Vulnerability Management - Complete Guide
Everything about Vulnerability Management: vulnerability scanning, prioritization, remediation, VM tools, CVSS, vulnerability lifecycle. Expert guides from nFlo.
Topics in this hub
VM Basics
8 articlesWhat is Vulnerability Management, definition and goals
Scanning & Detection
4 articlesVulnerability scanners, detection techniques
Prioritization & CVSS
4 articlesRisk assessment, CVSS scoring, prioritization
Remediation
3 articlesFixing vulnerabilities, patching, hardening
VM Tools
3 articlesTools and platforms for vulnerability management
All Vulnerability Management articles
CVE-2026-12073: The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to...
CVE-2026-13762: Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might...
CVE-2026-13763: Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF...
CVE-2026-37637: An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the...
CVE-2026-56782: Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api...
CVE-2026-57331: Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
CVE-2026-58053: Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container...
CVE-2026-12415: The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing...
CVE-2026-28701: Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated...
CVE-2025-11919: The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory...
CVE-2025-55017: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
CVE-2025-64152: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
CVE-2025-71327: Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account...
CVE-2025-71334: Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access...
CVE-2025-71336: Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote...
CVE-2025-71338: Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process...
CVE-2026-0685: Server side template inject (SSTI) in the expression evaluation component in Genshi Template...
CVE-2026-40702: WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate...
CVE-2026-45405: Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract...
CVE-2026-45406: Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an ap...
CVE-2026-54820: Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
CVE-2026-54825: Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
CVE-2026-54827: Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
CVE-2026-54831: Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
CVE-2026-56027: Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
CVE-2026-56028: Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website...
CVE-2026-56030: Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.
CVE-2026-56032: Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
CVE-2026-56033: Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.
CVE-2026-56034: Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
CVE-2026-56036: Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.
CVE-2026-56057: Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
CVE-2026-56058: Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
CVE-2026-56059: Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
CVE-2026-56062: Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.
CVE-2026-56067: Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.
CVE-2026-56068: Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.
CVE-2026-56070: Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.
CVE-2026-57658: Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
CVE-2026-57878: An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV...
CVE-2026-57879: An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV...
CVE-2026-57880: An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV...
CVE-2026-57881: An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV...
CVE-2026-12569: PTC Windchill and FlexPLM Improper Input Validation Vulnerability
CVE-2026-41120: Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous...
CVE-2026-54823: Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
CVE-2026-54836: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
CVE-2026-54843: Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.
CVE-2026-54849: Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
CVE-2026-56445: The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM...
CVE-2026-56786: RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function...
CVE-2026-57700: Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using...
CVE-2026-12416: The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset...
CVE-2026-12417: The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password...
CVE-2026-12485: GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled...
CVE-2026-12486: Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of...
CVE-2026-12846: GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled...
CVE-2026-12847: GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled...
CVE-2026-12848: GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled...
CVE-2026-12849: Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of...
CVE-2026-12850: Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of...
CVE-2026-12851: Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of...
CVE-2026-13028: Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote...
CVE-2026-13032: Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote...
CVE-2026-56111: Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING...
CVE-2026-56121: Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated...
CVE-2025-67038: Lantronix EDS5000 Code Injection Vulnerability
CVE-2026-11374: In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus,...
CVE-2026-11807: A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API....
CVE-2026-12866: All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API...
CVE-2026-56274: Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP...
CVE-2026-56315: picklescan before 1.0.4 fails to block at least seven Python standard library modules (including...
CVE-2026-9733: Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default...
CVE-2026-10561: IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python...
CVE-2026-10789: A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and...
CVE-2026-11373: metric injection in Perl Net::Statsite::Client (CVSS 9.1)
CVE-2026-12249: An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active...
CVE-2026-28381: The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run...
CVE-2026-7664: IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected...
CVE-2026-56265: Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default...
CVE-2026-56395: SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar...
CVE-2026-56397: SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar...
CVE-2019-25763: WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass...
CVE-2022-50972: WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute...
CVE-2024-58351: Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via...
CVE-2026-11551: The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all...
CVE-2026-5366: Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user...
CVE-2026-56073: Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that...
CVE-2026-56081: Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and...
CVE-2026-12045: Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence...
CVE-2026-12046: Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/...
CVE-2026-12048: Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text...
CVE-2026-40624: Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a...
CVE-2026-45480: Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate...
CVE-2026-47647: Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate...
CVE-2026-48582: Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
CVE-2026-48584: Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate...
CVE-2026-50242: In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430,...
CVE-2026-54130: Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to...
CVE-2026-54414: FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api...
CVE-2026-56141: In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430,...
CVE-2026-56142: In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430,...
CVE-2026-7515: The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to,...
CVE-2026-8713: The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to...
CVE-2026-38714: InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were...
CVE-2026-38715: InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were...
CVE-2026-38716: InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were...
CVE-2026-38717: InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were...
CVE-2026-54103: The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and...
CVE-2026-54390: JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability...
CVE-2026-54419: claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest...
CVE-2026-55740: Nur-Alam39 bus-ticket (no released versions; latest commit...
CVE-2026-55742: Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the...
CVE-2026-8024: A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability...
CVE-2025-59554: Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
CVE-2025-60229: Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This...
CVE-2025-60230: Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object...
CVE-2025-60231: Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object...
CVE-2025-60236: Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This...
CVE-2025-69111: Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
CVE-2025-69127: Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.
CVE-2025-71320: picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and...
CVE-2025-71321: picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers...
CVE-2025-71323: picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote...
CVE-2025-71325: picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when...
CVE-2026-20181: A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute...
CVE-2026-20266: In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute...
CVE-2026-36418: JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper...
CVE-2026-49108: Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
CVE-2026-53805: NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution...
CVE-2026-53873: picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to...
CVE-2026-53874: picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated...
CVE-2026-54194: Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.
CVE-2026-54387: Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length...
CVE-2026-54388: Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple...
CVE-2026-54807: Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.
CVE-2026-54808: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
CVE-2026-54809: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
CVE-2026-54811: Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.
CVE-2026-54812: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
CVE-2026-54815: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
CVE-2026-54819: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
CVE-2026-55196: Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey...
CVE-2026-55743: The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 ...
CVE-2026-11832: Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The...
CVE-2026-12087: Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs,...
CVE-2026-12205: Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private...
CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in...
CVE-2026-12315: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and...
CVE-2026-12316: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152.
CVE-2026-22313: The device has a webserver that exposes a REST API authenticated with a token on the management...
CVE-2026-39574: Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
CVE-2026-40750: Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store...
CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access Control Vulnerability
CVE-2026-49772: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
CVE-2026-49774: Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station...
CVE-2026-52715: Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.
CVE-2018-25436: WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload...
CVE-2026-45439: Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.
CVE-2026-48881: Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
CVE-2026-49067: Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
CVE-2026-49085: Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor,...
CVE-2026-49104: Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7,...
CVE-2026-49105: Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor,...
CVE-2026-49106: Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1...
CVE-2026-49109: Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms,...
CVE-2026-49763: Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
CVE-2026-49764: Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
CVE-2026-49765: Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms,...
CVE-2026-49766: Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
CVE-2026-49768: Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
CVE-2026-49769: Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.
CVE-2026-49770: Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
CVE-2026-49776: Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress:...
CVE-2026-49781: Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
CVE-2026-52693: Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
CVE-2026-52703: Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
CVE-2026-52704: Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas...
CVE-2026-54420: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
CVE-2026-8935: The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which,...
CVE-2026-9691: Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7,...
CVE-2026-9862: Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in...
CVE-2026-10557: The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are...
CVE-2026-11849: The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials...
CVE-2026-12027: Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a...
CVE-2026-28742: Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt...
CVE-2026-39494: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
CVE-2026-42647: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
CVE-2026-47365: Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM,...
CVE-2026-47367: A malicious actor with access to the network and low privileges could exploit an Improper Input...
CVE-2026-47369: A malicious actor with access to the network and low privileges could exploit an Improper Input...
CVE-2026-47370: A malicious actor with access to the network and low privileges could exploit an Improper Input...
CVE-2026-48558: SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication...
CVE-2026-48611: Improper authentication checks in the OAuth implementation allow account hijacking even when...
CVE-2026-49060: Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows...
CVE-2026-50083: The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which...
CVE-2026-50084: The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid...
CVE-2026-50086: The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against...
CVE-2026-50090: The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to...
CVE-2026-50091: Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same...
CVE-2026-50632: A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can...
CVE-2026-50633: A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which...
CVE-2026-53787: Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary...
CVE-2026-6853: Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food...
CVE-2026-11839: Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information...
CVE-2026-35273: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
CVE-2026-38581: SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote...
CVE-2026-41005: Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as...
CVE-2026-49973: Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that...
CVE-2026-7852: Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC...
CVE-2026-9648: The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS...
CVE-2025-6254: The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up...
CVE-2026-20253: In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below...
CVE-2026-53469: A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by...
CVE-2026-53470: A flaw was found in migration-planner. An authenticated attacker could exploit an improper access...
CVE-2026-53471: A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs)...
CVE-2026-53474: A flaw was found in migration-planner. A remote authenticated attacker could exploit this...
CVE-2026-53475: A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer...
CVE-2026-53476: A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same...
CVE-2026-9067: The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user...
CVE-2009-10007: Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session...
CVE-2017-20251: WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that...
CVE-2025-10263: Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1,...
CVE-2026-10045: Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2...
CVE-2026-10520: An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1...
