Cut the noise.
Know which vulnerabilities demand action.

Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.

Analytics

EPSS Trending (30d)

Threat Indicators

915
CISA KEV
266
Exploits
574
Proof-of-Concept
8.5%
Average EPSS

EPSS Hot Zone

|
Sort by:
KEV Prediction — Top%
EPSS Percentile — Top%

Emerging Vulnerabilities

04 Oct/26
CVE-2026-88779
HIGH

This vulnerability is a stack-based buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway components. The root cause lies in improper bounds checking of input data processed by certain internal functions, leading to memory corruption. Affected versions include NetScaler ADC before 14.1-73.41, 13.1-64.28, and corresponding FIPS releases, as well as NetScaler Gateway before 14.1-73.41 and 13.1-64.28.

CVSS 8.7
EPSS 0.6%
KEV Pred in 25d
Product NetScaler ADC netscaler
CVSS v4.0 KEV CWE-119
30 Sep/26
CVE-2026-102490
CRITICAL

The vulnerability is a privilege escalation flaw rooted in improper permission handling within Zammad's local user management. Specifically, the local 'zammad' user account is able to escalate privileges to root due to insufficient access control enforcement in the underlying privilege separation mechanism. This affects all versions of the Zammad application, including the latest alpha releases, impacting the system's user privilege boundary.

CVSS 9.8
EPSS 0.6%
KEV Pred in 21d
Product Zammad GmbH Zammad zammad
CVSS v3.1 CVSS v4.0 KEV CWE-269
22 Sep/26
CVE-2026-93952
CRITICAL

This vulnerability in Arista Networks VeloCloud Orchestrator (VCO) On-Prem is a logic validation flaw classified under CWE-20 (Improper Input Validation). The root cause is inadequate validation of remote requests targeting privileged internal functions within the orchestrator's management interface. The affected component is the VCO on-premises orchestration platform, which processes unauthenticated network requests allowing unauthorized access to sensitive functionality.

CVSS 10.0
EPSS 1.1%
KEV Pred in 13d
Product Arista Networks VeloCloud Orchestrator (VCO) On-Prem arista
CVSS v3.1 CVSS v4.0 KEV CWE-20
15 Sep/26
CVE-2026-58704
HIGH

This vulnerability is a permission bypass caused by a logic error within the Cellular Modem component of Google Android. The flaw arises from improper enforcement of access control checks, allowing unauthorized operations to proceed. The affected code fails to correctly validate permissions, leading to an escalation of privilege without requiring additional execution rights.

CVSS 8.8
EPSS 0.6%
KEV Pred in 6d
Product Google Android google
CVSS v3.1 KEV CWE-285
08 Sep/26
CVE-2026-84869
CRITICAL

The vulnerability is an authorization bypass in the ConnectWise ScreenConnect client component that improperly controls file transfer and execution permissions during active remote sessions. The root cause lies in insufficient validation of user privileges and session state, allowing unauthorized file operations without host confirmation. This flaw specifically affects the client-side session management feature responsible for handling remote file transfers and execution commands.

CVSS 9.9
EPSS 0.9%
KEV Pred 73%
Product ConnectWise ScreenConnect connectwise
CVSS v3.1 KEV CWE-269 RANSOMWARE
05 Sep/26
CVE-2026-67277
HIGH

This vulnerability is an authentication bypass in Mikrotik RouterOS's IPv4 UDP testing feature. The root cause lies in the acceptance of a "related" btest connection before the primary session completes authentication, allowing unauthenticated clients to initiate tests. Additionally, improper handling of packet size intervals leads to unsigned integer underflow and kernel packet buffer misuse, affecting the RouterOS kernel's network packet processing component.

CVSS 8.2
EPSS 1.6%
KEV Pred 81%
Product Mikrotik RouterOS mikrotik
CVSS v3.1 CVSS v4.0 KEV CWE-306
19 Aug/26
CVE-2026-72529
CRITICAL

This vulnerability is an authentication bypass (CWE-306) affecting TrueConf Server's internal function handling. The root cause is the presence of an undocumented function accessible over network port 4307/TCP that lacks authentication controls, allowing unauthorized invocation. The affected component is the TrueConf Server software versions 5.3.x through 5.5.5 on both Windows and Linux platforms.

