |
| CVE-2024-43468 | Microsoft Configuration Manager | Microsoft Configuration Manager SQL Injection Vulnerability | Feb 12, 2026 | Mar 5, 2026 |
| CVE-2025-15556 | Notepad++ Notepad++ | Notepad++ Download of Code Without Integrity Check Vulnerability | Feb 12, 2026 | Mar 5, 2026 |
| CVE-2025-40536 | SolarWinds Web Help Desk | SolarWinds Web Help Desk Security Control Bypass Vulnerability | Feb 12, 2026 | Feb 15, 2026 |
| CVE-2026-21513 | Microsoft Windows | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability | Feb 10, 2026 | Mar 3, 2026 |
| CVE-2026-21525 | Microsoft Windows | Microsoft Windows NULL Pointer Dereference Vulnerability | Feb 10, 2026 | Mar 3, 2026 |
| CVE-2026-21510 | Microsoft Windows | Microsoft Windows Shell Protection Mechanism Failure Vulnerability | Feb 10, 2026 | Mar 3, 2026 |
| CVE-2026-21533 | Microsoft Windows | Microsoft Windows Improper Privilege Management Vulnerability | Feb 10, 2026 | Mar 3, 2026 |
| CVE-2026-21519 | Microsoft Windows | Microsoft Windows Type Confusion Vulnerability | Feb 10, 2026 | Mar 3, 2026 |
| CVE-2026-21514 | Microsoft Office | Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability | Feb 10, 2026 | Mar 3, 2026 |
| CVE-2025-11953 | React Native Community CLI | React Native Community CLI OS Command Injection Vulnerability | Feb 5, 2026 | Feb 26, 2026 |
| CVE-2026-24423 | SmarterTools SmarterMail | SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability | Feb 5, 2026 | Feb 26, 2026 |
| CVE-2021-39935 | GitLab Community and Enterprise Editions | GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability | Feb 3, 2026 | Feb 24, 2026 |
| CVE-2025-64328 | Sangoma FreePBX | Sangoma FreePBX OS Command Injection Vulnerability | Feb 3, 2026 | Feb 24, 2026 |
| CVE-2019-19006 | Sangoma FreePBX | Sangoma FreePBX Improper Authentication Vulnerability | Feb 3, 2026 | Feb 24, 2026 |
| CVE-2025-40551 | SolarWinds Web Help Desk | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | Feb 3, 2026 | Feb 6, 2026 |
| CVE-2026-1281 | Ivanti Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | Jan 29, 2026 | Feb 1, 2026 |
| CVE-2026-24858 | Fortinet Multiple Products | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability | Jan 27, 2026 | Jan 30, 2026 |
| CVE-2018-14634 | Linux Kernel | Linux Kernel Integer Overflow Vulnerability | Jan 26, 2026 | Feb 16, 2026 |
| CVE-2025-52691 | SmarterTools SmarterMail | SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability | Jan 26, 2026 | Feb 16, 2026 |
| CVE-2026-23760 | SmarterTools SmarterMail | SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability | Jan 26, 2026 | Feb 16, 2026 |
| CVE-2026-24061 | GNU InetUtils | GNU InetUtils Argument Injection Vulnerability | Jan 26, 2026 | Feb 16, 2026 |
| CVE-2026-21509 | Microsoft Office | Microsoft Office Security Feature Bypass Vulnerability | Jan 26, 2026 | Feb 16, 2026 |
| CVE-2024-37079 | Broadcom VMware vCenter Server | Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability | Jan 23, 2026 | Feb 13, 2026 |
| CVE-2025-68645 | Synacor Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability | Jan 22, 2026 | Feb 12, 2026 |
| CVE-2025-34026 | Versa Concerto | Versa Concerto Improper Authentication Vulnerability | Jan 22, 2026 | Feb 12, 2026 |
| CVE-2025-31125 | Vite Vitejs | Vite Vitejs Improper Access Control Vulnerability | Jan 22, 2026 | Feb 12, 2026 |
| CVE-2025-54313 | Prettier eslint-config-prettier | Prettier eslint-config-prettier Embedded Malicious Code Vulnerability | Jan 22, 2026 | Feb 12, 2026 |
| CVE-2026-20045 | Cisco Unified Communications Manager | Cisco Unified Communications Products Code Injection Vulnerability | Jan 21, 2026 | Feb 11, 2026 |
| CVE-2026-20805 | Microsoft Windows | Microsoft Windows Information Disclosure Vulnerability | Jan 13, 2026 | Feb 3, 2026 |
| CVE-2025-8110 | Gogs Gogs | Gogs Path Traversal Vulnerability | Jan 12, 2026 | Feb 2, 2026 |
| CVE-2009-0556 | Microsoft Office | Microsoft Office PowerPoint Code Injection Vulnerability | Jan 7, 2026 | Jan 28, 2026 |
