Cut the noise.
Know which vulnerabilities demand action.

Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.

Analytics

EPSS Trending (30d)

Threat Indicators

865
CISA KEV
251
Exploits
519
Proof-of-Concept
84.0%
Average EPSS

EPSS Hot Zone

|
Sort by:
KEV Prediction — Top%
EPSS Percentile — Top%

Emerging Vulnerabilities

22 Jul/26
CVE-2026-16232
CRITICAL

This vulnerability is an authentication bypass affecting the Check Point SmartConsole login process within the Quantum Security Management product. The root cause lies in improper validation of authentication tokens during the login sequence, allowing an unauthenticated attacker to retrieve a valid application login token. The flaw specifically impacts the authentication mechanism of the Management Server component when Trusted Clients restrictions are not enforced.

CVSS 9.8
EPSS 73.3%
KEV Pred 73%
Product checkpoint Quantum Security Management checkpoint
CVSS v3.1 CVSS v4.0 KEV CWE-287 PoC
17 Jul/26
CVE-2026-63030
CRITICAL

This vulnerability is a SQL injection rooted in a route confusion issue within the WordPress REST API batch endpoint. The flaw arises from improper handling of the author__not_in parameter in WP_Query, which allows crafted queries to bypass intended filtering. The affected component is the REST API batch endpoint in WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2, where route resolution errors enable injection of malicious SQL commands.

CVSS 9.8
EPSS 95.6%
KEV Pred 71%
Product WordPress wordpress
CVSS v3.1 KEV CWE-436 Exploit PoC
17 Jul/26
CVE-2026-60137
MEDIUM

This vulnerability is a SQL Injection flaw caused by improper sanitization of the author__not_in parameter within the WP_Query component of WordPress. The root cause lies in the failure to validate or escape untrusted input passed to this parameter, allowing malicious input to be interpreted as part of an SQL query. This affects the query construction logic in WordPress versions prior to 6.8.6, 6.9.5, and 7.0.2.

CVSS 5.9
EPSS 73.1%
KEV Pred 70%
Product WordPress wordpress
CVSS v3.1 KEV CWE-89 Exploit PoC
14 Jul/26
CVE-2026-15410
HIGH

This vulnerability is a post-authentication code injection flaw rooted in improper control over code generation within the SonicWall SMA1000 Appliance Management Console (AMC). The vulnerability arises due to insufficient validation of user-supplied input that is incorporated into command execution contexts. The affected component is the AMC interface, which processes administrative commands and configurations.

CVSS 7.2
EPSS 76.3%
KEV Pred 65%
Product SonicWall SMA1000 sonicwall
CVSS v3.1 KEV CWE-94 Exploit PoC RANSOMWARE
14 Jul/26
CVE-2026-15409
CRITICAL

This vulnerability is a Server-Side Request Forgery (SSRF) affecting the SonicWall SMA1000 Appliance Work Place interface. The root cause lies in improper validation of user-supplied URLs, allowing the appliance to be manipulated into making arbitrary HTTP requests. The flaw exists within the appliance's internal request handling mechanism, specifically in the interface that processes incoming request parameters without adequate origin verification.

CVSS 10.0
EPSS 74.2%
KEV Pred 73%
Product SonicWall SMA1000 sonicwall
CVSS v3.1 KEV CWE-918 Exploit PoC RANSOMWARE
14 Jul/26
CVE-2026-50522
CRITICAL

This vulnerability is a deserialization flaw in Microsoft Office SharePoint's handling of untrusted data. The root cause lies in insecure deserialization logic within SharePoint Enterprise Server 2016 and related versions, where unvalidated input is processed by deserialization routines. This affects the SharePoint server component responsible for processing serialized data objects over network requests.

CVSS 9.8
EPSS 77.0%
KEV Pred 78%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-502 PoC RANSOMWARE
09 Jul/26
CVE-2026-56291
CRITICAL

This vulnerability is an unauthenticated arbitrary file upload flaw in the Balbooa Forms extension for Joomla. The root cause lies in insufficient validation and sanitization of uploaded files within the form submission handler, allowing executable files to be accepted and stored. The affected component is the file upload functionality of the Balbooa Forms Joomla extension, which fails to restrict file types or enforce authentication checks before processing uploads.