CVE-2026-10523: An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and...
CVE-2026-11634: Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote...
CVE-2026-11638: Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to...
CVE-2026-11645: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
CVE-2026-11651: Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to...
CVE-2026-11654: Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote...
CVE-2026-11659: Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote...
CVE-2026-11671: Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker...
CVE-2026-11697: Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed...
CVE-2026-20245: Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection')...
CVE-2026-26142: Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to...
CVE-2026-27671: Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of...
CVE-2026-34691: Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a...
CVE-2026-40128: SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft...
CVE-2026-42904: Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate...
CVE-2026-44748: SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with...
CVE-2026-44815: Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute...
CVE-2026-45447: Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free...
CVE-2026-45602: No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering...
CVE-2026-45657: Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
CVE-2026-47281: Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate...
CVE-2026-47291: Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute...
CVE-2026-47643: External control of file name or path in Azure Stack Edge allows an unauthorized attacker to...
CVE-2026-47928: ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation...
CVE-2026-47938: Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side...
CVE-2026-48303: Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect...
CVE-2026-7486: Improper neutralization of special elements used in an SQL command ('SQL injection')...
CVE-2026-8025: Improper neutralization of special elements used in an SQL command ('SQL injection')...
CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that...
CVE-2023-54352: Remote code execution in WordPress Seotheme (theme)
CVE-2024-58348: Remote code execution in WordPress Background Image Cropper (plugin)
CVE-2024-58349: Arbitrary file upload in WordPress Travelscape (theme)
CVE-2026-11499: Stack Buffer Overflow in Tenda HG7HG9 / HG10
CVE-2026-25555: Authentication bypass in openbullet OpenBullet2
CVE-2026-39910: Missing authorization check in STACKIT IaaS API
CVE-2026-41448: Authentication bypass in AdguardTeam AdGuard Home
CVE-2026-42271: BerriAI LiteLLM Command Injection Vulnerability
CVE-2026-44631: Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the...
CVE-2026-50751: Auth Bypass in Check Point VPN Remote Access (IKEv1)
CVE-2026-50752: Site-to-Site VPN Certificate Bypass in Check Point (IKEv1)
CVE-2025-1740: Improper restriction of authentication attempts in Akinsoft MyRezzta
CVE-2025-71317: Hard-coded backdoor account in Riello UPS NetMan 204
CVE-2025-71318: Missing Authentication in Riello NetMan 204
CVE-2026-10580: Authentication Bypass in Hippoo Mobile App for WooCommerce (plugin)
CVE-2026-10881: Out-of-bounds Read/Write in ANGLE in Google Chrome
CVE-2026-10886: Use-after-free in FileSystem in Google Chrome
CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
CVE-2026-48567: Authentication Bypass in Microsoft Azure HorizonDB
CVE-2026-48579: Improper Authorization in Microsoft Exchange Online
CVE-2026-49777: Malicious Code Injection in Product Slider Pro for WooCommerce
CVE-2026-6207: Observable Response Discrepancy in HAVELSAN Geographic Tracking System
CVE-2026-6208: Authorization bypass in HAVELSAN Inc. Geographic Tracking System
CVE-2026-6209: Improper Access Control in HAVELSAN Inc. Geographic Tracking System
CVE-2026-6274: Authentication Bypass in DTS Electronics Redline WR3200
CVE-2026-7762: Heap Buffer Overflow in Morse Micro HaLowLink 2
CVE-2019-25727: Arbitrary file download in WordPress Ad Manager WD (plugin)
CVE-2019-25729: Server-side template injection in PDF Signer 3.0
CVE-2019-25738: Unauthenticated settings change in WordPress Hybrid Composer (plugin)
CVE-2019-25741: SEH-based buffer overflow in Mobatek MobaXterm
CVE-2026-10840: Excessive RBAC permissions in Red Hat OpenShift Pipelines
CVE-2026-20230: SSRF and Arbitrary File Write in Cisco Unified CM (CUCM)
CVE-2026-4104: SQL Injection and authorization bypass in Akmer Informatics TeknoPass
CVE-2026-41283: Remote Code Execution in OpenStack Mistral
CVE-2026-8037: OS command injection (RCE) in Progress LoadMaster
CVE-2026-9614: Privilege Escalation in Ivanti Neurons for ITSM
CVE-2010-0249: 2010 Vulnerability Now Actively Exploited (Microsoft)
CVE-2025-14771: Files accessible to external parties in ABB T-MAC Plus
CVE-2026-35075: Hard-coded password in MBS Universal Gateway (UGW)
CVE-2026-36576: OS command injection in openlabs docker-wkhtmltopdf-aas
CVE-2026-36748: Stored XSS in Spark Development Network Rock RMS
CVE-2026-4035: Server-side credential exfiltration in MLflow
CVE-2026-47065: Deserialization filter bypass in Apache MINA
CVE-2018-25427: Stack-based buffer overflow in Arm Whois Whois
CVE-2022-0492: 2022 Vulnerability Now Actively Exploited (Linux)
CVE-2025-48595: Android Framework Integer Overflow Vulnerability
CVE-2025-53209: Privilege Escalation in Themeisle Masteriyo LMS PRO
CVE-2026-0611: Unauthenticated RCE in Spacelabs Healthcare Sentinel
CVE-2026-10629: Missing IPsec integrity protection in Verizon IMS
CVE-2026-40965: Private key exposure in Cloud Foundry UAA
CVE-2026-42684: Blind SQL Injection in WordPress WP Job Portal (plugin)
CVE-2026-47117: Remote code execution in OpenMed privacy-filter loader
CVE-2026-5076: Insecure password reset in WordPress ARMember Premium (plugin)
CVE-2026-7198: Improper access control in Progress Sitefinity
CVE-2026-7312: Insufficiently Protected Credentials in Progress Sitefinity
CVE-2026-8206: Account takeover in WordPress Kirki (plugin)
CVE-2024-21182: 2024 Vulnerability Now Actively Exploited (Oracle)
CVE-2026-42252: Command Injection in Apache Airflow
CVE-2026-42672: Blind SQL Injection in WordPress WP Directory Kit plugin
CVE-2026-42680: Privilege Escalation in WordPress Contest Gallery Pro plugin
CVE-2026-42682: Missing Authorization in Tomdever wpForo Forum
CVE-2026-48188: Unauthenticated SQL Injection in OTRS
CVE-2026-48866: Path Traversal in WordPress Gravity Forms plugin
CVE-2026-48879: Privilege Escalation in Sergey AIWU
CVE-2026-7858: Unauthenticated RCE via Deserialization in Dassault Systemes Teamwork Cloud
CVE-2026-8644: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
CVE-2026-9311: Remote Code Execution in IBM WebSphere Application Server
CVE-2026-9319: Remote code execution in IBM WebSphere Application Server
CVE-2026-10187: Stack-Based Buffer Overflow in Totolink N300RH
CVE-2018-25412: Arbitrary File Upload in Delta Sql
CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
CVE-2026-10042: Remote code execution in zyddnys manga-image-translator
CVE-2026-10071: Arbitrary file upload in Interinfo DreamMaker
CVE-2026-3655: Authentication Bypass in WordPress OTP Login With Phone Number plugin
CVE-2026-5386: Unauthenticated Password Reset in KMW CCTV Security Cameras
CVE-2026-7786: Hardcoded Credentials in PUSR USR-W610 Converter
CVE-2026-8732: Privilege Escalation in WordPress WP Maps Pro plugin
CVE-2026-8809: Privilege Escalation in WordPress Advanced Custom Fields: Extended plugin
CVE-2026-9051: Authentication Bypass in NI SystemLink Enterprise
CVE-2026-24444: Hardcoded password in SDMC NE6037
CVE-2026-32996: High-Severity Arbitrary File Write / Privilege Escalation in Veeam
CVE-2026-32997: High-Severity Arbitrary File Write / Privilege Escalation in Veeam
CVE-2026-32998: Critical RCE in Veeam Service Provider Console and Backup & Replication
CVE-2026-32999: Code Injection in Comet Backup Server
CVE-2026-34926: Trend Micro Apex One Server Directory Traversal - Actively Exploited (ITW)
CVE-2026-34927: Local Privilege Escalation in Trend Micro Apex One / Vision One SEP Agent
