Cut the noise.
Know which vulnerabilities demand action.

Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.

Analytics

EPSS Trending (30d)

Threat Indicators

915
CISA KEV
266
Exploits
574
Proof-of-Concept
11.1%
Average EPSS

EPSS Hot Zone

|
Sort by:
KEV Prediction — Top%
EPSS Percentile — Top%

Emerging Vulnerabilities

01 Oct/26
CVE-2026-104286
CRITICAL

This vulnerability is a path traversal flaw caused by improper validation of pathname inputs within Fortinet FortiMail. The affected component fails to restrict access to directories, allowing crafted HTTP or HTTPS requests to manipulate file paths beyond intended boundaries. This weakness exists in FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1, specifically in the web interface handling of file operations.

CVSS 9.8
EPSS 2.2%
KEV Pred in 22d
Product Fortinet FortiMail fortinet
CVSS v3.1 KEV CWE-22 PoC RANSOMWARE
30 Sep/26
CVE-2026-102489
CRITICAL

This vulnerability is a session hijacking flaw rooted in improper session management within Zammad's authentication mechanism. The affected component fails to adequately validate or isolate session tokens, allowing unauthorized users to assume the identity of legitimate sessions. The flaw exists in the session handling logic of Zammad versions 6.3.0 through 6.5.4 and partially in versions 7.0.0 to 7.1.3 under specific environmental conditions.

CVSS 9.8
EPSS 1.3%
KEV Pred in 21d
Product Zammad GmbH Zammad zammad
CVSS v3.1 CVSS v4.0 KEV CWE-384 PoC
30 Sep/26
CVE-2026-76504
CRITICAL

This vulnerability is an authentication bypass caused by improper URI encoding handling within the HTTP request processing of Cisco Catalyst SD-WAN Manager's API session-based authentication management. The flaw resides in the API endpoint access control mechanism, where crafted HTTP requests with encoded URIs bypass authentication rules intended to restrict access. The affected component is the API authentication logic of Cisco Catalyst SD-WAN Manager.

CVSS 9.8
EPSS 1.8%
KEV Pred in 21d
Product Cisco Catalyst SD-WAN Manager cisco
CVSS v3.1 KEV CWE-177 PoC RANSOMWARE
28 Sep/26
CVE-2026-86950
HIGH

This vulnerability is an out-of-bounds write flaw caused by improper bounds checking during file processing in Apple iOS and iPadOS. The root cause lies in the failure to correctly validate input size or index values, leading to memory corruption. The affected components are the file parsing routines within the operating system's media or document handling subsystems.

CVSS 8.8
EPSS 1.2%
KEV Pred in 19d
Product Apple iOS and iPadOS apple
CVSS v3.1 KEV CWE-787 PoC
27 Sep/26
CVE-2026-88772
CRITICAL

This vulnerability is a memory corruption issue classified under CWE-119, specifically a buffer overflow within Citrix NetScaler ADC and Gateway components. The root cause lies in improper handling of input data in certain network protocol processing routines, leading to unsafe memory operations. Affected versions include multiple releases prior to 14.1-73.37 and 13.1-64.23, impacting both standard and FIPS/NDcPP builds of the ADC and Gateway.

CVSS 9.5
EPSS 1.3%
KEV Pred in 18d
Product Citrix NetScaler ADC citrix
CVSS v4.0 KEV CWE-119 PoC
27 Sep/26
CVE-2026-88771
CRITICAL

This vulnerability is an improper input validation flaw in Citrix NetScaler ADC and Gateway components. The root cause lies in insufficient sanitization of user-supplied input within specific request handling routines, allowing malicious data to bypass validation checks. Affected components include NetScaler ADC versions prior to 14.1-73.37 and 13.1-64.23, including FIPS and NDcPP variants, as well as NetScaler Gateway versions before 14.1-73.37 and 13.1-64.23.

CVSS 9.5
EPSS 1.1%
KEV Pred in 18d
Product Citrix NetScaler ADC citrix
CVSS v4.0 KEV CWE-20 PoC
22 Sep/26
CVE-2026-87902
HIGH

This vulnerability is a local file inclusion (LFI) flaw rooted in improper validation of file paths within the WordPress function get_page_template(). The function incorrectly resolves page templates by allowing inclusion of arbitrary readable .php files outside the active theme directories. This occurs due to insufficient restrictions on file path inputs used in template resolution logic, affecting the WordPress theme handling component.

