Every published CVE from the last 120 days with CVSS score, vendor and product, cross-referenced against CISA's Known Exploited Vulnerabilities catalog. 10 added to KEV in the last 7 days.
| CVE | CVSS | Severity | Vendor / product | Summary | Published |
|---|---|---|---|---|---|
| CVE-2026-34926exploited | 6.7 | medium | trendmicro / apex one | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local atta | 107d ago |
| CVE-2026-20262exploited | 6.5 | medium | cisco / catalyst sd-wan manager | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authentica | 82d ago |
| CVE-2026-48710exploited | 6.5 | medium | encode / starlette | Starlette is a lightweight ASGI framework/toolkit. | 102d ago |
| CVE-2026-7473exploited | 5.8 | medium | arista / eos | On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensib | 92d ago |
| CVE-2026-45498exploited | 4 | medium | microsoft / defender antimalware platform | Microsoft Defender Denial of Service Vulnerability | 108d ago |
Sources: NIST National Vulnerability Database (descriptions, CVSS, CPE) and CISA Known Exploited Vulnerabilities catalog (exploitation status). Both are United States government works in the public domain. Data refreshes daily; KEV hourly.