CVSS 9.8
EPSS 1.5%
KEV Pred 83%
Product TrueConf Server trueconf
CVSS v3.1 CVSS v4.0 KEV CWE-306
12 Aug/26
CVE-2026-42018
HIGH

This vulnerability is an authentication bypass rooted in improper token handling within JFrog Artifactory. Specifically, the system erroneously issues an internal anonymous-user token to unauthenticated requests despite anonymous access being disabled. The flaw resides in the authentication token generation and validation logic of the Artifactory server component responsible for managing access tokens.

CVSS 7.5
EPSS 9.8%
KEV Pred 81%
Product jfrog artifactory jfrog
CVSS v3.1 KEV CWE-287
11 Aug/26
CVE-2026-20349
HIGH

This vulnerability is a denial of service caused by improper error handling within the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software. The root cause is insufficient validation of HTTP request inputs, leading to unexpected device reloads when malformed requests are processed. The affected component is the HTTP request processing logic in the Remote Access SSL VPN feature.

CVSS 8.6
EPSS 1.0%
KEV Pred 83%
Product Cisco Secure Firewall Adaptive Security Appliance (ASA) Software cisco
CVSS v3.1 KEV CWE-244
29 Jul/26
CVE-2026-20316
MEDIUM

This vulnerability is an authentication bypass caused by the presence of static user credentials embedded within the Cisco Secure Firewall Management Center (FMC) web interface. The root cause lies in the use of hardcoded low-privileged account credentials that allow unauthenticated remote access. The affected component is the FMC management software's web interface authentication mechanism, which fails to enforce unique or dynamic credential validation for this account.

CVSS 5.3
EPSS 35.1%
KEV Pred 78%
Product Cisco Secure Firewall Management Center (FMC) cisco
CVSS v3.1 KEV CWE-259 RANSOMWARE
27 Jul/26
CVE-2026-42016
HIGH

This vulnerability is a privilege escalation issue arising from improper validation of token attributes in JFrog Artifactory (Self Hosted) versions prior to 7.133.11. Specifically, the system validates the token's signature and issuer but fails to verify the token’s scope, allowing unauthorized privilege elevation. The affected component is the token validation mechanism within the authentication subsystem of the Artifactory server.

CVSS 8.8
EPSS 8.6%
KEV Pred 80%
Product jfrog artifactory jfrog
CVSS v3.1 KEV CWE-863
27 Jul/26
CVE-2026-16812
CRITICAL

VeloCloud Orchestrator on-prem exposes internal-only functionality on its remotely reachable interface, and that functionality passes data into an OS command context. The vendor states the capability was designed for internal use and was never meant to be remotely accessible, so the root cause is an exposure boundary error compounded by unsanitized command construction.

CVSS 10.0
EPSS 1.0%
KEV Pred 83%
Product Arista Networks VeloCloud Orchestrator On-Prem arista
CVSS v3.1 CVSS v4.0 KEV CWE-78
16 Jul/26
CVE-2021-27137
HIGH

This vulnerability is a stack-based buffer overflow caused by the use of an unsafe strcpy operation within the UPnP handling code of DD-WRT's ssdp.c component. Specifically, the flaw exists in the ssdp_msearch function which processes M-SEARCH requests. The root cause is the lack of proper boundary checks when copying incoming data into a fixed-size internal buffer, affecting the UPnP feature of the router firmware.

CVSS 8.1
EPSS 4.0%
KEV Pred 81%
Product DD-WRT dd-wrt
CVSS v3.1 KEV CWE-121
14 Jul/26
CVE-2026-58644
CRITICAL

This vulnerability is a deserialization flaw in Microsoft Office SharePoint Server 2016, stemming from improper handling of untrusted serialized data. The root cause lies in insecure deserialization logic within SharePoint's data processing components, which fail to validate or sanitize incoming serialized objects. This affects the SharePoint Enterprise Server 2016 platform, specifically its data deserialization routines that process network-received payloads.