CVSS 9.8
EPSS 76.1%
KEV Pred 67%
Product balbooa.com Balbooa Forms extension for Joomla balbooa.com
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
30 Jun/26
CVE-2026-48282
CRITICAL

This vulnerability is a path traversal flaw caused by insufficient validation of user-supplied file path inputs within Adobe ColdFusion. The affected component improperly restricts pathname access, allowing attackers to traverse directories outside intended boundaries. This weakness occurs in ColdFusion versions 2023 and earlier, impacting the file handling mechanisms responsible for directory access control.

CVSS 10.0
EPSS 99.2%
KEV Pred 82%
Product Adobe ColdFusion adobe
CVSS v3.1 KEV CWE-22 PoC RANSOMWARE
29 Jun/26
CVE-2026-56290
CRITICAL

This vulnerability is an unauthenticated arbitrary file upload flaw in the JoomlaCK.fr Page Builder CK extension for Joomla. The root cause lies in insufficient validation and filtering of uploaded files within the extension's file upload functionality. The affected component is the file upload handler that processes incoming files without proper authentication or content-type restrictions, enabling malicious payloads to be uploaded.

CVSS 9.8
EPSS 83.3%
KEV Pred 62%
Product JoomlaCK.fr Page Builder CK extension for Joomla joomlack.fr
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
20 Jun/26
CVE-2026-48908
CRITICAL

This vulnerability is an unrestricted file upload flaw in the SP Page Builder extension for Joomla. The root cause is insufficient validation and sanitization of uploaded files, allowing unauthenticated users to upload arbitrary files, including executable PHP scripts. The affected component is the file upload functionality within the SP Page Builder extension.

CVSS 9.8
EPSS 88.1%
KEV Pred 58%
Product joomshaper.net SP Page Builder extension for Joomla joomshaper.net
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
20 Jun/26
CVE-2026-48939
CRITICAL

The vulnerability is an arbitrary file upload flaw rooted in improper validation of file attachments within the iCagenda extension for Joomla. The file attachment feature lacks sufficient sanitization and filtering controls, enabling the upload of malicious files. This weakness resides specifically in the file handling component of the iCagenda extension, allowing attackers to bypass restrictions on executable content types.

CVSS 9.8
EPSS 82.5%
KEV Pred 59%
Product icagenda.com iCagenda extension for Joomla icagenda.com
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
11 Jun/26
CVE-2026-35273
CRITICAL

This vulnerability is an authentication bypass flaw in the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools. The root cause is insufficient access control on HTTP endpoints responsible for environment updates, allowing unauthenticated network requests to interact with privileged management functions. Affected components are versions 8.61 and 8.62 of PeopleSoft Enterprise PeopleTools.

CVSS 9.8
EPSS 95.5%
KEV Pred 69%
Product Oracle Corporation PeopleSoft Enterprise PeopleTools oracle
CVSS v3.1 KEV CWE-306 PoC RANSOMWARE
10 Jun/26
CVE-2026-20253
CRITICAL

This vulnerability is an authentication bypass affecting the PostgreSQL sidecar service endpoint in Splunk Enterprise. The root cause is the absence of authentication controls on this endpoint, which allows unauthenticated network users to invoke file operations. The affected component is the PostgreSQL sidecar service integrated within Splunk Enterprise versions prior to 10.2.4 and 10.0.7.

CVSS 9.8
EPSS 96.9%
KEV Pred 61%
Product Splunk Enterprise splunk
CVSS v3.1 KEV CWE-306 PoC
09 Jun/26
CVE-2026-25089
CRITICAL

This vulnerability is an OS command injection flaw caused by improper neutralization of special elements within HTTP request parameters. The root cause lies in Fortinet FortiSandbox's failure to sanitize user-supplied input before incorporating it into operating system commands. Affected components include FortiSandbox versions 4.2.x, 4.4.0 through 4.4.8, 5.0.0 through 5.0.5, FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5.

CVSS 9.8
EPSS 73.6%
KEV Pred 80%
Product Fortinet FortiSandbox fortinet
CVSS v3.1 KEV CWE-78 PoC RANSOMWARE
09 Jun/26
CVE-2026-10520
CRITICAL

The vulnerability is an OS command injection rooted in improper input validation within Ivanti Sentry's command execution routines. Specifically, the affected component fails to sanitize user-supplied input before passing it to underlying system shell commands. This flaw exists in versions prior to R10.5.2, R10.6.2, and R10.7.1, impacting the command processing mechanism that interfaces with the operating system shell.