CVSS 8.1
EPSS 40.0%
KEV Pred in 13d
Product WordPress wordpress
CVSS v3.1 KEV CWE-98 PoC
22 Sep/26
CVE-2026-94127
CRITICAL

This vulnerability is a heap-based buffer overflow (CWE-122) in the F5 BIG-IP Access Policy Manager (APM) component when configured as an OAuth Authorization Server. The flaw arises from improper handling of specific OAuth profile inputs within the virtual server's access policy, allowing crafted malicious traffic to corrupt memory. The issue affects the data plane processing path of BIG-IP APM when OAuth authorization server profiles are active, leading to uncontrolled execution flow.

CVSS 9.8
EPSS 2.2%
KEV Pred in 13d
Product F5 BIG-IP f5
CVSS v3.1 CVSS v4.0 KEV CWE-122 PoC
22 Sep/26
CVE-2026-93616
CRITICAL

This vulnerability is a directory traversal and file upload flaw in Check Point Quantum Security Management. It arises from insufficient input validation in the file upload functionality, allowing unauthorized manipulation of file paths. The affected component is the Check Point Management Server's file handling mechanism, which fails to restrict user-supplied file paths, enabling arbitrary file placement on the server.

CVSS 9.8
EPSS 19.7%
KEV Pred in 13d
Product checkpoint Quantum Security Management checkpoint
CVSS v3.1 KEV CWE-22 PoC
16 Sep/26
CVE-2026-76460
CRITICAL

This vulnerability is an authentication bypass caused by insufficient authentication controls on a specific API endpoint within Cisco Identity Services Engine (ISE) Software. The root cause lies in the failure to enforce proper authentication checks on the affected API, allowing unauthenticated access. The flaw specifically impacts the web-based management interface component of Cisco ISE, enabling unauthorized interactions with its API endpoints.

CVSS 10.0
EPSS 14.0%
KEV Pred in 8d
Product Cisco Identity Services Engine Software cisco
CVSS v3.1 KEV CWE-648 PoC RANSOMWARE
14 Sep/26
CVE-2026-76461
CRITICAL

This vulnerability is a command injection flaw rooted in improper input validation within the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. The affected component fails to sanitize crafted email messages containing malicious SQL statements, allowing arbitrary command execution at the operating system level. The issue specifically arises from insufficient validation in the email parsing mechanism that processes incoming email content.

CVSS 9.8
EPSS 28.3%
KEV Pred in 5d
Product Cisco Secure Email cisco
CVSS v3.1 KEV CWE-89 PoC RANSOMWARE
09 Sep/26
CVE-2026-85102
CRITICAL

This vulnerability is an improper certificate trust validation flaw within the VPN negotiation process of Check Point Quantum Security Gateway. The root cause is the failure to correctly verify the authenticity of certificates presented during the VPN handshake, allowing acceptance of malicious or forged certificates. The affected component is the VPN negotiation module responsible for establishing secure tunnels between endpoints.

CVSS 9.8
EPSS 7.5%
KEV Pred N/A
Product checkpoint Quantum Security Gateway checkpoint
CVSS v3.1 KEV CWE-295 PoC
09 Sep/26
CVE-2026-87491
HIGH

This vulnerability is an out-of-bounds write (CWE-787) occurring within the V8 JavaScript engine component of Google Chrome. The root cause is improper bounds checking during memory operations in V8's handling of crafted JavaScript code, leading to memory corruption. The flaw specifically affects versions of Google Chrome prior to 153.0.8010.36, compromising the integrity of the V8 sandbox environment.

CVSS 8.8
EPSS 3.1%
KEV Pred 81%
Product Google Chrome google
CVSS v3.1 KEV CWE-787 PoC
07 Sep/26
CVE-2026-75650
CRITICAL

This vulnerability is an improper neutralization of special elements within the template engine of Adobe Commerce. The root cause lies in insufficient sanitization of user-controllable input embedded in templates, allowing injection of malicious code. The affected component is the template processing mechanism responsible for rendering dynamic content in Adobe Commerce versions including 2.4.4 and its patches.