CVSS 9.8
EPSS 15.9%
KEV Pred 81%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-502 RANSOMWARE
18 Jun/26
CVE-2026-12569
CRITICAL

This vulnerability is a remote code execution flaw resulting from insecure deserialization of untrusted data within PTC Windchill PDMLink and FlexPLM components. Specifically, the deserialization process fails to properly validate or sanitize incoming serialized objects, allowing malicious payloads to be executed during object reconstruction. The affected components include all CPS versions and Windchill/FlexPLM releases prior to 11.0 M030, where the deserialization functionality is exposed to network input.

CVSS 9.8
EPSS 46.0%
KEV Pred 84%
Product PTC Windchill PDMLink ptc
CVSS v3.1 CVSS v4.0 KEV CWE-20 RANSOMWARE
16 Jun/26
CVE-2026-7273
HIGH

This vulnerability is a stack-based buffer overflow occurring within the CGI program of the Zyxel GS1900-48HPv2 firmware. It results from improper bounds checking on input data processed by the CGI component, allowing excessive data to overwrite the stack memory. The flaw specifically affects firmware versions up to 2.90(ABTQ.1)C0, compromising the integrity of the device's HTTP request handling subsystem.

CVSS 8.8
EPSS 2.5%
KEV Pred 92%
Product Zyxel GS1900-48HPv2 firmware zyxel
CVSS v3.1 KEV CWE-121
27 May/26
CVE-2026-48027
CRITICAL

The vulnerability involves a supply chain compromise where a maliciously altered version (18.95.0) of the Nx Console extension was published briefly on the Visual Studio Marketplace and OpenVSX. This tampered package contains unauthorized code injected into the extension's distribution, affecting the integrity of the Nx Console user interface component for Nx & Lerna. The root cause is the introduction of malicious payload within the extension's published package, bypassing normal validation or review processes.

CVSS 9.8
EPSS 1.3%
KEV Pred 81%
Product nrwl nx-console nrwl
CVSS v3.1 CVSS v4.0 KEV CWE-506 RANSOMWARE
22 May/26
CVE-2026-34909
CRITICAL

This vulnerability is a Path Traversal flaw (CWE-22) in Ubiquiti UniFi OS Server and related firmware components. The root cause is insufficient validation of user-supplied file path inputs, allowing traversal sequences to access files outside the intended directory scope. The affected components include UniFi OS Server and various UniFi device firmware versions that handle file requests without proper sanitization.

CVSS 10.0
EPSS 1.8%
KEV Pred 93%
Product Ubiquiti Inc UniFi OS Server ubiquiti
CVSS v3.1 KEV CWE-22
15 May/26
CVE-2026-8398
CRITICAL

This vulnerability is a supply chain compromise affecting the build and distribution process of AVB Disc Soft's DAEMON Tools Lite Windows installer packages, specifically versions 12.5.0.2421 through 12.5.0.2434. The root cause is unauthorized access to the vendor's build infrastructure, allowing attackers to inject malicious code into three signed binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe). The trojanized binaries maintain valid digital signatures, impacting the integrity verification mechanism of the installation process.

CVSS 9.8
EPSS 1.0%
KEV Pred 75%
Product AVB Disc Soft DAEMON Tools Lite avb
CVSS v3.1 CVSS v4.0 KEV CWE-506
07 May/26
CVE-2026-6973
HIGH

This vulnerability is an improper input validation flaw within Ivanti Endpoint Manager Mobile's administrative interface. The root cause lies in insufficient sanitization of inputs processed by privileged functions, enabling crafted input to bypass validation controls. The affected component is the administrative access functionality in versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1.

CVSS 7.2
EPSS 2.5%
KEV Pred 73%
Product Ivanti Endpoint Manager Mobile ivanti
CVSS v3.1 KEV CWE-20 RANSOMWARE
25 Feb/26
CVE-2026-22719
HIGH

This vulnerability is a command injection flaw rooted in improper input validation within VMware Aria Operations. Specifically, the support-assisted product migration component fails to sanitize user-supplied input, allowing execution of arbitrary system commands. The affected feature processes migration-related commands without adequate filtering, enabling injection through crafted inputs during migration operations.