CVSS 10.0
EPSS 99.9%
KEV Pred 77%
Product ivanti Sentry ivanti
CVSS v3.1 KEV CWE-78 PoC RANSOMWARE
08 Jun/26
CVE-2026-50751
CRITICAL

This vulnerability is an authentication bypass caused by a logic flaw in the certificate validation process within the deprecated IKEv1 key exchange protocol. The flaw exists in the Remote Access and Mobile Access components of the Check Point Quantum Security Gateway, specifically in the handling of certificate validation during VPN connection establishment. The root cause is improper validation logic that fails to verify user credentials correctly, allowing unauthorized access through the affected authentication mechanism.

CVSS 9.3
EPSS 82.6%
KEV Pred 79%
Product checkpoint Quantum Security Gateway checkpoint
CVSS v3.1 KEV CWE-287 PoC RANSOMWARE
05 Jun/26
CVE-2026-48907
CRITICAL

The vulnerability is an authentication bypass in the Joomla Content Editor (JCE) extension for Joomla, allowing unauthenticated users to create new editor profiles. This flaw arises from improper access control validation in the profile creation component of the JCE editor. The affected feature is the editor profile management functionality within the JCE extension, which fails to restrict profile creation to authorized users only.

CVSS 9.8
EPSS 68.8%
KEV Pred 54%
Product joomlacontenteditor.net Joomla Content Editor (JCE) extension for Joomla joomlacontenteditor.net
CVSS v3.1 CVSS v4.0 KEV CWE-284 Exploit PoC
04 Jun/26
CVE-2026-8037
CRITICAL

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

CVSS 9.8
EPSS 99.3%
KEV Pred 72%
Product Progress Software LoadMaster progress
CVSS v3.1 KEV CWE-77 PoC
03 Jun/26
CVE-2026-20230
HIGH

This vulnerability is a server-side request forgery (SSRF) arising from improper input validation of specific HTTP requests in Cisco Unified Communications Manager and its Session Management Edition. The flaw exists within the WebDialer service component, which processes HTTP requests without sufficient sanitization, allowing crafted requests to manipulate internal server behavior. The root cause is the lack of validation on input parameters that control file operations on the underlying operating system.

CVSS 8.6
EPSS 83.2%
KEV Pred 69%
Product Cisco Unified Communications Manager cisco
CVSS v3.1 KEV CWE-918 PoC
22 May/26
CVE-2026-34910
CRITICAL

This vulnerability is a command injection flaw resulting from improper input validation in UniFi OS Server and related UniFi firmware components. The root cause lies in the failure to sanitize user-supplied input before passing it to system-level command execution functions. Affected components include UniFi OS Server and multiple UniFi device firmware versions, where network-accessible interfaces process untrusted input without adequate validation.

CVSS 10.0
EPSS 87.0%
KEV Pred 82%
Product Ubiquiti Inc UniFi OS Server ubiquiti
CVSS v3.1 KEV CWE-20 PoC
22 May/26
CVE-2026-34908
CRITICAL

This vulnerability is an Improper Access Control flaw affecting Ubiquiti UniFi OS Server and related firmware components. The root cause lies in insufficient enforcement of authorization checks within system management interfaces, allowing unauthorized network actors to interact with privileged functions. The affected components include UniFi OS devices and various UniFi Dream Machine firmware variants, where control mechanisms fail to restrict access to critical configuration endpoints.

CVSS 10.0
EPSS 85.2%
KEV Pred 80%
Product Ubiquiti Inc UniFi OS Server ubiquiti
CVSS v3.1 KEV CWE-284 PoC
22 May/26
CVE-2026-34909
CRITICAL

This vulnerability is a Path Traversal flaw (CWE-22) in Ubiquiti UniFi OS Server and related firmware components. The root cause is insufficient validation of user-supplied file path inputs, allowing traversal sequences to access files outside the intended directory scope. The affected components include UniFi OS Server and various UniFi device firmware versions that handle file requests without proper sanitization.