CVE-2026-34928: LPE in Trend Micro Apex One / Vision One SEP Agent (Named Pipe)
CVE-2026-34929: LPE in Trend Micro Apex One / Vision One SEP Agent (IPC)
CVE-2026-34930: LPE in Trend Micro Apex One / Vision One SEP Agent (Process Protection)
CVE-2026-38702: Command injection in InHand Networks IR302
CVE-2026-38703: Command injection in InHand Networks IR302
CVE-2026-38704: Command injection in InHand Networks IR302
CVE-2026-38707: Command injection in InHand Networks IR302
CVE-2026-40701: High-Severity Denial of Service in NGINX (Bundle K000160932)
CVE-2026-42934: High-Severity Out-of-Bounds Read in NGINX (Bundle K000160932)
CVE-2026-42945: Critical RCE in NGINX ngx_http_rewrite_module (Public PoC Available)
CVE-2026-42946: High-Severity Use-After-Free in NGINX (Bundle K000160932)
CVE-2026-4408: Remote command execution in Samba
CVE-2026-45206: LPE in Trend Micro Apex One / Vision One SEP Agent
CVE-2026-45207: LPE in Trend Micro Apex One / Vision One SEP Agent
CVE-2026-45208: TOCTOU LPE in Trend Micro Apex One / Vision One SEP Agent
CVE-2025-12686: Buffer overflow RCE in Synology BeeStation Manager
CVE-2026-42727: SQL injection in WordPress Active Products Tables for WooCommerce
CVE-2026-42731: Privilege escalation in WordPress miniOrange OTP Verification
CVE-2026-42740: SQL injection in WordPress Tainacan plugin
CVE-2026-42747: SQL injection in WordPress Easy Form Builder plugin
CVE-2026-42748: Web shell upload in WordPress WPify Woo Czech plugin
CVE-2026-42755: SQL Injection in WordPress TableOn plugin
CVE-2026-42756: Path Traversal in WordPress QuickWebP plugin
CVE-2026-42757: Path Traversal in WordPress WebinarIgnition plugin
CVE-2026-42758: Privilege Escalation in WordPress WebinarIgnition plugin
CVE-2026-42761: SQL Injection in WordPress Active Products Tables for WooCommerce
CVE-2026-45321: TanStack Unspecified Vulnerability
CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability
CVE-2026-49002: Broken access control in Web Application Access Control Module
CVE-2026-7524: Remote code execution in IBM Langflow OSS
CVE-2026-8175: Buffer overflow in IBM Aspera High-Speed Transfer Server
CVE-2026-8362: Stack buffer overflow in WOS HTTP Server
CVE-2026-8363: Stack buffer overflow in WOS HTTP Server
CVE-2026-8364: Unauthenticated remote access in Gladinet Triofox
CVE-2026-8450: OS command injection in Perl HTTP::Daemon
CVE-2026-8760: Authentication Bypass in WordPress Login with OTP plugin
CVE-2018-25350: Username enumeration in UserSpice
CVE-2018-25357: Remote code evaluation in Dolibarr ERP CRM
CVE-2026-23652: Command injection in Microsoft Power Pages
CVE-2026-2651: Broken access control in MLflow artifact upload
CVE-2026-33843: Authentication bypass in Microsoft Azure Active Directory B2C
CVE-2026-39821: Privilege escalation in Go golang.org/x/net/idna
CVE-2026-40411: Improper Input Validation in Azure Virtual Network Gateway
CVE-2026-40412: Unrestricted File Upload in Azure Orbital Spatio
CVE-2026-41090: Command injection in Microsoft Copilot
CVE-2026-41104: Untrusted Data Deserialization in Microsoft Planetary Computer Pro
CVE-2026-42773: Blind SQL injection in eMagicOne Store Manager
CVE-2026-42774: SQL injection in Crocoblock JetEngine
CVE-2026-42901: Origin Validation Error in Microsoft Entra ID
CVE-2026-44930: LDAP Injection in Apache CXF (XKMS server)
CVE-2026-45247: PHP object injection RCE in Mirasvit Full Page Cache Warmer
CVE-2026-47280: Improper authentication in Microsoft Azure Resource Manager
CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
CVE-2026-48689: Heap Buffer Overflow in FastNetMon Community Edition
CVE-2026-7251: Hard-coded VNC password in Eppendorf BioFlo 320
CVE-2026-7374: Symlink privilege escalation in KubeVirt virt-handler
CVE-2026-8633: Remote code execution in IBM WebSphere Application Server
CVE-2026-8670: Session replay flaw in Syslink Software AG Avantra
CVE-2026-9543: OS command injection in Totolink N300RH
CVE-2026-9642: Unauthenticated Database Access in WellinTech DIAView (CVE-2025-62582 Bypass)
CVE-2026-33000: Command injection in Ubiquiti UniFi OS
CVE-2026-34908: Improper access control in Ubiquiti UniFi OS
CVE-2026-34909: Path traversal in Ubiquiti UniFi OS
CVE-2026-34910: Command injection in Ubiquiti UniFi OS
CVE-2026-6960: Arbitrary file upload in WordPress BookingPress Pro plugin
CVE-2026-9082: Drupal Core SQL Injection Vulnerability
CVE-2026-44050: Heap buffer overflow in Netatalk CNID daemon
CVE-2026-5433: Command injection in Honeywell Control Network Module (CNM)
CVE-2026-6279: Unauthenticated RCE in WordPress Avada Builder plugin
CVE-2008-4250: 2008 Vulnerability Now Actively Exploited (Microsoft)
CVE-2009-1537: 2009 Vulnerability Now Actively Exploited (Microsoft)
CVE-2009-3459: 2009 Vulnerability Now Actively Exploited (Adobe)
CVE-2010-0806: 2010 Vulnerability Now Actively Exploited (Microsoft)
CVE-2026-20223: Critical Authentication Bypass in Cisco Secure Workload
CVE-2026-22314: Code Injection in Mesalvo Meona
CVE-2026-24207: Authentication bypass in NVIDIA Triton Inference Server
CVE-2026-41091: Microsoft Defender Link Following Vulnerability
CVE-2026-45444: Arbitrary file upload in Gift Cards For WooCommerce Pro (plugin)
CVE-2026-6555: Arbitrary File Upload in WordPress ProSolution WP Client (plugin)
CVE-2026-7284: Privilege escalation in Easy Elements for Elementor (plugin)
CVE-2026-7637: PHP Object Injection in WordPress Boost (plugin)
CVE-2026-8495: Missing Authorization in Drupal Date iCal
CVE-2026-8598: Unauthenticated config export port in ZKTeco CCTV Camera
CVE-2026-9139: Hard-coded credentials in Taiko AG1000-01A SMS Alert Gateway
CVE-2026-9141: Authentication bypass in Taiko AG1000-01A SMS Alert Gateway
CVE-2026-2586: Authenticated RCE in Eclipse GlassFish Admin Console
CVE-2026-2587: Server-side EL injection RCE in Eclipse GlassFish
CVE-2026-2611: Improper origin validation RCE in MLflow Assistant
CVE-2026-31986: Hard-coded cryptographic key in Apache OFBiz
CVE-2026-36829: Authentication bypass in Panabit PAP-XM320
CVE-2026-41919: LDAP Injection in Apache OFBiz
CVE-2026-43633: Unauthenticated Deserialization RCE in HestiaCP
CVE-2026-44159: Default Admin Credentials in Tyler Identity Local (TID-L)
CVE-2026-47107: Incorrect Default Permissions in Windmill nsjail Sandbox
CVE-2026-4883: Arbitrary File Upload in WordPress Piotnet Forms plugin
CVE-2026-4885: Arbitrary File Upload in WordPress Piotnet Addons for Elementor Pro
CVE-2026-8948: Same-Origin Policy Bypass in Mozilla Firefox
CVE-2026-8950: Same-Origin Policy Bypass in Mozilla Firefox
CVE-2026-8953: Use-after-free sandbox escape in Mozilla Firefox
CVE-2026-8956: Integer Overflow in Mozilla Firefox
CVE-2026-8959: Sandbox Escape in Mozilla Firefox
CVE-2026-8973: Memory safety bugs in Mozilla Firefox
CVE-2026-8974: Memory safety bugs in Mozilla Firefox
CVE-2026-8975: Memory safety bugs in Mozilla Firefox
CVE-2026-7301: Unauthenticated RCE in SGLang multimodal runtime
CVE-2026-7302: Unauthenticated path traversal in SGLang
CVE-2026-7304: Unauthenticated RCE in SGLang custom logit processor
CVE-2018-25320: Arbitrary code execution in Galvanize ACL Analytics
CVE-2018-25332: Unauthenticated RCE in GitBucket
CVE-2018-25335: Arbitrary file upload in WordPress Peugeot Music plugin
CVE-2020-37228: CAPTCHA bypass in iDS6 DSSPro Digital Signage System
CVE-2020-37239: Broken double-free detection in babl (libbabl)
CVE-2021-47952: Remote code execution in Python jsonpickle (py/repr)
CVE-2026-42897: Microsoft Exchange Server Cross-Site Scripting Vulnerability
CVE-2026-5229: Authentication Bypass in WordPress Form Notify plugin
CVE-2026-8398: Supply chain attack trojanizing DAEMON Tools Lite installers
CVE-2025-11024: Blind SQL Injection in Akilli Commerce E-Commerce Website
CVE-2026-20182: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
CVE-2026-2347: Authorization Bypass in Akilli Commerce E-Commerce Website
CVE-2026-41615: Information Disclosure in Microsoft Authenticator
CVE-2026-6271: Arbitrary File Upload RCE in WordPress Career Section plugin
CVE-2026-6510: Privilege Escalation in WordPress InfusedWoo Pro plugin
CVE-2026-6512: Authorization Bypass in WordPress InfusedWoo Pro plugin