CVSS 8.1
EPSS 17.7%
KEV Pred 73%
Product VMware Aria Operations vmware
CVSS v3.1 KEV CWE-77
25 Feb/26
CVE-2026-20122
MEDIUM

This vulnerability is a file overwrite flaw caused by improper file handling in the API interface of Cisco Catalyst SD-WAN Manager. Specifically, the API allows authenticated users with read-only credentials to upload files without sufficient validation or restrictions, enabling arbitrary file overwrite on the local filesystem. The affected component is the API subsystem responsible for processing file uploads within the SD-WAN Manager product.

CVSS 5.4
EPSS 25.0%
KEV Pred 77%
Product Cisco Catalyst SD-WAN Manager cisco
CVSS v3.1 KEV CWE-648
25 Feb/26
CVE-2026-20133
HIGH

This vulnerability is an information disclosure flaw caused by insufficient file system access controls within Cisco Catalyst SD-WAN Manager. The root cause lies in the improper enforcement of access restrictions on API endpoints, allowing unauthorized read access to sensitive files on the underlying operating system. The affected component is the API interface of the Cisco Catalyst SD-WAN Manager software.

CVSS 7.5
EPSS 31.8%
KEV Pred 75%
Product Cisco Catalyst SD-WAN Manager cisco
CVSS v3.1 KEV CWE-200
17 Feb/26
CVE-2026-22769
CRITICAL

This vulnerability is a hardcoded credential flaw within Dell RecoverPoint for Virtual Machines prior to version 6.0.3.1 HF1. The root cause is the presence of static, embedded authentication credentials in the software, which are accessible without authentication. The affected component is the authentication mechanism of the RecoverPoint for Virtual Machines management interface, allowing unauthorized access to privileged functions.

CVSS 10.0
EPSS 13.3%
KEV Pred 80%
Product Dell RecoverPoint for Virtual Machines dell
CVSS v3.1 KEV CWE-798
13 Feb/26
CVE-2026-25108
HIGH

This vulnerability is an OS command injection flaw in Soliton Systems K.K. FileZen, specifically triggered when the FileZen Antivirus Check Option is enabled. The root cause lies in insufficient input validation of user-supplied data within HTTP requests, allowing injection of arbitrary operating system commands. The affected component is the FileZen web interface handling these specially crafted requests from authenticated users.

CVSS 8.8
EPSS 5.2%
KEV Pred 56%
Product Soliton Systems K.K. FileZen soliton
CVSS v3.1 CVSS v4.0 KEV CWE-78
10 Feb/26
CVE-2026-21513
HIGH

This vulnerability is a protection mechanism failure within the MSHTML Framework, specifically involving an improper enforcement of security boundaries. The root cause lies in the component's inability to correctly validate or restrict certain operations, allowing bypass of embedded security controls. The flaw affects MSHTML, the rendering engine responsible for processing HTML content in affected Windows 10 versions.

CVSS 8.8
EPSS 15.9%
KEV Pred 81%
Product Microsoft Windows 10 Version 1607 microsoft
CVSS v3.1 KEV CWE-693 RANSOMWARE
10 Feb/26
CVE-2025-68686
MEDIUM

FortiOS exposes sensitive information to an unauthorized actor through crafted HTTP requests that bypass the patch Fortinet developed for the symbolic link persistency mechanism seen in earlier post-exploit cases. The flaw is therefore a bypass of a prior remediation rather than a new primitive: the original persistence path was closed, and this reopens it. FortiOS 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, and all versions of 7.2, 7.0 and 6.4 are affected.

CVSS 5.9
EPSS 29.5%
KEV Pred 77%
Product Fortinet FortiOS fortinet
CVSS v3.1 KEV CWE-200 RANSOMWARE
13 Jan/26
CVE-2025-25249
HIGH

This vulnerability is a heap-based buffer overflow occurring in Fortinet FortiSwitchManager and FortiOS versions specified. The root cause lies in improper bounds checking during packet processing, which leads to memory corruption on the heap. The flaw affects the packet handling routines within the FortiSwitchManager component and FortiOS network processing modules.

CVSS 7.4
EPSS 3.9%
KEV Pred 77%
Product Fortinet FortiSwitchManager fortinet
CVSS v3.1 KEV CWE-122 RANSOMWARE
05 Jan/26
CVE-2025-66376
MEDIUM

This vulnerability is a stored Cross-Site Scripting (XSS) flaw affecting the Classic UI component of Zimbra Collaboration Suite (ZCS). The root cause lies in improper sanitization of Cascading Style Sheets (CSS) @import directives embedded within HTML email messages, allowing malicious CSS to be stored and later executed in the user interface. The flaw exists in ZCS versions prior to 10.0.18 and 10.1.13, specifically in the handling of HTML email content rendering.