CVSS 10.0
EPSS 63.9%
KEV Pred 83%
Product Ubiquiti Inc UniFi OS Server ubiquiti
CVSS v3.1 KEV CWE-22
20 May/26
CVE-2026-9082
CRITICAL

This vulnerability is a SQL Injection flaw resulting from improper neutralization of special elements within SQL commands in Drupal core. The root cause lies in insufficient input sanitization allowing crafted input to alter SQL queries. The affected component is Drupal core versions from 8.9.0 up to but not including specified patched releases across multiple major versions, impacting database query handling mechanisms.

CVSS 9.8
EPSS 88.3%
KEV Pred 69%
Product Drupal core drupal
CVSS v3.1 KEV CWE-89 PoC
14 May/26
CVE-2026-42897
MEDIUM

The vulnerability is a cross-site scripting (XSS) flaw caused by improper neutralization of user-supplied input during web page generation in Microsoft Exchange Server 2016 Cumulative Update 23. This occurs due to insufficient sanitization of input data processed by the web interface, allowing malicious scripts to be injected into dynamically generated pages. The affected component is the web-based management interface of Microsoft Exchange Server 2016 CU23.

CVSS 6.1
EPSS 70.3%
KEV Pred 82%
Product Microsoft Exchange Server 2016 Cumulative Update 23 microsoft
CVSS v3.1 KEV CWE-79 PoC RANSOMWARE
14 May/26
CVE-2026-20182
CRITICAL

This vulnerability is an authentication bypass in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller and Manager. The root cause lies in improper validation during the control connection handshaking process, allowing crafted requests to circumvent authentication checks. The affected component is the peering authentication feature responsible for establishing secure control connections within the SD-WAN fabric.

CVSS 10.0
EPSS 91.5%
KEV Pred 68%
Product Cisco Catalyst SD-WAN Manager cisco
CVSS v3.1 KEV CWE-287 Exploit PoC RANSOMWARE
13 May/26
CVE-2026-0257
CRITICAL

This vulnerability is an authentication bypass affecting the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS software. The root cause lies in improper validation of authentication mechanisms allowing unauthorized users to circumvent security checks. The flaw specifically impacts the VPN authentication process, enabling access without valid credentials.

CVSS 9.1
EPSS 93.9%
KEV Pred 78%
Product Palo Alto Networks Cloud NGFW palo
CVSS v3.1 CVSS v4.0 KEV CWE-565 PoC RANSOMWARE
08 May/26
CVE-2026-42208
CRITICAL

This vulnerability is a SQL injection caused by improper handling of user-supplied input in a database query. Specifically, the proxy server component of LiteLLM improperly concatenates the Authorization header value directly into the SQL query string instead of using parameterized queries. The affected feature is the API key verification mechanism within the proxy’s error-handling path that interacts with the backend database.

CVSS 9.8
EPSS 89.4%
KEV Pred 65%
Product BerriAI litellm berriai
CVSS v3.1 CVSS v4.0 KEV CWE-89 Exploit PoC
08 May/26
CVE-2026-42271
HIGH

This vulnerability is a command injection flaw in the LiteLLM proxy server component, specifically affecting the AI Gateway's handling of server configuration inputs. The root cause lies in two POST endpoints (/mcp-rest/test/connection and /mcp-rest/test/tools/list) that accept unvalidated server configuration data, including command, args, and env fields, which are executed via stdio transport as subprocesses with proxy process privileges. The lack of role-based access control combined with acceptance of arbitrary commands enables exploitation.

CVSS 8.8
EPSS 83.0%
KEV Pred 76%
Product BerriAI litellm berriai
CVSS v3.1 CVSS v4.0 KEV CWE-77 PoC
29 Apr/26
CVE-2026-41940
CRITICAL

This vulnerability is an authentication bypass in the login flow of cPanel and WHM versions post-11.40. The root cause lies in improper validation of authentication tokens or session states, allowing unauthenticated requests to circumvent normal login procedures. The affected component is the web-based control panel authentication mechanism, specifically the login endpoint handling user credential verification.

CVSS 9.8
EPSS 98.1%
KEV Pred 69%
Product cPanel cpanel
CVSS v3.1 CVSS v4.0 KEV CWE-306 Exploit PoC RANSOMWARE
14 Apr/26
CVE-2026-33824
CRITICAL

This vulnerability is a double free memory corruption issue occurring within the Windows IKE (Internet Key Exchange) Extension component. The root cause stems from improper handling of memory allocation and deallocation sequences, where the same memory region is freed multiple times during processing of network packets. This flaw affects the Windows 10 operating system versions 1607, 1809, and 21H2 across multiple architectures including x64, x86, and ARM64.