CVE-2026-8181: Authentication bypass in WordPress Burst Statistics (plugin)
CVE-2026-8500: Command Injection (RCE) in Perl Web::Passwd
CVE-2026-8511: Use-after-free in UI in Google Chrome (sandbox escape)
CVE-2026-8580: Use-after-free in Mojo in Google Chrome (sandbox escape)
CVE-2026-8634: Environment variable exposure in Crabbox (secret leakage)
CVE-2020-37168: Weak Cryptographic Implementation in Ecommerce Systempay
CVE-2025-11159: Remote Code Execution via JDBC in Hitachi Vantara Pentaho
CVE-2026-32661: Stack-based buffer overflow in GUARDIANWALL MailSuite
CVE-2026-40621: Missing Authentication in ELECOM Wireless LAN Access Points
CVE-2026-41225: Arbitrary Command Execution in F5 BIG-IP iControl REST
CVE-2026-42062: OS Command Injection in ELECOM Wireless LAN Access Point
CVE-2025-40949: Unauthenticated RCE in Siemens RUGGEDCOM ROX
CVE-2025-6577: SQL Injection in Akilli Commerce E-Commerce Website
CVE-2026-22924: Resource Exhaustion DoS in Siemens SIMATIC CN 4100
CVE-2026-25786: Stored XSS via PLC Name in Siemens SIMATIC Web Interface
CVE-2026-25787: Stored XSS via Technology Object Name in Siemens SIMATIC
CVE-2026-26083: Missing authorization in Fortinet FortiSandbox
CVE-2026-29204: Insufficient ownership checks in cPanel clientarea.php
CVE-2026-31230: Argument Injection in Adversarial Robustness Toolbox
CVE-2026-31242: Missing Authentication in mem0 Server (DELETE /memories)
CVE-2026-33117: Improper authentication in Azure SDK allows security feature bypass
CVE-2026-34260: SQL Injection in SAP S/4HANA Enterprise Search for ABAP
CVE-2026-34263: Unauthenticated Code Injection in SAP Commerce Cloud
CVE-2026-34659: Deserialization of Untrusted Data in Adobe Connect
CVE-2026-34660: Incorrect Authorization in Adobe Connect
CVE-2026-40379: Sensitive Information Exposure in Azure Entra ID
CVE-2026-40402: Use-After-Free Privilege Escalation in Microsoft Windows Hyper-V
CVE-2026-41089: Stack-based Buffer Overflow in Microsoft Windows Netlogon
CVE-2026-41096: Heap-based Buffer Overflow in Microsoft Windows DNS
CVE-2026-41103: Privilege Escalation in Microsoft SSO Plugin for Jira & Confluence
CVE-2026-41551: Path Traversal in Siemens ROS#
CVE-2026-42823: Improper Access Control in Azure Logic Apps
CVE-2026-42833: Execution with Unnecessary Privileges in Microsoft Dynamics 365
CVE-2026-42898: Code Injection in Microsoft Dynamics 365 (on-premises)
CVE-2026-44277: Improper Access Control in Fortinet FortiAuthenticator
CVE-2026-45185: Remotely Reachable Use-After-Free in Exim MTA
CVE-2026-8043: File name external control in Ivanti Xtraction
CVE-2026-40636: Hard-coded Credentials in Dell ECS and ObjectScale
CVE-2026-7813: Authorization bypass in pgAdmin Development Team pgAdmin 4
CVE-2021-47923: Session Fixation Vulnerability in OpenCart
CVE-2021-47932: Privilege Escalation in WordPress TheCartPress Plugin
CVE-2021-47933: Arbitrary File Upload in WordPress MStore API Plugin
CVE-2021-47936: Remote Code Execution via File Upload in OpenCATS
CVE-2021-47940: Arbitrary File Upload in WordPress Download From Files Plugin
CVE-2026-25199: Tenant Isolation Bypass in Apache CloudStack Proxmox Extension
CVE-2026-33109: Improper access control in Azure Managed Instance for Apache Cassandra
CVE-2026-33823: Improper authorization in Microsoft Teams allows information disclosure
CVE-2026-33844: Improper Input Validation in Azure Managed Instance for Apache Cassandra
CVE-2026-35428: Command Injection in Azure Cloud Shell
CVE-2026-42208: BerriAI LiteLLM SQL Injection Vulnerability
CVE-2026-42826: Sensitive Information Exposure in Azure DevOps
CVE-2026-8153: OS command injection in Universal Robots PolyScope
CVE-2026-33587: SSTI remote code execution in Lfnovo Open-Notebook
CVE-2026-40982: Directory Traversal in VMware Spring Cloud Config
CVE-2026-5791: CSRF Vulnerability in DivvyDrive
CVE-2026-6508: Origin Validation Error in TUBITAK BILGEM Liderahenk
CVE-2026-6795: Open Redirect Vulnerability in DivvyDrive
CVE-2026-6973: Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
CVE-2026-7414: Hardcoded Credentials in Yarbo Firmware
CVE-2026-7415: Unauthenticated MQTT access in Yarbo Yarbo Firmware
CVE-2026-0300: Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
CVE-2026-28780: Heap-based buffer overflow in Apache HTTP Server mod_proxy_ajp
CVE-2026-5081: Insecure Session ID Generation in Perl Apache-Session
CVE-2023-54342: Remote Code Execution in Eclipse Equinox OSGi
CVE-2023-54344: Remote Code Execution in Eclipse Equinox OSGi via Console
CVE-2025-13618: Privilege Escalation in WordPress Mentoring Plugin
CVE-2026-36356: OS Command Injection in MeiG Smart FORGE_SLT711
CVE-2026-40797: Blind SQL Injection in Saleswonder LLC WebinarIgnition Plugin
CVE-2026-5294: Missing Authorization RCE in WordPress Geeky Bot Plugin
CVE-2026-5722: Authentication Bypass in WordPress MoreConvert Pro plugin
CVE-2026-7411: Path Traversal RCE in Eclipse BaSyx Java Server SDK
CVE-2026-7823: OS command injection in Totolink A8000RU
CVE-2026-7834: Stack buffer overflow in EFM Networks ipTIME NAS1dual
CVE-2026-7853: Buffer overflow in D-Link DI-8100
CVE-2026-7854: Buffer overflow in D-Link DI-8100 POST Parameter Handler
CVE-2025-14320: Reflected XSS in Tegsoft Online Support Application
CVE-2026-25293: Buffer overflow in Qualcomm PLC Firmware
CVE-2026-42364: OS command injection in GeoVision LPC2011/LPC2211
CVE-2026-42368: Privilege escalation in GeoVision LPC2011/LPC2211
CVE-2026-42369: Remote interface exposure in GeoVision GV-VMS V20
CVE-2026-42370: Stack overflow in GeoVision GV-VMS V20 WebCam Server Login
CVE-2026-42373: Hardcoded telnet backdoor in D-Link DIR-605L (rev. B2, EOL)
CVE-2026-42374: Hardcoded telnet backdoor in D-Link DIR-600L (rev. B1, EOL)
CVE-2026-42375: Hardcoded telnet backdoor in D-Link DIR-600L (rev. A1, EOL)
CVE-2026-42376: Hardcoded telnet backdoor in D-Link DIR-456U
CVE-2026-42796: Unauthenticated RCE in Arelle (/rest/configure)
CVE-2026-42809: Privilege escalation in Apache Polaris via vended storage credentials
CVE-2026-42810: Wildcard injection in Apache Polaris (S3 IAM)
CVE-2026-42811: GCS credential scope bypass in Apache Polaris
CVE-2026-42812: Metadata validation bypass in Apache Polaris (Iceberg)
CVE-2026-7161: Credential leak in GeoVision GV-IP Device Utility
CVE-2026-7372: Stack overflow in GeoVision GV-VMS V20 (sscanf)
CVE-2026-7482: Heap out-of-bounds read in Ollama (GGUF loader)
CVE-2026-7719: Buffer overflow in Totolink WA300
CVE-2026-7747: Buffer overflow in Totolink N300RH
CVE-2026-4882: Arbitrary file upload in WordPress User Registration Advanced Fields
CVE-2026-7458: Authentication bypass in WordPress User Verification by PickPlugins
CVE-2026-31431: Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
CVE-2026-37531: Zip Slip and TOCTOU in Automotive Grade Linux app-framework-main
CVE-2026-37539: Buffer overflow in cannelloni CAN frame parser
CVE-2026-37541: Buffer overflow in Open Vehicle Monitoring System 3 (OVMS3)
CVE-2026-42482: Stack buffer overflow in hashcat mangle_to_hex
CVE-2026-42483: Heap buffer overflow in hashcat Kerberos hash parser
CVE-2026-42484: Heap buffer overflow in hashcat PKZIP hash parser
CVE-2026-42778: Incomplete deserialization fix in Apache MINA (2.1.X/2.2.X branches)
CVE-2026-42779: Deserialization allowlist bypass in Apache MINA (2.1.X/2.2.X)
CVE-2026-7538: OS command injection in Totolink A8000RU
CVE-2026-7546: Stack buffer overflow in Totolink NR1800X
CVE-2026-7567: Authentication bypass in WordPress Temporary Login plugin
CVE-2018-25316: Authentication bypass in Tenda W308R router
CVE-2018-25317: Authentication bypass in Tenda W3002R/A302/W309R routers
CVE-2018-25318: Authentication bypass in Tenda FH303/A300 routers
CVE-2026-36841: Command injection in TOTOLINK N200RE V5
CVE-2026-41446: Hidden diagnostic endpoints in Snap One WattBox 800/820
CVE-2026-41940: Authentication bypass in cPanel & WHM login flow
CVE-2026-42523: Stored XSS in Jenkins GitHub Plugin
CVE-2026-5166: Path Traversal in TUBITAK BILGEM Pardus Software Center
CVE-2026-7333: Use-after-free in Google Chrome GPU component
CVE-2026-7343: Use-after-free in Google Chrome on Windows (Views component)
CVE-2024-1708: 2024 Vulnerability Now Actively Exploited (ConnectWise)
CVE-2026-32644: Default SSL private keys in Milesight AIOT cameras