CVSS 6.1
EPSS 20.2%
KEV Pred 79%
Product Zimbra Collaboration zimbra
CVSS v3.1 KEV CWE-79
17 Dec/25
CVE-2025-59374
CRITICAL

This vulnerability originates from unauthorized modifications introduced into specific builds of the ASUS Live Update client through a supply chain compromise. The root cause is the presence of altered code within the update client binary that triggers unintended actions under certain targeting conditions. The affected component is the ASUS Live Update client software, which has reached End-of-Support as of October 2021.

CVSS 9.8
EPSS 1.2%
KEV Pred 83%
Product ASUS live update asus
CVSS v3.1 CVSS v4.0 KEV CWE-506
05 Dec/25
CVE-2025-66644
CRITICAL

This vulnerability is a command injection flaw rooted in improper input validation within Array Networks ArrayOS AG versions prior to 9.4.5.9. The issue arises from insufficient sanitization of user-supplied data passed to system-level commands in the VPN appliance's management interface. The affected component is the ArrayOS AG software responsible for handling administrative command inputs, enabling attackers with elevated privileges to inject arbitrary commands.

CVSS 9.8
EPSS 3.4%
KEV Pred 81%
Product Array Networks ArrayOS AG array
CVSS v3.1 KEV CWE-78
17 Nov/25
CVE-2025-13223
HIGH

This vulnerability is a type confusion flaw within the V8 JavaScript engine component of Google Chrome. The root cause lies in improper type handling during object manipulation, leading to inconsistent assumptions about object structure and memory layout. Specifically, this occurs in the V8 engine's internal representation of JavaScript objects prior to version 142.0.7444.175, which affects memory safety and integrity during script execution.

CVSS 8.8
EPSS 5.0%
KEV Pred 81%
Product Google Chrome google
CVSS v3.1 KEV CWE-843
05 Nov/25
CVE-2023-43000
HIGH

This vulnerability is a use-after-free condition arising from improper memory management in the processing of web content. The flaw occurs within Apple's WebKit rendering engine, specifically affecting Safari and related system components on macOS, iOS, and iPadOS. The root cause is the premature release of memory objects that are subsequently accessed, leading to memory corruption.

CVSS 8.8
EPSS 4.0%
KEV Pred 92%
Product Apple macOS apple
CVSS v3.1 KEV CWE-416
20 Oct/25
CVE-2025-61932
CRITICAL

The vulnerability in MOTEX Inc. Lanscope Endpoint Manager (On-Premises) arises from improper verification of the origin of incoming network requests. Specifically, the Client program (MR) and Detection agent (DA) components fail to validate the authenticity of packets received, enabling an attacker to craft and send malicious packets that are processed without adequate origin checks. This flaw is rooted in insufficient input validation within the network communication handling modules of the endpoint management system.

CVSS 9.8
EPSS 2.8%
KEV Pred 93%
Product MOTEX Inc. Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) motex
CVSS v3.1 CVSS v4.0 KEV CWE-940
15 Oct/25
CVE-2025-53521
CRITICAL

This vulnerability is a remote code execution flaw arising from improper handling of specific malicious traffic within the Access Policy Manager (APM) feature of F5 BIG-IP virtual servers. The root cause lies in the APM access policy processing logic failing to adequately validate or sanitize crafted input, enabling execution of arbitrary code. The affected component is the BIG-IP APM access policy configured on virtual servers.

CVSS 9.8
EPSS 2.3%
KEV Pred 83%
Product F5 BIG-IP f5
CVSS v3.1 CVSS v4.0 KEV CWE-121
19 Sep/25
CVE-2025-59689
MEDIUM

This vulnerability is a command injection flaw rooted in improper input validation of compressed email attachments processed by Libraesva Email Security Gateway. The affected component fails to sanitize or securely handle shell commands embedded within these attachments, allowing crafted data to be executed on the underlying system. The flaw specifically impacts versions 4.5 through 5.5.x prior to designated patch releases, compromising the email attachment processing module.