CVSS 9.8
EPSS 77.9%
KEV Pred 69%
Product Microsoft Windows 10 Version 1607 microsoft
CVSS v3.1 KEV CWE-415 PoC RANSOMWARE
14 Apr/26
CVE-2026-32202
MEDIUM

This vulnerability is a protection mechanism failure classified under spoofing attacks within the Windows Shell component. The root cause lies in inadequate validation and enforcement of security boundaries in the shell's network communication processes, allowing crafted inputs to bypass expected protections. Specifically, the flaw affects the Windows Shell's handling of network-originated data, enabling unauthorized manipulation of shell interactions.

CVSS 4.3
EPSS 63.7%
KEV Pred 79%
Product Microsoft Windows 10 Version 1607 microsoft
CVSS v3.1 KEV CWE-693 PoC RANSOMWARE
14 Apr/26
CVE-2026-39808
CRITICAL

This vulnerability is an OS command injection flaw caused by improper neutralization of special elements in user-supplied input within Fortinet FortiSandbox versions 4.4.0 through 4.4.8. The root cause lies in inadequate sanitization and validation of input parameters that are subsequently passed to underlying operating system commands. The affected component is the FortiSandbox's command execution interface that processes these inputs without sufficient filtering, enabling injection of arbitrary OS commands.

CVSS 9.8
EPSS 91.2%
KEV Pred 79%
Product Fortinet FortiSandbox fortinet
CVSS v3.1 KEV CWE-78 PoC RANSOMWARE
09 Apr/26
CVE-2026-34486
HIGH

This vulnerability is a missing encryption flaw in Apache Tomcat resulting from an incomplete fix of a prior issue that allowed bypassing the EncryptInterceptor component. The root cause lies in the failure to properly enforce encryption on sensitive data within the request processing pipeline. Specifically, the EncryptInterceptor, responsible for encrypting data, can be circumvented due to a logic flaw introduced in versions 9.0.116, 10.1.53, and 11.0.20 of Apache Tomcat.

CVSS 7.5
EPSS 82.9%
KEV Pred 69%
Product Apache Software Foundation Apache Tomcat apache
CVSS v3.1 KEV CWE-311 PoC RANSOMWARE
09 Apr/26
CVE-2026-39987
CRITICAL

This vulnerability is an authentication bypass in the marimo reactive Python notebook's WebSocket terminal interface. The root cause lies in the /terminal/ws endpoint, which omits the required authentication validation by skipping the validate_auth() call. Instead, it only verifies the running mode and platform support before establishing connections, exposing the terminal WebSocket to unauthenticated access.

CVSS 9.8
EPSS 96.6%
KEV Pred 67%
Product marimo-team marimo marimo-team
CVSS v3.1 CVSS v4.0 KEV CWE-306 PoC
07 Apr/26
CVE-2026-34197
HIGH

This vulnerability is a code injection flaw caused by improper input validation and control of code generation within Apache ActiveMQ Broker's Jolokia JMX-HTTP bridge. The affected component is the Jolokia endpoint exposed at /api/jolokia/ on the web console, where the default access policy allows execution of operations on all ActiveMQ MBeans. The root cause lies in the BrokerService's acceptance of crafted discovery URIs that trigger loading of remote Spring XML application contexts before configuration validation, enabling injection of malicious code via bean instantiation.

CVSS 8.8
EPSS 97.2%
KEV Pred 54%
Product Apache Software Foundation Apache ActiveMQ Broker apache
CVSS v3.1 KEV CWE-20 Exploit PoC
04 Apr/26
CVE-2026-35616
CRITICAL

This vulnerability is an improper access control flaw in Fortinet FortiClientEMS versions 7.4.5 and 7.4.6. The root cause lies in the failure to enforce authentication checks on certain API endpoints, allowing unauthenticated requests to invoke privileged functions. The affected component is the FortiClientEMS management server handling incoming API requests.