CVE-2026-40976: Spring Boot default web security ineffective, allows unauthorized access
CVE-2026-7202: OS command injection in Totolink A8000RU (setWiFiWpsStart)
CVE-2026-7203: OS command injection in Totolink A8000RU (setUrlFilterRules)
CVE-2026-7204: OS command injection in Totolink A8000RU (setPptpServerCfg)
CVE-2026-7240: OS command injection in Totolink A8000RU (setVpnAccountCfg)
CVE-2026-7241: OS command injection in Totolink A8000RU (setWiFiBasicCfg)
CVE-2026-7242: OS command injection in Totolink A8000RU (setOpenVpnClientCfg)
CVE-2026-7243: OS command injection in Totolink A8000RU (setRadvdCfg)
CVE-2026-7244: OS command injection in Totolink A8000RU (setWiFiEasyGuestCfg)
CVE-2026-7248: Buffer overflow in D-Link DI-8100 CGI tgfile.htm endpoint
CVE-2026-7321: Sandbox escape in Mozilla Firefox ESR via WebRTC Networking
CVE-2026-22336: SQL injection in WordPress Directorist Booking plugin
CVE-2026-22337: Privilege escalation in Directorist Social Login plugin
CVE-2026-30352: RCE in /devserver/start endpoint of leonvanzyl/autocoder
CVE-2026-33453: Header injection in Apache Camel camel-coap leads to RCE
CVE-2026-33454: Header injection in Apache Camel camel-mail
CVE-2026-40453: Incomplete header filter fix in Apache Camel
CVE-2026-40860: Unsafe JMS ObjectMessage deserialization in Apache Camel
CVE-2026-41409: Incomplete deserialization fix in Apache MINA
CVE-2026-41462: Unauthenticated SQL injection in ProjeQtor
CVE-2026-41635: Class allowlist bypass in Apache MINA
CVE-2026-42363: Insufficient encryption in GeoVision GV-IP Device Utility
CVE-2026-7121: OS command injection in Totolink A8000RU (setWizardCfg)
CVE-2026-7122: OS command injection in Totolink A8000RU (setUPnPCfg)
CVE-2026-7136: OS command injection in Totolink A8000RU (setDmzCfg)
CVE-2026-7139: OS command injection in Totolink A8000RU (setWiFiAclRules)
CVE-2026-7140: OS command injection in Totolink A8000RU (CsteSystem)
CVE-2026-7037: OS command injection in Totolink A8000RU router - public exploit
CVE-2026-6951: RCE in npm simple-git via incomplete fix bypass
CVE-2024-57726: 2024 Vulnerability Now Actively Exploited (SimpleHelp )
CVE-2024-57728: 2024 Vulnerability Now Actively Exploited (SimpleHelp )
CVE-2024-7399: 2024 Vulnerability Now Actively Exploited (Samsung)
CVE-2025-29635: D-Link DIR-823X Command Injection Vulnerability
CVE-2026-1949: Stack buffer overflow in Delta Electronics AS320T (GET/PUT handler)
CVE-2026-1950: Buffer overflow in Delta Electronics AS320T (file name length)
CVE-2026-1951: Buffer overflow in Delta Electronics AS320T (directory name length)
CVE-2026-1952: Denial of service in Delta Electronics AS320T
CVE-2026-21515: Privilege escalation in Microsoft Azure IoT Central
CVE-2026-24303: Privilege escalation in Microsoft Partner Center via improper access control
CVE-2026-25775: Unauthenticated firmware update in SenseLive X3050
CVE-2026-26210: Unsafe pickle deserialization in KTransformers
CVE-2026-27843: Persistent device lockout in SenseLive X3050 via web management flaw
CVE-2026-32210: SSRF in Microsoft Dynamics 365 (Online)
CVE-2026-33102: Open redirect in Microsoft M365 Copilot
CVE-2026-33819: Deserialization of untrusted data in Microsoft Bing - RCE
CVE-2026-35431: SSRF in Microsoft Entra ID Entitlement Management
CVE-2026-35503: Client-side authentication bypass in SenseLive X3050
CVE-2026-39920: Default credentials in BridgeHead FileStore lead to RCE
CVE-2026-40620: Unauthenticated management service in SenseLive X3050
CVE-2026-40630: Access control bypass in SenseLive X3050 web interface
CVE-2026-23751: Unauthenticated .NET Remoting access in Kofax Capture / Tungsten Capture
CVE-2026-29198: NoSQL injection and account takeover in Rocket.Chat
CVE-2026-31175: Command injection in TOTOLINK A3300R via stunEnable parameter
CVE-2026-31177: Command injection in TOTOLINK A3300R via stunMinAlive parameter
CVE-2026-31178: Command injection in TOTOLINK A3300R via stunMaxAlive parameter
CVE-2026-31181: Command injection in TOTOLINK A3300R via stunServerAddr parameter
CVE-2026-3844: Arbitrary file upload in Breeze Cache plugin for WordPress
CVE-2026-39087: Remote code execution (RCE) in Ntfy (ntfy.sh)
CVE-2026-39440: Code injection leading to RCE in FunnelFormsPro
CVE-2026-39987: Marimo Remote Code Execution Vulnerability
CVE-2026-40470: Critical XSS in hackage-server (hackage.haskell.org)
CVE-2026-40471: Missing CSRF protection in hackage-server (hackage.haskell.org)
CVE-2026-40472: Stored XSS in hackage-server (Haskell)
CVE-2026-41460: Critical SQL injection in SocialEngine
CVE-2026-6885: Arbitrary file upload in Borg SPM 2007 leading to RCE
CVE-2026-6886: Authentication bypass in Borg SPM 2007
CVE-2026-6887: SQL Injection in Borg SPM 2007
CVE-2026-6942: OS command injection in radare2-mcp
CVE-2018-25270: Remote code execution in ThinkPHP 5.0.23
CVE-2018-25272: Remote code execution and privilege escalation in ELBA5 5.8.0
CVE-2026-1555: Arbitrary file upload in WebStack theme for WordPress
CVE-2026-33825: Microsoft Defender Insufficient Granularity of Access Control Vulnerability
CVE-2026-34415: Incomplete input validation in Xerte Online Toolkits leads to RCE
CVE-2026-4119: Authorization bypass in Create DB Tables plugin for WordPress
CVE-2026-6235: Authorization bypass in Sendmachine plugin for WordPress
CVE-2026-6356: Privilege escalation to super administrator via parameter manipulation
CVE-2017-20230: Stack overflow in Perl Storable before 3.05
CVE-2025-15638: Vulnerable libtomcrypt in Perl Net::Dropbear before 0.14
CVE-2026-33518: Incorrect privilege assignment in Esri Portal for ArcGIS 11.5
CVE-2026-33519: Incorrect authorization of developer credentials in Esri Portal for ArcGIS 11.4–12.0
CVE-2026-34275: Unauthenticated takeover of Oracle Advanced Inbound Telephony (E-Business Suite)
CVE-2026-34279: Scope-change compromise in Oracle Enterprise Manager Event Management
CVE-2026-34285: Unauthenticated data tampering in Oracle Identity Manager Connector (Fusion Middleware)
CVE-2026-34286: Unauthenticated data tampering in Oracle Identity Manager Connector (Fusion Middleware)
CVE-2026-34287: Unauthenticated data tampering in Oracle Identity Manager Connector (Fusion Middleware)
CVE-2026-38835: Command injection in Tenda W30E router
CVE-2026-40050: Unauthenticated path traversal in CrowdStrike LogScale
CVE-2026-5652: Insecure direct object reference in Crafty Controller Users API
CVE-2026-5965: Command injection in NewSoft NewSoftOA
CVE-2026-6768: Mitigation bypass in Firefox Networking Cookies component
CVE-2023-27351: 2023 Vulnerability Now Actively Exploited (PaperCut)
CVE-2024-27199: 2024 Vulnerability Now Actively Exploited (JetBrains)
CVE-2025-2749: Kentico Xperience Path Traversal Vulnerability
CVE-2025-32975: Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
CVE-2026-20128: Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
CVE-2026-30269: Privilege escalation in Doorman
CVE-2026-32956: Buffer overflow in Silex Technology SD-330AC / AMC Manager
CVE-2026-33557: SASL OAuth JWT validation flaw in Apache Kafka
CVE-2026-39109: SQL injection in PHPGurukul Apartment Visitors Management System
CVE-2026-39918: Code injection via installation endpoint in Vvveb
CVE-2026-5760: Remote code execution in SGLang
CVE-2026-5963: SQL injection in Digiwin EasyFlow .NET
CVE-2026-5964: SQL injection in Digiwin EasyFlow .NET
CVE-2026-6257: Remote code execution via file rename in Vvveb CMS
CVE-2026-25917: XCom arbitrary code execution by DAG authors in Apache Airflow
CVE-2026-2262: Sensitive data exposure in WordPress Easy Appointments plugin
CVE-2026-6443: Backdoored Accordion plugin for WordPress
CVE-2026-31843: Unauthenticated PHP file overwrite in Laravel pay-uz package
CVE-2026-34197: Apache ActiveMQ Improper Input Validation Vulnerability
CVE-2026-3596: Privilege escalation in WordPress
CVE-2026-37338: SQL injection in SourceCodester Simple Music Cloud Community System
CVE-2026-37345: SQL injection in SourceCodester Vehicle Parking Area Management System
CVE-2026-37347: SQL injection in SourceCodester Payroll Management and Information System
CVE-2026-40504: Buffer overflow in Creolabs Gravity
CVE-2026-40959: Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.