CVSS 6.1
EPSS 1.9%
KEV Pred 81%
Product Libraesva Email Security Gateway libraesva
CVSS v3.1 KEV CWE-77
12 Sep/25
CVE-2025-21043
HIGH

This vulnerability is an out-of-bounds write occurring within the libimagecodec.quram.so library used in Samsung mobile devices. The root cause is improper bounds checking during image codec operations, which leads to memory corruption when processing malformed input data. The flaw specifically affects the image codec component responsible for decoding certain image formats on Samsung Android 13.0 platforms prior to the SMR September 2025 Release 1.

CVSS 8.8
EPSS 2.1%
KEV Pred 83%
Product Samsung Mobile Devices samsung
CVSS v3.1 KEV CWE-787
29 Aug/25
CVE-2025-9377
HIGH

This vulnerability is an authenticated remote command injection in the Parental Control feature of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 firmware. The root cause lies in improper input validation on the Parental Control page, allowing shell commands to be injected and executed with elevated privileges. The flaw resides specifically in the firmware component handling user inputs on the Parental Control management interface.

CVSS 7.2
EPSS 35.8%
KEV Pred 76%
Product TP-Link Systems Inc. Archer C7(EU) V2 tp-link
CVSS v3.1 CVSS v4.0 KEV CWE-78
14 Aug/25
CVE-2025-8876
HIGH

This vulnerability is a command injection flaw caused by improper input validation in N-able N-central. The root cause lies in the failure to sanitize user-supplied inputs in specific components, enabling crafted inputs to be interpreted as operating system commands. The affected component is the N-central management platform prior to version 2025.3.1, where input handling mechanisms do not adequately restrict command execution vectors.

CVSS 8.8
EPSS 3.4%
KEV Pred 67%
Product N-able N-central n-able
CVSS v3.1 CVSS v4.0 KEV CWE-20
05 Aug/25
CVE-2025-54948
CRITICAL

This vulnerability is a command injection flaw rooted in insufficient input validation within the Trend Micro Apex One on-premise management console. The flaw allows unauthenticated remote attackers to upload and execute arbitrary code by exploiting the console's file upload handling mechanism. The affected component is the management console interface responsible for processing incoming requests without proper authentication checks or sanitization.

CVSS 9.8
EPSS 23.9%
KEV Pred 83%
Product Trend Micro, Inc. Trend Micro Apex One trend
CVSS v3.1 KEV CWE-78
24 Jun/25
CVE-2025-32975
CRITICAL

This vulnerability is an authentication bypass caused by improper validation in the Single Sign-On (SSO) authentication mechanism of Quest KACE Systems Management Appliance (SMA). The root cause lies in the flawed handling of authentication tokens or session states, allowing the system to incorrectly grant access without verifying legitimate credentials. The affected component is the SSO authentication handler across multiple SMA software versions prior to specified patch levels.

CVSS 10.0
EPSS 2.5%
KEV Pred 77%
Product Quest KACE Systems Management Appliance (SMA) quest
CVSS v3.1 KEV CWE-287
23 Jun/25
CVE-2025-48700
MEDIUM

This vulnerability is a Cross-Site Scripting (XSS) flaw rooted in insufficient sanitization of HTML content within the Zimbra Classic UI. The issue arises from improper handling of crafted tag structures and attribute values that include @import directives and other script injection vectors. The affected component is the Classic UI rendering engine that processes email message content, failing to neutralize malicious JavaScript payloads embedded in email bodies.

CVSS 6.1
EPSS 1.7%
KEV Pred 75%
Product synacor zimbra collaboration suite synacor
CVSS v3.1 KEV CWE-79
16 Jun/25
CVE-2025-43200
MEDIUM

This vulnerability is a logic flaw in the media processing component of Apple iOS and iPadOS, specifically when handling photos or videos shared via iCloud Link. The root cause lies in insufficient validation and improper processing logic for maliciously crafted media files, leading to incorrect handling of input data within the media parsing routines. This flaw affects the media handling subsystem across multiple Apple operating systems including iOS, iPadOS, macOS, visionOS, and watchOS.

CVSS 4.2
EPSS 1.2%
KEV Pred 83%
Product Apple iOS and iPadOS apple
CVSS v3.1 KEV
03 Jun/25
CVE-2025-27038
HIGH

This vulnerability is a use-after-free memory corruption occurring within the Adreno GPU driver component used by Qualcomm Snapdragon devices. The flaw arises from improper management of memory objects during graphics rendering operations in the Chrome environment, specifically related to the handling of GPU command buffers. The affected component is the Adreno GPU driver firmware across multiple Qualcomm firmware versions, leading to unsafe memory access conditions.

CVSS 7.5
EPSS 1.0%
KEV Pred 83%
Product Qualcomm, Inc. Snapdragon qualcomm,
CVSS v3.1 KEV CWE-416
28 May/25
CVE-2025-48927
MEDIUM

This vulnerability is an information disclosure flaw stemming from an exposed heap dump endpoint in the TeleMessage service's Spring Boot Actuator configuration. The root cause is the unsecured exposure of the /heapdump URI, which allows unauthenticated access to JVM heap memory dumps. The affected component is the Spring Boot Actuator's heap dump feature within TeleMessage service versions prior to 2025-05-05.

CVSS 5.3
EPSS 11.1%
KEV Pred 81%
Product TeleMessage service telemessage
CVSS v3.1 KEV CWE-1188
13 May/25
CVE-2025-42999
CRITICAL

This vulnerability is a deserialization flaw in the SAP NetWeaver Visual Composer Metadata Uploader component. The root cause is improper validation and handling of serialized metadata content uploaded by privileged users, allowing untrusted or malicious data to be deserialized. This flaw affects the Visual Composer development server within SAP NetWeaver 7.5, specifically the metadata upload functionality that processes serialized input without sufficient integrity checks.

CVSS 9.1
EPSS 13.9%
KEV Pred 83%
Product SAP_SE SAP NetWeaver (Visual Composer development server) sap_se
CVSS v3.1 KEV CWE-502 RANSOMWARE
08 May/25
CVE-2025-47729
MEDIUM

The vulnerability is an information exposure flaw caused by the TeleMessage archiving backend storing message data in cleartext form. This occurs within the backend component responsible for archiving messages from the TM SGNL (Archive Signal) application. The root cause is the backend's failure to apply end-to-end encryption to archived messages, contrary to the documented encryption claims.

CVSS 4.9
EPSS 0.4%
KEV Pred 80%
Product TeleMessage archiving backend telemessage
CVSS v3.1 KEV CWE-912
07 May/25
CVE-2025-35939
MEDIUM

This vulnerability is a server-side file injection issue rooted in improper handling of session data in Craft CMS. The system stores arbitrary content from unauthenticated users directly into session files located on the server without sanitization. The affected component is the session management mechanism that writes user-supplied return URLs into session files named with predictable patterns under '/var/lib/php/sessions'.

CVSS 5.3
EPSS 1.3%
KEV Pred 71%
Product Craft CMS craft
CVSS v3.1 CVSS v4.0 KEV CWE-472
05 May/25
CVE-2025-27920
HIGH

This vulnerability is a directory traversal flaw caused by improper sanitization of file path parameters in Srimax Output Messenger versions prior to 2.0.63. The affected component fails to correctly validate or normalize user-supplied input containing "../" sequences, allowing traversal outside the intended directory scope. This weakness resides in the file handling routines responsible for managing resource access within the messaging application.

CVSS 8.8
EPSS 1.9%
KEV Pred 83%
Product Srimax Output Messenger srimax
CVSS v3.1 KEV CWE-24 RANSOMWARE
25 Apr/25
CVE-2025-3935
HIGH

This vulnerability is a ViewState code injection issue affecting ASP.NET Web Forms used by ConnectWise ScreenConnect versions 25.2.3 and earlier. The root cause lies in the reliance on ViewState, which encodes page and control state data in Base64 and protects it using machine keys. If an attacker obtains these machine keys, they can craft malicious ViewState payloads that the server deserializes, leading to code injection via the ViewState mechanism.

CVSS 7.2
EPSS 3.5%
KEV Pred 67%
Product ConnectWise ScreenConnect connectwise
CVSS v3.1 KEV CWE-502
Page 1 of 5 (236 total)