CVSS 10.0
EPSS 3.9%
KEV Pred 84%
Product Adobe Commerce adobe
CVSS v3.1 KEV CWE-1336 PoC RANSOMWARE
06 Sep/26
CVE-2026-86218
CRITICAL

The vulnerability is a pre-authentication remote code execution caused by improper handling of input data within N-able N-central. The root cause lies in the unsafe processing of commands or scripts in a component responsible for handling unauthenticated requests, allowing arbitrary code execution. This flaw affects N-central versions prior to 2026.3.1.14, specifically within the core service that processes external input without sufficient validation or sanitization.

CVSS 9.8
EPSS 12.9%
KEV Pred 81%
Product N-able N-central n-able
CVSS v3.1 CVSS v4.0 KEV CWE-96 Exploit PoC
05 Sep/26
CVE-2026-86060
CRITICAL

This vulnerability is a privilege escalation flaw caused by improper argument handling in the SSH login process of Mikrotik RouterOS. Specifically, usernames beginning with a prohibited character bypass input validation, allowing unauthorized modification of the trusted RouterOS policy mask. The affected component is the RouterOS SSH login helper, which processes authentication requests without sufficient sanitization of username parameters.

CVSS 9.8
EPSS 6.4%
KEV Pred 84%
Product Mikrotik RouterOS mikrotik
CVSS v3.1 CVSS v4.0 KEV CWE-88 PoC
05 Sep/26
CVE-2026-67279
MEDIUM

This vulnerability is an authentication bypass in the SSH protocol implementation of Mikrotik RouterOS. The root cause is that after a client requests a rekey operation, the server transitions into the connection protocol phase without verifying user authentication. This flaw affects the SSH server component responsible for managing session channels and command dispatching within RouterOS.

CVSS 6.5
EPSS 1.0%
KEV Pred 81%
Product Mikrotik RouterOS mikrotik
CVSS v3.1 CVSS v4.0 KEV CWE-841 PoC
03 Sep/26
CVE-2026-85046
HIGH

This vulnerability is a type confusion flaw located within the V8 JavaScript engine component of Google Chrome. The root cause stems from improper handling of object types in memory, leading to incorrect assumptions about data structures. This flaw affects V8's internal type system prior to version 152.0.7977.82, allowing crafted input to manipulate memory layout inconsistently.

CVSS 8.8
EPSS 48.9%
KEV Pred 79%
Product Google Chrome google
CVSS v3.1 KEV CWE-843 PoC
01 Sep/26
CVE-2026-83548
CRITICAL

The SMA1000 Work Place interface exposes an unintended alternate access path that reaches internal request-handling functionality before authentication is enforced. Because the appliance treats this path as trusted, the server can be induced to issue requests on the attacker's behalf, which is the classic Server-Side Request Forgery pattern. The flaw sits in the pre-auth surface of the appliance, so no session or credential material is involved in reaching the vulnerable code.

CVSS 10.0
EPSS 8.8%
KEV Pred 78%
Product SonicWall SMA1000 sonicwall
CVSS v3.1 KEV CWE-441 Exploit PoC RANSOMWARE
28 Aug/26
CVE-2026-82329
CRITICAL

JFrog Artifactory ships a default configuration in which the authentication layer accepts material that should never be trusted from the network. Public analysis of the patch describes a phantom join key: an attacker-supplied value that the server accepts when validating a URL parameter, allowing a service admin token to be forged rather than issued. The weakness is in the identity verification path itself, not in any single API handler.

CVSS 9.8
EPSS 14.1%
KEV Pred 81%
Product jfrog artifactory jfrog
CVSS v3.1 KEV CWE-287 PoC
26 Aug/26
CVE-2026-60004
CRITICAL

This vulnerability is a code injection flaw rooted in improper validation of input passed to the diffpatch API within Gitea's Git hook installation process. The affected component is the diffpatch API endpoint, which processes patch data without sufficient sanitization, enabling execution of arbitrary code via crafted input. The issue arises from the unsafe handling of patch content that is integrated into Git hooks, leading to command execution capability embedded in the repository management workflow.