CVE-2026-4880: Privilege escalation in WordPress
CVE-2026-6350: Buffer overflow in Openfind MailAudit
CVE-2026-6388: Privilege escalation in Argo CD Argo CD Image Updater
CVE-2025-41118: Data handling vulnerability in Grafana Pyroscope
CVE-2026-20147: Authenticated command execution in Cisco ISE
CVE-2026-20180: Authenticated command execution in Cisco Identity Services Engine
CVE-2026-20184: SSO impersonation in Cisco Webex Services Control Hub
CVE-2026-20186: Authenticated command execution in Cisco Identity Services Engine
CVE-2026-27304: Improper input validation leading to RCE in Adobe ColdFusion
CVE-2026-6296: Buffer overflow in Google Chrome
CVE-2009-0238: 2009 Vulnerability Now Actively Exploited (Microsoft)
CVE-2025-63939: SQL injection in anirudhkannan Grocery Store Management System
CVE-2025-65135: SQL injection in manikandan580 School-management-system
CVE-2026-22562: Remote code execution in Ubiquiti UniFi Play
CVE-2026-22563: Command injection in Ubiquiti UniFi Play
CVE-2026-22564: Access control bypass in Ubiquiti UniFi Play
CVE-2026-26149: Security feature bypass in Microsoft Power Apps
CVE-2026-27243: Cross-site scripting in Adobe Connect
CVE-2026-27245: Cross-site scripting in Adobe Connect
CVE-2026-27246: Cross-site scripting in Adobe Connect
CVE-2026-27303: Deserialization in Adobe Connect
CVE-2026-27681: Critical SQL Injection Vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse
CVE-2026-32201: Microsoft SharePoint Server Improper Input Validation Vulnerability
CVE-2026-33824: Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-34256: Missing Authorization Check in SAP ERP and SAP S/4HANA
CVE-2026-34615: Deserialization in Adobe Connect
CVE-2026-38526: Arbitrary file upload in Krayin Krayin CRM
CVE-2026-39808: OS command injection in Fortinet FortiSandbox
CVE-2026-39813: Path traversal in Fortinet FortiSandbox
CVE-2026-4365: Unauthorized data deletion in LearnPress plugin for WordPress
CVE-2026-5752: Sandbox escape via prototype chain in Terrarium
CVE-2026-6264: Unauthenticated RCE via JMX port in Talend JobServer
CVE-2012-1854: 2012 Vulnerability Now Actively Exploited (Microsoft)
CVE-2020-9715: 2020 Vulnerability Now Actively Exploited (Adobe)
CVE-2023-21529: 2023 Vulnerability Now Actively Exploited (Microsoft)
CVE-2023-36424: 2023 Vulnerability Now Actively Exploited (Microsoft)
CVE-2025-60710: Microsoft Windows Link Following Vulnerability
CVE-2026-21643: Fortinet SQL Injection Vulnerability
CVE-2026-31282: Access control bypass in Totara Totara LMS
CVE-2026-31283: Missing rate limiting in Totara LMS forgot-password API
CVE-2026-40042: XXE in Pachno wiki/issue parser
CVE-2026-40044: Deserialization RCE via cache files in Pachno
CVE-2026-5085: Insecure session ID generation in Perl Solstice::Session
CVE-2026-6131: OS command injection via setTracerouteCfg() in Totolink A7100RU CGI
CVE-2026-6132: OS command injection via setLedCfg() in Totolink A7100RU CGI
CVE-2026-6138: OS command injection via setAccessDeviceCfg() in Totolink A7100RU CGI
CVE-2026-6139: OS command injection via UploadOpenVpnCert() in Totolink A7100RU CGI
CVE-2026-6140: OS command injection via UploadFirmwareFile() in Totolink A7100RU CGI
CVE-2026-6154: OS command injection via setWizardCfg() in Totolink A7100RU CGI
CVE-2026-6155: OS command injection via setWanCfg() in Totolink A7100RU CGI
CVE-2026-6156: OS command injection via setIpQosRules() in Totolink A7100RU CGI
CVE-2026-6195: OS command injection via setPasswordCfg() in Totolink A7100RU CGI
CVE-2019-25709: Database leak via upload/data directory in CF Image Hosting Script
CVE-2026-31845: Cross-site scripting in Rukovoditel CRM
CVE-2026-34621: Prototype pollution leading to RCE in Adobe Acrobat Reader
CVE-2026-4149: Remote code execution in Sonos Era 300 Firmware
CVE-2026-5058: Command injection in aws-mcp-server aws-mcp-server
CVE-2026-5059: Command injection in aws-mcp-server aws-mcp-server
CVE-2026-1115: Cross-site scripting in Lollms
CVE-2026-23781: Hardcoded debug credentials in BMC Control-M/MFT
CVE-2026-33784: Default password in Juniper Networks Support Insights
CVE-2026-34424: Backdoored Smart Slider 3 Pro plugin for WordPress
CVE-2026-36235: SQL injection in Itsourcecode Online Student Enrollment System
CVE-2026-5993: OS command injection via setWiFiGuestCfg() in Totolink A7100RU CGI
CVE-2026-5994: OS command injection via setTelnetCfg() in Totolink A7100RU CGI
CVE-2026-5995: OS command injection via setMiniuiHomeInfoShow() in Totolink A7100RU CGI
CVE-2026-5996: OS command injection via setAdvancedInfoShow() in Totolink A7100RU CGI
CVE-2026-5997: OS command injection via setLoginPasswordCfg() in Totolink A7100RU CGI
CVE-2026-6025: OS command injection via setSyslogCfg() in Totolink A7100RU CGI
CVE-2026-6026: OS command injection via setPortalConfWeChat() in Totolink A7100RU CGI
CVE-2026-6027: OS command injection via setUrlFilterRules() in Totolink A7100RU CGI
CVE-2026-6028: OS command injection via setPptpServerCfg() in Totolink A7100RU CGI
CVE-2026-6029: OS command injection via setVpnAccountCfg() in Totolink A7100RU CGI
CVE-2026-6057: Arbitrary file upload in FalkorDB Browser
CVE-2025-13926: Traffic forgery via network sniffing in Contemporary Controls BASC 20T
CVE-2025-57735: JWT token reuse after logout in Apache Airflow
CVE-2026-0233 and CVE-2026-0234: Critical Vulnerabilities in Palo Alto Networks Cortex XSOAR, XSIAM and ADEM - Immediate Update Required
CVE-2026-1830: Unauthenticated RCE via REST API in Quick Playground plugin for WordPress
CVE-2026-39912: Authentication token leak via loginWithMailLink in V2Board/Xboard
CVE-2026-40035: Flask debug mode enabled by default in Unfurl
CVE-2026-4112: Critical Privilege Escalation Vulnerability in SonicWall SMA 1000 - Immediate Update Required
CVE-2026-5850: OS command injection via setVpnPassCfg() in Totolink A7100RU CGI
CVE-2026-5851: OS command injection via setUPnPCfg() in Totolink A7100RU CGI
CVE-2026-5852: OS command injection via setIptvCfg() in Totolink A7100RU CGI
CVE-2026-5853: OS command injection via setIpv6LanCfg() in Totolink A7100RU CGI
CVE-2026-5854: OS command injection via setWiFiEasyCfg() in Totolink A7100RU CGI
CVE-2026-5975: OS command injection via setDmzCfg() in Totolink A7100RU CGI
CVE-2026-5976: OS command injection via setStorageCfg() in Totolink A7100RU CGI
CVE-2026-5977: OS command injection via setWiFiBasicCfg() in Totolink A7100RU CGI
CVE-2026-5978: OS command injection via setWiFiAclRules() in Totolink A7100RU CGI
CVE-2023-46945: QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request
CVE-2026-1340: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVE-2026-1346: Local privilege escalation to root in IBM Security Verify Access
CVE-2026-25776: Perl code injection in Movable Type
CVE-2026-2942: Arbitrary file upload in ProSolution WP Client plugin for WordPress
CVE-2026-31017: SSRF in Frappe ERPNext
CVE-2026-3296: PHP Object Injection in Everest Forms plugin for WordPress
CVE-2026-3535: Arbitrary file upload in WordPress
CVE-2026-4003: Privilege escalation via user meta update in Users Manager PN plugin for WordPress
CVE-2021-4473: Command injection in Tianxin Internet Behavior Management System
CVE-2026-0740: Arbitrary file upload in Ninja Forms File Uploads plugin for WordPress
CVE-2026-1114: Access control bypass in Parisneo lollms
CVE-2026-20889: Buffer overflow in LibRaw
CVE-2026-20911: Buffer overflow in LibRaw
CVE-2026-21413: Buffer overflow in LibRaw
CVE-2026-22679: Unauthenticated RCE via Dubbo debug endpoint in Weaver E-cology
CVE-2026-23696: SQL injection in Windmill
CVE-2026-39355: Access control bypass in Kreaweb Genealogy
CVE-2026-4631: SSH command injection via login endpoint in Cockpit
CVE-2026-5627: Information disclosure in Mintplex Labs anything-llm
CVE-2026-5731: Memory corruption in Mozilla Firefox
CVE-2026-5734: Memory corruption in Mozilla Firefox
CVE-2026-5735: Memory corruption in Mozilla Firefox
CVE-2016-20052: Arbitrary file upload in Snews CMS
CVE-2017-20234: Authentication bypass via hardcoded credentials in GarrettCom Magnum switches
CVE-2017-20235: Authentication bypass in ProSoft Technology ICX35-HWC web UI
CVE-2017-20236: Command injection in ProSoft Technology ICX35-HWC web UI
CVE-2018-25236: Authentication bypass in Hirschmann HiOS/HiSecOS management
CVE-2018-25237: Buffer overflow in Hirschmann HiSecOS