CVSS 9.8
EPSS 90.7%
KEV Pred 79%
Product Fortinet FortiClientEMS fortinet
CVSS v3.1 KEV CWE-284 PoC RANSOMWARE
23 Mar/26
CVE-2026-33634
HIGH

This vulnerability is a supply chain compromise involving credential theft and unauthorized code injection. The root cause is improper credential management and non-atomic credential rotation, which allowed an attacker to use valid tokens to push malicious commits and replace version tags in GitHub repositories. The affected components include the aquasecurity Trivy binary (version 0.69.4), the trivy-action GitHub Action (versions 0.0.1 to 0.34.2), and the setup-trivy GitHub Action (versions 0.2.0 to 0.2.6).

CVSS 8.8
EPSS 59.2%
KEV Pred 79%
Product aquasecurity setup-trivy aquasecurity
CVSS v3.1 CVSS v4.0 KEV CWE-506 PoC RANSOMWARE
23 Mar/26
CVE-2026-3055
CRITICAL

This vulnerability is a memory overread caused by insufficient input validation within the SAML Identity Provider (IDP) functionality of NetScaler ADC and NetScaler Gateway. Specifically, the flaw arises when processing malformed SAML assertions or requests, leading to out-of-bounds memory access. The affected components are the NetScaler ADC and NetScaler Gateway platforms configured as SAML IDPs, where input handling routines fail to properly verify data boundaries.

CVSS 9.8
EPSS 84.5%
KEV Pred 80%
Product NetScaler ADC netscaler
CVSS v3.1 CVSS v4.0 KEV CWE-125 Exploit PoC
20 Mar/26
CVE-2026-33017
CRITICAL

This vulnerability is an unauthenticated remote code execution caused by improper input validation and insecure code execution. The affected component is the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint in langflow-ai langflow versions prior to 1.9.0. The root cause is that the endpoint accepts attacker-controlled flow data containing arbitrary Python code, which is executed via Python's exec() function without sandboxing or authentication checks.

CVSS 9.8
EPSS 96.2%
KEV Pred 71%
Product langflow-ai langflow langflow-ai
CVSS v3.1 CVSS v4.0 KEV CWE-94 Exploit PoC
25 Feb/26
CVE-2026-20127
CRITICAL

This vulnerability is an authentication bypass affecting the peering authentication mechanism in Cisco Catalyst SD-WAN Controller and Manager components. The root cause lies in improper validation of authentication requests during the peering process, which fails to enforce correct credentials. This flaw resides specifically within the peering authentication subsystem responsible for establishing trust between SD-WAN nodes.

CVSS 10.0
EPSS 88.2%
KEV Pred 80%
Product Cisco Catalyst SD-WAN Manager cisco
CVSS v3.1 KEV CWE-287 Exploit PoC RANSOMWARE
10 Feb/26
CVE-2026-1603
HIGH

This vulnerability is an authentication bypass in Ivanti Endpoint Manager versions prior to 2024 SU5. It stems from improper access control mechanisms within the RemoteControlAuth API, specifically the POST /RemoteControlAuth/api/Auth endpoint. The flaw allows unauthenticated remote actors to bypass normal authentication checks and access sensitive credential data stored by the application.

CVSS 7.5
EPSS 80.6%
KEV Pred 80%
Product Ivanti Endpoint Manager ivanti
CVSS v3.1 KEV CWE-288
06 Feb/26
CVE-2026-1731
CRITICAL

This vulnerability is a pre-authentication remote code execution caused by improper input validation in BeyondTrust Remote Support and older Privileged Remote Access versions. The root cause lies in the WebSocket endpoint /nw, which accepts binary payloads without adequate sanitization, allowing injection of operating system commands. The affected components are the WebSocket service and the mechanism that retrieves the company identifier via the /get_mech_list endpoint, which is exploited to authenticate the malicious WebSocket connection.

CVSS 9.8
EPSS 88.6%
KEV Pred 81%
Product BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA) beyondtrust
CVSS v3.1 CVSS v4.0 KEV CWE-78 Exploit PoC RANSOMWARE
06 Feb/26
CVE-2026-21643
CRITICAL

This vulnerability is a SQL injection flaw rooted in improper neutralization of special characters within SQL commands. The issue arises from insufficient input validation in the Fortinet FortiClientEMS web interface, allowing crafted HTTP requests to manipulate backend database queries. The affected component is the FortiClientEMS management system version 7.4.4, specifically its handling of SQL statements triggered by user-supplied input.

CVSS 9.8
EPSS 94.1%
KEV Pred 83%
Product Fortinet FortiClientEMS fortinet
CVSS v3.1 KEV CWE-89 PoC RANSOMWARE
29 Jan/26
CVE-2026-1340
CRITICAL

This vulnerability is a code injection flaw rooted in improper input validation within Ivanti Endpoint Manager Mobile. The affected component fails to sanitize user-supplied data before processing, enabling malicious payloads to be injected and executed. The flaw resides in the core mobile management service handling remote commands or scripts without adequate security controls.

CVSS 9.8
EPSS 86.0%
KEV Pred 73%
Product Ivanti Endpoint Manager Mobile ivanti
CVSS v3.1 KEV CWE-94 Exploit RANSOMWARE
29 Jan/26
CVE-2026-1281
CRITICAL

This vulnerability is a code injection flaw rooted in improper handling of user-supplied input within Ivanti Endpoint Manager Mobile. Specifically, the affected component fails to sanitize input parameters, enabling injection of arbitrary code into the execution context. The flaw resides in the mobile management interface, which processes remote requests without adequate validation, allowing attackers to inject and execute code remotely without authentication.

CVSS 9.8
EPSS 81.5%
KEV Pred 77%
Product Ivanti Endpoint Manager Mobile ivanti
CVSS v3.1 KEV CWE-94 Exploit PoC RANSOMWARE
28 Jan/26
CVE-2025-40551
CRITICAL

This vulnerability is an unsafe deserialization flaw within the jabsorb JSON-RPC library used by SolarWinds Web Help Desk. The root cause lies in the insecure handling of serialized data objects, allowing manipulation of the deserialization process. The affected component is the Apache Xalan JNDIConnectionPool class, which is exploited through crafted JSON-RPC requests processed by the web application.

CVSS 9.8
EPSS 83.6%
KEV Pred 75%
Product SolarWinds Web Help Desk solarwinds
CVSS v3.1 KEV CWE-502 Exploit
28 Jan/26
CVE-2025-40536
CRITICAL

This vulnerability is a security control bypass affecting SolarWinds Web Help Desk, rooted in insufficient enforcement of access restrictions within the application's web interface. The flaw allows unauthenticated users to circumvent authentication and authorization controls, exposing restricted administrative functions. The affected component is the Web Help Desk application prior to version 12.8.8 Hotfix 1, where access control mechanisms fail to properly validate user privileges on sensitive endpoints.

CVSS 9.8
EPSS 71.5%
KEV Pred 71%
Product SolarWinds Web Help Desk solarwinds
CVSS v3.1 KEV CWE-693 Exploit PoC
27 Jan/26
CVE-2026-24858
CRITICAL

This vulnerability is an authentication bypass caused by improper validation of FortiCloud SSO authentication tokens. The flaw resides in Fortinet FortiOS and associated products, where the authentication mechanism fails to correctly verify user-device bindings. This allows an attacker with a valid FortiCloud account and a registered device to exploit alternate authentication paths, bypassing standard credential checks within the FortiCloud SSO integration component.

CVSS 9.8
EPSS 85.8%
KEV Pred 69%
Product Fortinet FortiOS fortinet
CVSS v3.1 KEV CWE-288 PoC RANSOMWARE
23 Jan/26
CVE-2026-24423
CRITICAL

This vulnerability is an unauthenticated remote code execution flaw caused by missing authentication controls in the ConnectToHub API method of SmarterTools SmarterMail. The root cause is that the ConnectToHub function accepts and executes OS commands obtained from an external HTTP server without validating the source or requiring authentication. This affects SmarterMail versions prior to build 9511, specifically the ConnectToHub API component responsible for hub communication.

CVSS 9.8
EPSS 87.7%
KEV Pred 77%
Product SmarterTools SmarterMail smartertools
CVSS v3.1 CVSS v4.0 KEV CWE-306 PoC RANSOMWARE
23 Jan/26
CVE-2026-0770
CRITICAL

This vulnerability is a remote code execution flaw caused by improper handling of the exec_globals parameter in Langflow's validate endpoint. The root cause lies in the inclusion of resources from an untrusted control sphere, allowing unvalidated input to be executed within the application's global execution context. The affected component is the exec_globals parameter processing within the validate API endpoint of Langflow.

CVSS 9.8
EPSS 62.9%
KEV Pred 69%
Product Langflow langflow
CVSS v3.1 KEV CWE-829 PoC
Page 1 of 11 (505 total)