CVSS 9.8
EPSS 24.0%
KEV Pred 80%
Product Gitea gitea
CVSS v3.1 KEV CWE-94 PoC
19 Aug/26
CVE-2026-72530
CRITICAL

This vulnerability is a code injection flaw classified under CWE-94, caused by improper handling of user-supplied scripts within the TrueConf Server isolated environment. The root cause lies in insufficient validation and sanitization of input scripts processed on port 4307/TCP, allowing crafted payloads to escape sandbox restrictions. The affected component is the script execution environment in TrueConf Server versions 5.3.x through 5.5.5 on Windows and Linux platforms.

CVSS 9.0
EPSS 1.7%
KEV Pred 83%
Product TrueConf Server trueconf
CVSS v3.1 CVSS v4.0 KEV CWE-94 PoC
19 Aug/26
CVE-2026-19490
CRITICAL

This vulnerability is an authentication bypass flaw rooted in improper validation of user credentials within the NetScaler ADC and Gateway authentication modules. The issue arises from the failure to correctly verify authentication tokens or session parameters, allowing unauthorized access to protected components. The affected components include NetScaler ADC and NetScaler Gateway versions ranging from 13.1 through 63.21 and 14.1 through 73.32, impacting both FIPS and non-FIPS deployments.

CVSS 9.8
EPSS 23.2%
KEV Pred 83%
Product NetScaler ADC netscaler
CVSS v3.1 CVSS v4.0 KEV CWE-288 PoC
17 Aug/26
CVE-2026-64849
CRITICAL

This vulnerability is an SSRF (Server-Side Request Forgery) flaw rooted in improper validation of webhook URLs within the MLflow platform. Specifically, the _validate_webhook_url() function only validates the original URL without accounting for HTTP redirects. The mlflow/webhooks/delivery.py component follows redirects and re-resolves hostnames, enabling attackers to bypass URL validation and interact with unintended internal or cloud metadata endpoints.

CVSS 9.3
EPSS 9.8%
KEV Pred 60%
Product mlflow mlflow
CVSS v3.1 KEV CWE-918 PoC
12 Aug/26
CVE-2026-66384
MEDIUM

Artifactory does not properly constrain the pathname it derives when writing Docker layer data into the cache directory for remote repositories. Under specific remote-repository conditions the resolved path escapes the intended cache root, which is the classic path traversal pattern applied to a caching write rather than to a read.

CVSS 5.3
EPSS 0.7%
KEV Pred 77%
Product jfrog artifactory jfrog
CVSS v3.1 KEV CWE-22 PoC
11 Aug/26
CVE-2026-65660
HIGH

This vulnerability is a code injection flaw arising from improper control over code generation within Microsoft Office SharePoint Server 2016. The root cause lies in insufficient validation and sanitization of user-supplied input that is processed in SharePoint's code generation mechanisms. The affected component is the SharePoint Enterprise Server 2016 platform, specifically in its handling of input that influences dynamic code execution.

CVSS 8.8
EPSS 2.1%
KEV Pred 76%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-94 PoC RANSOMWARE
10 Aug/26
CVE-2026-72898
CRITICAL

Metabase concatenates user-supplied input directly into SQL statements at the reset_password database endpoint, without parameterization. The endpoint is reachable before authentication, so the injection point sits on the unauthenticated attack surface of the analytics server. This is a textbook SQL injection: the query structure is built from data the caller controls.

CVSS 10.0
EPSS 19.0%
KEV Pred 81%
Product Metabase metabase
CVSS v3.1 CVSS v4.0 KEV CWE-89 PoC
06 Aug/26
CVE-2026-65400
CRITICAL

This vulnerability is an authentication bypass issue rooted in improper state management within the Screen Sharing service of Apple macOS. The flaw allows network-based attackers to circumvent authentication controls by exploiting how session state is handled during the authentication process. The affected component is the Screen Sharing feature across multiple macOS versions, where authentication validation does not adequately verify credential legitimacy.

CVSS 9.8
EPSS 1.7%
KEV Pred 84%
Product Apple macOS apple
CVSS v3.1 KEV CWE-287 PoC
06 Aug/26
CVE-2026-5430
CRITICAL

This vulnerability is an authentication bypass caused by improper validation of JSON Web Tokens (JWT) in the WSO2 Universal Gateway's JWT authentication mechanism. The root cause lies in the acceptance of JWT tokens signed with algorithms that are not explicitly configured or supported by the system. This flaw affects the JWT authentication component responsible for verifying token signatures before granting access.

CVSS 10.0
EPSS 0.6%
KEV Pred 83%
Product WSO2 Universal Gateway wso2
CVSS v3.1 KEV CWE-347 PoC
02 Aug/26
CVE-2026-18577
HIGH

This vulnerability is an authentication bypass stemming from an incomplete patch applied to N-able N-central versions through 2026.3.1. The root cause lies in improper validation of authentication tokens within the access control mechanism, specifically affecting the authentication workflow component. The flaw allows bypassing normal authentication checks due to insufficient verification logic in the session validation process.

CVSS 8.1
EPSS 14.6%
KEV Pred 81%
Product N-able N-central n-able
CVSS v3.1 CVSS v4.0 KEV CWE-288 PoC
01 Aug/26
CVE-2026-18556
HIGH

This vulnerability is an authentication bypass in N-able N-central caused by improper validation of authentication mechanisms, allowing an attacker to circumvent normal authentication controls. The root cause lies in an alternate path or channel within the authentication process that fails to enforce required credentials. This flaw affects the authentication component of N-central versions through 2026.1, enabling unauthorized access through this bypass vector.

CVSS 7.4
EPSS 7.9%
KEV Pred 81%
Product N-able N-central n-able
CVSS v3.1 CVSS v4.0 KEV CWE-288 PoC
30 Jul/26
CVE-2026-59310
CRITICAL

This vulnerability is a directory traversal flaw within the VMware vCenter Syslog server component of VMware Cloud Foundation. The root cause lies in insufficient validation of file path inputs, allowing crafted requests to access arbitrary filesystem locations. This improper sanitization enables manipulation of file paths processed by the Syslog server, exposing underlying system directories.

CVSS 9.8
EPSS 2.6%
KEV Pred 93%
Product VMware Cloud Foundation vmware
CVSS v3.1 KEV CWE-22 PoC RANSOMWARE
17 Jul/26
CVE-2026-63030
CRITICAL

This vulnerability is a SQL Injection rooted in a route confusion within WordPress's REST API batch endpoint. The flaw arises from improper handling of the author__not_in parameter in WP_Query, which allows crafted queries to bypass intended filtering logic. The affected component is the REST API batch endpoint in WordPress versions prior to 6.9.5 and 7.0.2, where the route confusion leads to unintended query execution paths.

CVSS 9.8
EPSS 10.6%
KEV Pred 83%
Product WordPress wordpress
CVSS v3.1 KEV CWE-436 Exploit PoC
17 Jul/26
CVE-2026-60137
MEDIUM

This vulnerability is a SQL Injection flaw caused by improper sanitization of the author__not_in parameter within the WP_Query class of WordPress. The root cause lies in the failure to validate or escape untrusted input passed to this parameter, which is used to filter query results by excluding specific authors. The affected component is the WP_Query feature responsible for querying posts based on author exclusion criteria in WordPress versions prior to 6.8.6, 6.9.5, and 7.0.2.

CVSS 5.9
EPSS 5.3%
KEV Pred 83%
Product WordPress wordpress
CVSS v3.1 KEV CWE-89 Exploit PoC
17 Jul/26
CVE-2026-9198
CRITICAL

This vulnerability is a chained authentication bypass and arbitrary code execution flaw in IBM Langflow OSS versions 1.0.0 through 1.10.0. The root cause lies in the /api/v1/auto_login endpoint, which mints SUPERUSER tokens without authentication, combined with the /api/v1/validate/code endpoint that executes user-supplied code via the unsafe use of exec(). These two components together enable unauthorized execution of arbitrary commands on default Langflow deployments.

CVSS 9.8
EPSS 28.7%
KEV Pred 83%
Product IBM Langflow OSS ibm
CVSS v3.1 KEV CWE-94 Exploit PoC
17 Jul/26
CVE-2026-9586
CRITICAL

The /pa endpoint of Sangoma Switchvox SMB Edition processes XML documents beginning with a PolycomIPPhone element and concatenates the user-controlled PhoneIP value straight into PostgreSQL queries, with no sanitization and no parameterization. The endpoint answers before authentication, so the injection is reachable by anyone who can send an HTTP request to the PBX.

