| CVE-2026-48282exploited | 10 | critical | adobe / coldfusion | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restrict | 67d ago |
| CVE-2026-49869exploited | 10 | critical | kestra / kestra | Kestra is an open-source, event-driven orchestration platform. | 71d ago |
| CVE-2026-48558exploited | 10 | critical | simple-help / simplehelp | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability i | 85d ago |
| CVE-2026-10520exploited | 10 | critical | ivanti / standalone sentry | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a r | 88d ago |
| CVE-2026-34910exploited | 10 | critical | ui / unifi os server | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in Uni | 107d ago |
| CVE-2026-34909exploited | 10 | critical | ui / unifi os server | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS device | 107d ago |
| CVE-2026-34908exploited | 10 | critical | ui / unifi os server | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi | 107d ago |
| CVE-2026-20182exploited | 10 | critical | cisco / catalyst sd-wan manager | May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered | 114d ago |
| CVE-2026-8452exploited | 9.8 | critical | citrix / netscaler application delivery controller | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior an | 67d ago |
| CVE-2026-56290exploited | 9.8 | critical | joomlack / page builder ck | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla ext | 68d ago |
| CVE-2026-48939exploited | 9.8 | critical | joomlic / icagenda | A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment f | 77d ago |
| CVE-2026-48908exploited | 9.8 | critical | ollyo / sp page builder | A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately r | 77d ago |
| CVE-2026-12569exploited | 9.8 | critical | ptc / flexplm | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. | 80d ago |
| CVE-2026-35273exploited | 9.8 | critical | oracle / peoplesoft enterprise peopletools | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environmen | 86d ago |
| CVE-2026-20253exploited | 9.8 | critical | splunk / splunk | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create | 87d ago |
| CVE-2026-25089exploited | 9.8 | critical | fortinet / fortisandbox | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fort | 88d ago |
| CVE-2026-48907exploited | 9.8 | critical | widgetfactorylimited / jce | A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthentica | 92d ago |
| CVE-2026-46817exploited | 9.8 | critical | oracle / e-business suite | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). | 100d ago |
| CVE-2026-48027exploited | 9.8 | critical | nx / nx console | Nx Console is the user interface for Nx & Lerna. | 101d ago |
| CVE-2026-45247exploited | 9.8 | critical | mirasvit / full page cache warmer | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability | 102d ago |
| CVE-2026-48172exploited | 9.8 | critical | litespeedtech / litespeed cpanel plugin | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the | 108d ago |
| CVE-2026-9082exploited | 9.8 | critical | drupal / drupal | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal | 108d ago |
| CVE-2026-8398exploited | 9.8 | critical | disc-soft / daemon tools | A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0. | 113d ago |
| CVE-2026-3055exploited | 9.8 | critical | citrix / netscaler application delivery controller | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memor | 166d ago |
| CVE-2026-33017exploited | 9.8 | critical | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 169d ago |
| CVE-2025-67038exploited | 9.8 | critical | lantronix / eds5032 firmware | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. | 178d ago |
| CVE-2026-8037exploited | 9.6 | critical | progress / connection manager for objectscale | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated | 93d ago |
| CVE-2026-45321exploited | 9.6 | critical | tanstack / tanstack\/arktype-adapter | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages wer | 117d ago |
| CVE-2026-50751exploited | 9.3 | critical | checkpoint / gaia os | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange a | 89d ago |
| CVE-2026-0257exploited | 9.1 | critical | paloaltonetworks / pan-os | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® softwar | 115d ago |
| CVE-2026-11645exploited | 8.8 | high | google / chrome | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute a | 89d ago |
| CVE-2026-45659exploited | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 106d ago |
| CVE-2026-33634exploited | 8.8 | high | aquasec / setup-trivy | Trivy is a security scanner. | 166d ago |
| CVE-2026-3910exploited | 8.8 | high | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arb | 176d ago |
| CVE-2026-3909exploited | 8.8 | high | google / chrome | Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bou | 176d ago |
| CVE-2026-20230exploited | 8.6 | high | cisco / unified communications manager | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Sess | 94d ago |
| CVE-2026-54420exploited | 8.5 | high | litespeedtech / litespeed cpanel plugin | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks p | 83d ago |
| CVE-2026-55255exploited | 8.4 | high | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2025-48595exploited | 8.4 | high | google / android | In multiple locations, there is a possible way to achieve code execution due to an integer overflow. | 96d ago |
| CVE-2026-42897exploited | 8.1 | high | microsoft / exchange server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server | 114d ago |
| CVE-2026-53362exploited | 7.8 | high | linux / linux kernel | In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocat | 63d ago |
| CVE-2026-20245exploited | 7.8 | high | cisco / catalyst sd-wan manager | A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Mana | 93d ago |
| CVE-2026-41091exploited | 7.8 | high | microsoft / malware protection engine | Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker | 108d ago |
| CVE-2026-28318exploited | 7.5 | high | solarwinds / serv-u | SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authenti | 93d ago |
| CVE-2026-34926exploited | 6.7 | medium | trendmicro / apex one | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local atta | 107d ago |
| CVE-2026-20262exploited | 6.5 | medium | cisco / catalyst sd-wan manager | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authentica | 82d ago |
| CVE-2026-48710exploited | 6.5 | medium | encode / starlette | Starlette is a lightweight ASGI framework/toolkit. | 102d ago |
| CVE-2026-7473exploited | 5.8 | medium | arista / eos | On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensib | 92d ago |
| CVE-2026-45498exploited | 4 | medium | microsoft / defender antimalware platform | Microsoft Defender Denial of Service Vulnerability | 108d ago |