| CVE-2025-37164 | Hewlett Packard Enterprise (HPE) OneView | Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability | Jan 7, 2026 | Jan 28, 2026 |
| CVE-2025-14847 | MongoDB MongoDB and MongoDB Server | MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability | Dec 29, 2025 | Jan 19, 2026 |
| CVE-2023-52163 | Digiever DS-2105 Pro | Digiever DS-2105 Pro Missing Authorization Vulnerability | Dec 22, 2025 | Jan 12, 2026 |
| CVE-2025-14733 | WatchGuard Firebox | WatchGuard Firebox Out of Bounds Write Vulnerability | Dec 19, 2025 | Dec 26, 2025 |
| CVE-2025-59374 | ASUS Live Update | ASUS Live Update Embedded Malicious Code Vulnerability | Dec 17, 2025 | Jan 7, 2026 |
| CVE-2025-40602 | SonicWall SMA1000 appliance | SonicWall SMA1000 Missing Authorization Vulnerability | Dec 17, 2025 | Dec 24, 2025 |
| CVE-2025-20393 | Cisco Multiple Products | Cisco Multiple Products Improper Input Validation Vulnerability | Dec 17, 2025 | Dec 24, 2025 |
| CVE-2025-59718 | Fortinet Multiple Products | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability | Dec 16, 2025 | Dec 23, 2025 |
| CVE-2025-14611 | Gladinet CentreStack and Triofox | Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability | Dec 15, 2025 | Jan 5, 2026 |
| CVE-2025-43529 | Apple Multiple Products | Apple Multiple Products Use-After-Free WebKit Vulnerability | Dec 15, 2025 | Jan 5, 2026 |
| CVE-2018-4063 | Sierra Wireless AirLink ALEOS | Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability | Dec 12, 2025 | Jan 2, 2026 |
| CVE-2025-14174 | Google Chromium | Google Chromium Out of Bounds Memory Access Vulnerability | Dec 12, 2025 | Jan 2, 2026 |
| CVE-2025-58360 | OSGeo GeoServer | OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability | Dec 11, 2025 | Jan 1, 2026 |
| CVE-2025-6218 | RARLAB WinRAR | RARLAB WinRAR Path Traversal Vulnerability | Dec 9, 2025 | Dec 30, 2025 |
| CVE-2025-62221 | Microsoft Windows | Microsoft Windows Use After Free Vulnerability | Dec 9, 2025 | Dec 30, 2025 |
| CVE-2022-37055 | D-Link Routers | D-Link Routers Buffer Overflow Vulnerability | Dec 8, 2025 | Dec 29, 2025 |
| CVE-2025-66644 | Array Networks ArrayOS AG | Array Networks ArrayOS AG OS Command Injection Vulnerability | Dec 8, 2025 | Dec 29, 2025 |
| CVE-2025-55182 | Meta React Server Components | Meta React Server Components Remote Code Execution Vulnerability | Dec 5, 2025 | Dec 12, 2025 |
| CVE-2021-26828 | OpenPLC ScadaBR | OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability | Dec 3, 2025 | Dec 24, 2025 |
| CVE-2025-48633 | Android Framework | Android Framework Information Disclosure Vulnerability | Dec 2, 2025 | Dec 23, 2025 |
| CVE-2025-48572 | Android Framework | Android Framework Privilege Escalation Vulnerability | Dec 2, 2025 | Dec 23, 2025 |
| CVE-2021-26829 | OpenPLC ScadaBR | OpenPLC ScadaBR Cross-site Scripting Vulnerability | Nov 28, 2025 | Dec 19, 2025 |
| CVE-2025-61757 | Oracle Fusion Middleware | Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability | Nov 21, 2025 | Dec 12, 2025 |
| CVE-2025-13223 | Google Chromium V8 | Google Chromium V8 Type Confusion Vulnerability | Nov 19, 2025 | Dec 10, 2025 |
| CVE-2025-58034 | Fortinet FortiWeb | Fortinet FortiWeb OS Command Injection Vulnerability | Nov 18, 2025 | Nov 25, 2025 |
| CVE-2025-64446 | Fortinet FortiWeb | Fortinet FortiWeb Path Traversal Vulnerability | Nov 14, 2025 | Nov 21, 2025 |
| CVE-2025-12480 | Gladinet Triofox | Gladinet Triofox Improper Access Control Vulnerability | Nov 12, 2025 | Dec 3, 2025 |
| CVE-2025-62215 | Microsoft Windows | Microsoft Windows Race Condition Vulnerability | Nov 12, 2025 | Dec 3, 2025 |
| CVE-2025-9242 | WatchGuard Firebox | WatchGuard Firebox Out-of-Bounds Write Vulnerability | Nov 12, 2025 | Dec 3, 2025 |
| CVE-2025-21042 | Samsung Mobile Devices | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | Nov 10, 2025 | Dec 1, 2025 |
| CVE-2025-48703 | CWP Control Web Panel | CWP Control Web Panel OS Command Injection Vulnerability | Nov 4, 2025 | Nov 25, 2025 |
| CVE-2025-11371 | Gladinet CentreStack and Triofox | Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability | Nov 4, 2025 | Nov 25, 2025 |