CVSS 9.8
EPSS 19.0%
KEV Pred 81%
Product Sangoma Switchvox SMB Edition sangoma
CVSS v3.1 CVSS v4.0 KEV CWE-89 PoC
14 Jul/26
CVE-2026-15410
HIGH

This vulnerability is a post-authentication code injection flaw rooted in improper control over code generation within the SonicWall SMA1000 Appliance Management Console (AMC). The vulnerability arises due to insufficient validation of user-supplied input that is incorporated into command execution contexts. The affected component is the AMC interface, which processes administrative commands and configurations.

CVSS 7.2
EPSS 11.8%
KEV Pred 81%
Product SonicWall SMA1000 sonicwall
CVSS v3.1 KEV CWE-94 Exploit PoC RANSOMWARE
14 Jul/26
CVE-2026-15409
CRITICAL

This vulnerability is a Server-Side Request Forgery (SSRF) affecting the SonicWall SMA1000 Appliance Work Place interface. The root cause lies in improper validation of user-supplied URLs, allowing the appliance to be manipulated into making arbitrary HTTP requests. The flaw exists within the appliance's internal request handling mechanism, specifically in the interface that processes incoming request parameters without adequate origin verification.

CVSS 10.0
EPSS 6.8%
KEV Pred 92%
Product SonicWall SMA1000 sonicwall
CVSS v3.1 KEV CWE-918 Exploit PoC RANSOMWARE
14 Jul/26
CVE-2026-50522
CRITICAL

This vulnerability is a deserialization flaw arising from improper handling of untrusted data within Microsoft Office SharePoint's deserialization routines. The root cause lies in insecure deserialization logic that processes serialized objects without adequate validation or sanitization. The affected component is the Microsoft SharePoint Enterprise Server 2016, specifically its data processing mechanisms that deserialize incoming network data.

CVSS 9.8
EPSS 3.0%
KEV Pred 81%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-502 PoC RANSOMWARE
14 Jul/26
CVE-2026-56164
MEDIUM

This vulnerability is an authentication bypass affecting Microsoft SharePoint Enterprise Server 2016. The root cause is the absence of proper authentication controls on a critical function within the SharePoint service, allowing unauthorized network access. The flaw resides specifically in the SharePoint server's access control mechanism for privileged operations.

CVSS 5.3
EPSS 1.0%
KEV Pred 81%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-306 PoC RANSOMWARE
09 Jul/26
CVE-2026-56291
CRITICAL

This vulnerability is an unauthenticated arbitrary file upload flaw in the Balbooa Forms extension for Joomla. The root cause lies in insufficient validation and sanitization of uploaded files within the form submission handler, allowing executable files to be accepted and stored. The affected component is the file upload functionality of the Balbooa Forms Joomla extension, which fails to restrict file types or enforce authentication checks before processing uploads.

CVSS 9.8
EPSS 14.9%
KEV Pred 92%
Product balbooa.com Balbooa Forms extension for Joomla balbooa.com
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
08 Jul/26
CVE-2026-59822
HIGH

LiteLLM's MCP Streamable HTTP endpoint falls back to an OAuth2 passthrough path when LiteLLM key validation fails, and that fallback replaces the failed validation with an empty UserAPIKeyAuth() object. An empty auth object is treated as a successful authentication result rather than as an absence of one, so a fabricated Authorization header is enough to take the fallback branch and arrive authenticated.

CVSS 8.2
EPSS 0.8%
KEV Pred 81%
Product BerriAI litellm berriai
CVSS v3.1 CVSS v4.0 KEV CWE-287 PoC
30 Jun/26
CVE-2026-48282
CRITICAL

This vulnerability is a path traversal flaw caused by improper limitation of pathname access within Adobe ColdFusion's file handling components. The root cause lies in insufficient validation of user-supplied file path inputs, allowing navigation outside intended restricted directories. The affected feature is the ColdFusion server's file system access mechanism that processes pathname parameters without adequate sanitization, enabling unauthorized directory traversal.