CVE-2018-25254: Buffer overflow in NICO-FTP NICO-FTP
CVE-2021-4477: IPv6 IPsec firewall bypass in Hirschmann HiLCOS OpenBAT
CVE-2026-35616: Access control bypass in Fortinet Forticlientems
CVE-2017-20237: Authentication bypass in Hirschmann Industrial HiVision
CVE-2026-0545: Unauthenticated RCE via job endpoints in MLflow
CVE-2026-25197: IDOR in Gardyn user profile API
CVE-2026-26135: SSRF in Microsoft Azure Custom Locations Resource Provider
CVE-2026-28373: Path traversal in Stackfield Desktop App
CVE-2026-28766: Unauthenticated user account disclosure in Gardyn
CVE-2026-32211: Missing authentication in Azure MCP Server
CVE-2026-32213: Improper authorization in Azure AI Foundry
CVE-2026-33105: Improper authorization in Microsoft Azure Kubernetes Service
CVE-2026-33107: SSRF in Azure Databricks
Vulnerability Scanner — What It Is, How It Works and Which Tools to Choose
CVE-2026-25212: Shell command execution via Add Data Source in Percona PMM
CVE-2026-2699: Unauthenticated configuration access in Citrix ShareFile Storage Zones Controller
CVE-2026-2701: Authenticated file upload RCE in Citrix ShareFile Storage Zones Controller
CVE-2026-33615: SQL injection in MB connect line mbCONNECT24
CVE-2026-34877: Memory corruption in Mbed TLS
CVE-2026-3502: TrueConf Client Download of Code Without Integrity Check Vulnerability
What is vulnerability assessment? Vulnerability evaluation — process, tools, and best practices
CVE-2024-40489: Command injection in Jeecg Boot
CVE-2024-43028: Command injection in Jeecg Boot /jmreport endpoint
CVE-2025-15484: Authentication bypass in Order Notification for WooCommerce plugin
CVE-2025-71279: Passkey authentication compromise in XenForo
CVE-2026-20093: Authentication bypass in Cisco Integrated Management Controller
CVE-2026-20160: Unauthenticated command execution in Cisco Smart Software Manager On-Prem
CVE-2026-29014: Unauthenticated PHP code injection in MetInfo CMS
CVE-2026-30643: Code execution via module upload in DedeCMS
CVE-2026-31027: Buffer overflow in Totolink A3600r Firmware
CVE-2026-34872: Contributory-behavior flaw in FFDH in Arm Mbed TLS
CVE-2026-34875: Buffer overflow in Mbed TLS
CVE-2026-5281: Google Dawn Use-After-Free Vulnerability
CVE-2026-5288: Use-after-free in Google Chrome
CVE-2026-5289: Use-after-free in Google Chrome
CVE-2026-5290: Use-after-free in Google Chrome
CVE-2025-15618: Insecure secret key in Perl Business::OnlinePayment::StoredTransaction
CVE-2026-0596: Privilege escalation in MLflow
CVE-2026-1579: Unauthenticated command execution via unsigned MAVLink in PX4 Autopilot
CVE-2026-30282: Arbitrary file overwrite in UXGROUP Cast to TV Screen Mirroring
CVE-2026-32916: Authorization bypass via plugin subagent routes in OpenClaw
CVE-2026-33579: Privilege escalation in Openclaw
Cyber Resilience Act (CRA): 3 vulnerability definitions you need to know
CVE-2026-32917: Command injection via iMessage attachment SCP in OpenClaw
CVE-2026-32920: Arbitrary code execution via plugin auto-load in OpenClaw
CVE-2026-3300: PHP code injection RCE in Everest Forms Pro plugin for WordPress
CVE-2026-4257: Remote code execution in WordPress
CVE-2026-3055: Citrix NetScaler Out-of-Bounds Read Vulnerability
CVE-2026-30562: Cross-site scripting in Ahsanriaz26gmailcom Sales And Inventory System
CVE-2026-34714: Code execution via crafted file in Vim
CVE-2026-5128: Steam credentials exposure in ArthurFiorette steam-trader
CVE-2026-32922: Privilege escalation in Openclaw
CVE-2026-32973: Exec allowlist bypass via glob matching in OpenClaw
CVE-2026-32987: Privilege escalation in Openclaw
CVE-2026-22738: SpEL injection in Spring AI SimpleVectorStore
CVE-2026-27876: Remote code execution in Grafana
CVE-2026-30302: Command injection in Coderider Kilo Coderider
CVE-2026-30303: Command injection in Matterai Axon Code
CVE-2026-30304: Automatic command execution bypass in AI Code
CVE-2026-30530: SQL injection in Oretnom23 Online Food Ordering System
CVE-2026-30532: SQL injection in Oretnom23 Online Food Ordering System
CVE-2026-30533: SQL injection in Oretnom23 Online Food Ordering System
CVE-2026-33634: Aquasecurity Trivy Embedded Malicious Code Vulnerability
CVE-2026-4484: Privilege escalation in Masteriyo LMS plugin for WordPress
CVE-2026-4809: Arbitrary file upload in Laravel
CVE-2026-20688: Sandbox escape via path handling in Apple iOS/iPadOS
CVE-2026-25366: Critical Vulnerability in HP Woody ad snippets - Immediate Update Required
CVE-2026-25447: Critical Vulnerability in Widget Wrangler - Immediate Update Required
CVE-2026-26830: Critical Vulnerability in npm pdf-image - Immediate Update Required
CVE-2026-26832: Critical Vulnerability in npm node-tesseract-ocr - Immediate Update Required
CVE-2026-27044: Critical Vulnerability in Total Poll Lite - Immediate Update Required
CVE-2026-27049: Authentication bypass in NooTheme Jobica Core
CVE-2026-27084: Deserialization in ThemeREX Buisson buisson
CVE-2026-28827: Sandbox escape via directory path parsing in Apple macOS
CVE-2026-28858: Critical Vulnerability in Apple iOS - Immediate Update Required
CVE-2026-31920: SQL injection in Devteam HaywoodTech Product Rearrange for WooCommerce
CVE-2026-32499: SQL injection in QuantumCloud ChatBot
CVE-2026-32519: Privilege escalation in Bit Apps Bit SMTP
CVE-2026-32523: Arbitrary file upload in WPJAM Basic plugin for WordPress
CVE-2026-32525: Critical Vulnerability in JetFormBuilder - Immediate Update Required
CVE-2026-32536: Critical Vulnerability in Green Downloads - Immediate Update Required
CVE-2026-32539: Critical Vulnerability in PublishPress PublishPress Revisions revisionary - Immediate Update Required
CVE-2026-32573: Critical Vulnerability in Nelio AB Testing - Immediate Update Required
CVE-2026-33017: Langflow Code Injection Vulnerability
CVE-2026-4001: Critical Vulnerability in WordPress Woocommerce Custom Product Addons Pro - Immediate Update Required
CVE-2026-4283: Critical Vulnerability in WordPress WP DSGVO Tools (GDPR) - Immediate Update Required
CVE-2026-4688: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4691: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4696: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4698: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4700: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4701: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4702: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4705: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4711: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4715: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4716: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4717: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4720: Memory corruption in Mozilla Firefox
CVE-2026-4723: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4725: Critical Vulnerability in Mozilla Firefox - Immediate Update Required
CVE-2026-4750: Critical Vulnerability in woof - Immediate Update Required
CVE-2026-4753: Critical Vulnerability in RetroDebugger - Immediate Update Required
CVE-2026-4755: Critical Vulnerability in Android-ImageMagick7 - Immediate Update Required
CVE-2026-3587: Critical Vulnerability in Embedded Device CLI - Immediate Update Required
CVE-2026-4567: Critical Vulnerability in Tenda A15 - Immediate Update Required
CVE-2026-4599: Critical Vulnerability in npm jsrsasign - Immediate Update Required
CVE-2026-21992: Critical Vulnerability in Oracle Oracle Identity Manager - Immediate Update Required
CVE-2026-22732: Critical Vulnerability in VMware Spring Security - Immediate Update Required
CVE-2026-32194: Critical Vulnerability in Microsoft Bing Images - Immediate Update Required
CVE-2026-32985: Critical Vulnerability in HP Xerte Online Toolkits - Immediate Update Required
CVE-2026-33134: SQL injection in Wegia
CVE-2026-4038: Critical Vulnerability in WordPress Aimogen Pro - Immediate Update Required
CVE-2026-20131: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
CVE-2026-22557: Critical Path Traversal in Ubiquiti UniFi Network (CVSS 10.0)
CVE-2026-22558: Ubiquiti UniFi Network NoSQL Injection Vulnerability (CVSS 7.7)
CVE-2026-23554: Critical Citrix XenServer Vulnerability - Host Memory Leak from Guest VM
CVE-2026-27065: Critical Vulnerability in ThimPress BuilderPress - Immediate Update Required