CVSS 10.0
EPSS 42.4%
KEV Pred 93%
Product Adobe ColdFusion adobe
CVSS v3.1 KEV CWE-22 PoC RANSOMWARE
30 Jun/26
CVE-2026-8452
CRITICAL

NetScaler ADC and NetScaler Gateway mishandle the bounds of a memory buffer, so processing certain input drives an overflow inside the appliance's request handling. The condition arises when the appliance is configured as a Gateway, covering SSL VPN, ICA Proxy, CVPN and RDP Proxy roles, or as an AAA virtual server; a device without one of those roles does not expose the affected path.

CVSS 9.8
EPSS 1.0%
KEV Pred 83%
Product NetScaler ADC netscaler
CVSS v3.1 CVSS v4.0 KEV CWE-119 PoC
29 Jun/26
CVE-2026-56290
CRITICAL

This vulnerability is an unauthenticated arbitrary file upload flaw in the JoomlaCK.fr Page Builder CK extension for Joomla versions prior to 3.6.0. The root cause lies in insufficient validation and sanitization of uploaded files within the Page Builder CK component, allowing attackers to upload executable files without authentication. The affected feature is the file upload functionality of the Page Builder CK extension.

CVSS 9.8
EPSS 30.9%
KEV Pred 90%
Product JoomlaCK.fr Page Builder CK extension for Joomla joomlack.fr
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
26 Jun/26
CVE-2026-49869
CRITICAL

The AuthenticationFilter in Kestra OSS whitelists the public configuration endpoint from Basic Auth using request.getPath().endsWith("/configs"), a suffix match where an exact path comparison was intended. Any API path whose final segment happens to be configs therefore skips authentication entirely. The flaw is in the filter's matching logic, so it applies across the API surface rather than to one endpoint.

CVSS 10.0
EPSS 2.1%
KEV Pred 78%
Product kestra-io kestra kestra-io
CVSS v3.1 KEV CWE-78 PoC
23 Jun/26
CVE-2026-55255
HIGH

This vulnerability is an Insecure Direct Object Reference (IDOR) affecting the /api/v1/responses endpoint of langflow-ai langflow. The root cause is insufficient access control validation on user-specific flow identifiers, allowing authenticated users to specify arbitrary flow IDs without proper authorization checks. This flaw resides in the API component responsible for executing user-defined AI workflow flows.

CVSS 8.4
EPSS 0.9%
KEV Pred 79%
Product langflow-ai langflow langflow-ai
CVSS v3.1 KEV CWE-639 PoC
20 Jun/26
CVE-2026-48939
CRITICAL

The vulnerability is an arbitrary file upload flaw rooted in improper validation of file attachments within the iCagenda extension for Joomla. The file attachment feature lacks sufficient sanitization and filtering controls, enabling the upload of malicious files. This weakness resides specifically in the file handling component of the iCagenda extension, allowing attackers to bypass restrictions on executable content types.

CVSS 9.8
EPSS 20.1%
KEV Pred 81%
Product icagenda.com iCagenda extension for Joomla icagenda.com
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
15 Jun/26
CVE-2026-20262
MEDIUM

This vulnerability is a path traversal flaw (CWE-22) in the file upload functionality of Cisco Catalyst SD-WAN Manager's web UI. The root cause is improper validation of user-supplied input during the file upload process, allowing crafted input to manipulate file paths. The affected component is the API endpoint handling file uploads within the web management interface.

CVSS 6.5
EPSS 28.2%
KEV Pred 77%
Product Cisco Catalyst SD-WAN Manager cisco
CVSS v3.1 KEV CWE-22 PoC
14 Jun/26
CVE-2026-54420
HIGH

This vulnerability is a symbolic link (symlink) traversal issue in the LiteSpeed cPanel plugin and LiteSpeed WHM plugin components. The root cause lies in improper validation and handling of user-supplied symlink paths within the plugin's file management routines. Specifically, the plugin fails to correctly restrict symlink resolution for users with FTP or web shell access on shared hosting environments using CloudLinux/CageFS, enabling unauthorized access to filesystem locations outside intended boundaries.

CVSS 8.5
EPSS 0.8%
KEV Pred 81%
Product LiteSpeed Technologies cPanel Plugin litespeed
CVSS v3.1 KEV CWE-61 PoC
Page 1 of 4 (182 total)