CVE-2026-27067: Arbitrary file upload in Mobile App Editor plugin for WordPress
CVE-2026-27413: Critical Vulnerability in Profile Builder Pro - Immediate Update Required
CVE-2026-27540: Critical Vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture - Immediate Update Required
CVE-2026-27542: Critical Vulnerability in Woocommerce Wholesale Lead Capture - Immediate Update Required
CVE-2026-30402: Critical Vulnerability in wgcloud - Immediate Update Required
CVE-2026-32865: Critical Vulnerability in OPEXUS eComplaint and eCASE before - Immediate Update Required
CVE-2026-20963: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVE-2026-32698: SQL injection in Openproject
CVE-2026-3909: Google Skia Out-of-Bounds Write Vulnerability
CVE-2026-3910: Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability
CVE-2026-1603: Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
CVE-2026-21385: Qualcomm Multiple Chipsets Memory Corruption Vulnerability
CVE-2026-28363: tools.exec.safeBins validation bypass in OpenClaw
CVE-2026-20127: Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
CVE-2026-25108: Soliton Systems K.K FileZen OS Command Injection Vulnerability
CVE-2026-27593: Password reset token interception in Statamic CMS
CVE-2026-26980: Unauthenticated database read in Ghost CMS
CVE-2026-22769: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
CVE-2026-2441: Google Chromium CSS Use-After-Free Vulnerability
CVE-2026-1731: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
CVE-2026-20700: Apple Multiple Buffer Overflow Vulnerability
CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure Vulnerability
CVE-2026-21513: Microsoft Internet Explorer Protection Mechanism Failure Vulnerability
CVE-2026-21514: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability
CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability
CVE-2026-24423: SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability
CVE-2026-1281: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-21509: Microsoft Office Security Feature Bypass Vulnerability
CVE-2026-23760: SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-24061: GNU InetUtils Argument Injection Vulnerability
CVE-2025-15036: Path traversal in MLflow extract_archive_to_dir
CVE-2025-15379: Command injection in MLflow model serving
CVE-2025-53521: F5 BIG-IP Unspecified Vulnerability
CVE-2025-32991: Critical Vulnerability in N2WS Backup & Recovery - Immediate Update Required
CVE-2025-33244: Critical Vulnerability in Linux NVIDIA APEX for Linux - Immediate Update Required
CVE-2025-60949: Critical Vulnerability in Census CSWeb 8.0.1 - Immediate Update Required
CVE-2025-71275: Critical Vulnerability in Zimbra Zimbra Collaboration Suite - Immediate Update Required
CVE-2025-31277: Apple Multiple Products Buffer Overflow Vulnerability
CVE-2025-32432: High-Risk Craft CMS Vulnerability (EPSS: 79%)
CVE-2025-43510: Apple Multiple Products Improper Locking Vulnerability
CVE-2025-43520: Apple Multiple Products Classic Buffer Overflow Vulnerability
CVE-2025-54068: Laravel Livewire Code Injection Vulnerability
CVE-2025-60233: Deserialization in Themeton Zuut
CVE-2025-60237: Deserialization in Themeton Finag
CVE-2025-66376: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
CVE-2025-68613: High-Risk n8n Vulnerability (EPSS: 79%)
CVE-2025-26399: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
RidgeBot 6.2: Native Directory Brute-Force Scanning, Expanded WAP Support and Unauthenticated SMTP Relay
CVE-2025-40538: Access control bypass in Solarwinds Serv-U
CVE-2025-40539: Type confusion leading to RCE in SolarWinds Serv-U
CVE-2025-40540: Type confusion leading to RCE in SolarWinds Serv-U
CVE-2025-40541: IDOR leading to RCE in SolarWinds Serv-U
CVE-2025-49113: High-Risk Webmail Vulnerability (EPSS: 90%)
CVE-2025-68461: RoundCube Webmail Cross-site Scripting Vulnerability
CVE-2025-12107: Server-side template injection in WSO2 Identity Server
CVE-2025-13590: Remote code execution in Wso2 Api Control Plane
CVE-2025-15556: Notepad++ Download of Code Without Integrity Check Vulnerability
CVE-2025-40536: SolarWinds Web Help Desk Security Control Bypass Vulnerability
CVE-2025-11953: React Native Community CLI OS Command Injection Vulnerability
CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability
CVE-2025-52691: SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
From alert to action: How RidgeBot® reports turn data into strategic decisions
CVE-2016-20049: Buffer overflow in JAD
CVE-2017-20225: Buffer overflow in Ticalc Tiemu
CVE-2017-20227: Buffer overflow in Varaneckas Jad Java Decompiler
CVE-2017-20229: Buffer overflow in Invisible Island Mawk
CVE-2018-25220: Buffer overflow in Bochs Project Bochs
CVE-2018-25221: Buffer overflow in Echatserver Easy Chat Server
CVE-2018-25223: Buffer overflow in Ftnapps Crashmail Ii
CVE-2014-125112: Remote code execution in Perl Plack::Middleware::Session::Cookie
CVE-2019-25628: Critical Vulnerability in Download Accelerator Plus DAP - Immediate Update Required
CVE-2019-25646: Critical Vulnerability in Tabs Mail Carrier 2.5.1 - Immediate Update Required
CVE-2019-25614: Critical Vulnerability in Free Float FTP 1.0 - Immediate Update Required
CVE-2006-10003: Critical buffer overflow in Perl XML::Parser - Immediate Update Required
CVE-2021-22054: 2021 Vulnerability Now Actively Exploited (Omnissa)
CVE-2017-7921: 2017 Vulnerability Now Actively Exploited (Hikvision)
CVE-2021-22681: 2021 Vulnerability Now Actively Exploited (Rockwell)
CVE-2021-30952: 2021 Vulnerability Now Actively Exploited (Apple)
CVE-2023-41974: 2023 Vulnerability Now Actively Exploited (Apple)
CVE-2023-43000: 2023 Vulnerability Now Actively Exploited (Apple)
CVE-2022-20775: 2022 Vulnerability Now Actively Exploited (Cisco)
CVE-2008-0015: 2008 Vulnerability Now Actively Exploited (Microsoft)
CVE-2020-7796: 2020 Vulnerability Now Actively Exploited (Synacor)
CVE-2024-7694: 2024 Vulnerability Now Actively Exploited (TeamT5)
CVE-2024-43468: 2024 Vulnerability Now Actively Exploited (Microsoft)
CVE-2019-19006: 2019 Vulnerability Now Actively Exploited (Sangoma)
What Is CVSS (Common Vulnerability Scoring System)? A Complete Guide to Vulnerability Assessment
What is CWE? Guide to Common Weakness Enumeration
Vulnerability Disclosure - How to Responsibly Report Security Flaws
CVE-2018-14634: 2018 Vulnerability Now Actively Exploited (Linux)
Source Code Vulnerability Analysis
Vulnerability scanners: How to choose the right tool and effectively manage the results?
Risk assessment in OT: Why is CVSS not enough and how to assess the real risk to the production process?
OT Vulnerability Management: Legacy Systems — My PLC Controller Can't Be Updated
What Is CSRF (Cross-Site Request Forgery)? Detection, How It Works, and Prevention
Verified Risk vs Vulnerabilities: How RidgeBot Eliminates False Alarms Through Exploit Validation
What Is SQL Injection? A Complete Guide to Web Application Vulnerabilities and Protections
Vulnerability Management Lifecycle - Complete Guide
Automating ISO 27001 and NIS2 Compliance: How RidgeBot® Supports Regulatory Requirements
Vulnerability prioritization in practice
Micro Focus Fortify – Automatic Code Vulnerability Testing
Automation in vulnerability management
Tenable: Solutions and Support for Proactive Vulnerability Management
Comprehensive Vulnerability Management: Your organization's proactive shield against cyber attacks
Comprehensive Penetration Testing and Its Business Significance: How Does It Differ from Vulnerability Scanning?
Hardware YubiKey keys in practice: how to implement FIDO2 and hardware MFA in your company step by step
What is RidgeBot®? A complete guide to offensive security validation
Why Does Your Pentest Report Gather Dust? The Remediation Gap Problem
Retesting and Remediation Validation After Pentests: Why and How to Verify Fixes
Vulnerability Management Lifecycle
Vulnerability Management: What Is It and How Does It Work?
What is CVE (Common Vulnerabilities and Exposures)? - Key Information
Network Penetration Testing - Security Testing Process, Vulnerability Identification, and Threat Detection
Need help with Vulnerability Management?
nFlo offers full Vulnerability Management services: vulnerability scanning, prioritization, remediation support.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist