Cut the noise.
Know which vulnerabilities demand action.

Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.

Analytics

EPSS Trending (30d)

Threat Indicators

915
CISA KEV
266
Exploits
574
Proof-of-Concept
84.1%
Average EPSS

EPSS Hot Zone

|
Sort by:
KEV Prediction — Top%
EPSS Percentile — Top%

Emerging Vulnerabilities

12 Sep/26
CVE-2026-85706
CRITICAL

This vulnerability is a directory traversal flaw caused by improper path confinement and lack of authentication enforcement within the GitLab repository commits API. The root cause lies in the API's failure to validate and restrict file path inputs, allowing unauthorized access to files outside intended directories. The affected component is the repository commits API in GitLab Community and Enterprise Editions across multiple versions prior to specific patch releases.

CVSS 10.0
EPSS 93.0%
KEV Pred in 3d
Product GitLab gitlab
CVSS v3.1 KEV CWE-22 Exploit PoC
28 Aug/26
CVE-2026-82078
CRITICAL

This vulnerability is a dynamic class loading flaw in PaperCut MF and NG's database connection utilities. The root cause is the application's instantiation of database driver classes based on configurable driver names without validating these against an allowlist of approved drivers. This unsafe dynamic loading occurs within the database connection component, enabling untrusted class loading from the application classpath.

CVSS 9.1
EPSS 63.5%
KEV Pred 77%
Product PaperCut MF/NG papercut
CVSS v3.1 CVSS v4.0 KEV CWE-470 Exploit RANSOMWARE
28 Aug/26
CVE-2026-81578
CRITICAL

This vulnerability is an improper access control flaw in the web management interface of PaperCut MF and PaperCut NG. The root cause is the premature execution of backend administrative functions before completing access validation checks. This affects the administrative web interface component responsible for enforcing authentication and authorization controls on remote requests.

CVSS 9.8
EPSS 85.6%
KEV Pred 83%
Product PaperCut MF/NG papercut
CVSS v3.1 CVSS v4.0 KEV CWE-305 Exploit PoC RANSOMWARE
13 Aug/26
CVE-2026-73570
HIGH

This vulnerability is a command injection flaw rooted in improper sanitization of untrusted input within the SNMP notification processing component of Zimbra Collaboration Suite (ZCS). Specifically, when the optional zimbra-snmp package is installed and SNMP notifications are enabled, maliciously crafted SMTP requests can inject operating system commands. The flaw arises from inadequate input validation during the handling of SNMP notifications in affected ZCS versions prior to 10.1.20.

CVSS 8.9
EPSS 71.7%
KEV Pred 79%
Product Zimbra Collaboration zimbra
CVSS v3.1 KEV CWE-78 PoC RANSOMWARE
11 Aug/26
CVE-2026-71362
CRITICAL

The vulnerability in Adobe Commerce is an Incorrect Authorization flaw rooted in improper access control checks within the application. This issue arises from the failure to correctly enforce privilege restrictions on certain administrative functions, allowing unauthorized users to escalate privileges. The affected component is the authorization mechanism governing access to sensitive resources and administrative features in Adobe Commerce versions including 2.4.4 and its patches.

CVSS 9.1
EPSS 87.5%
KEV Pred 93%
Product Adobe Commerce adobe
CVSS v3.1 KEV CWE-863 PoC RANSOMWARE
27 Jul/26
CVE-2026-63077
CRITICAL

This vulnerability is an unsafe deserialization flaw (CWE-502) in the JetBrains TeamCity agent polling protocol. The root cause lies in improper validation and handling of serialized data received from unauthenticated remote sources during agent-server communication. The affected component is the TeamCity server's agent polling mechanism, which processes incoming serialized objects without adequate integrity or authenticity checks.

CVSS 9.8
EPSS 89.6%
KEV Pred 81%
Product JetBrains TeamCity jetbrains
CVSS v3.1 KEV CWE-502 Exploit PoC RANSOMWARE
22 Jul/26
CVE-2026-16232
CRITICAL

This vulnerability is an authentication bypass affecting the Check Point SmartConsole login process within the Quantum Security Management product. The root cause lies in improper validation of authentication tokens during the login sequence, allowing an unauthenticated attacker to retrieve a valid application login token. The flaw specifically impacts the authentication mechanism of the Management Server component when Trusted Clients restrictions are not enforced.

CVSS 9.8
EPSS 78.0%
KEV Pred 83%
Product checkpoint Quantum Security Management checkpoint
CVSS v3.1 CVSS v4.0 KEV CWE-287 Exploit PoC
14 Jul/26
CVE-2026-55040
CRITICAL

This vulnerability is an authentication bypass caused by weak authentication mechanisms within Microsoft Office SharePoint Enterprise Server 2016. The root cause lies in improper validation of authentication tokens or credentials during network-based access attempts. The affected component is the authentication subsystem of SharePoint Server, which fails to enforce adequate security checks, allowing unauthorized access to protected resources.

CVSS 9.1
EPSS 69.5%
KEV Pred 82%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-1390 PoC RANSOMWARE
20 Jun/26
CVE-2026-48908
CRITICAL

The vulnerability is an unrestricted file upload flaw in the SP Page Builder extension for Joomla, specifically within its file handling component. The root cause is the lack of proper validation and restriction on file types and content, allowing unauthenticated users to upload arbitrary files. This improper input validation affects the file upload functionality of the extension, enabling execution of unauthorized code on the server.

CVSS 9.8
EPSS 88.5%
KEV Pred 79%
Product joomshaper.net SP Page Builder extension for Joomla joomshaper.net
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
10 Jun/26
CVE-2026-20253
CRITICAL

This vulnerability is an authentication bypass affecting the PostgreSQL sidecar service endpoint in Splunk Enterprise. The root cause is the absence of authentication controls on this endpoint, which allows unauthenticated network users to invoke file operations. The affected component is the PostgreSQL sidecar service integrated within Splunk Enterprise versions prior to 10.2.4 and 10.0.7.

CVSS 9.8
EPSS 96.9%
KEV Pred 78%
Product Splunk Enterprise splunk
CVSS v3.1 KEV CWE-306 PoC
09 Jun/26
CVE-2026-25089
CRITICAL

This vulnerability is an OS command injection flaw caused by improper neutralization of special elements within HTTP request parameters. The root cause lies in Fortinet FortiSandbox's failure to sanitize user-supplied input before incorporating it into operating system commands. Affected components include FortiSandbox versions 4.2.x, 4.4.0 through 4.4.8, 5.0.0 through 5.0.5, FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5.

CVSS 9.8
EPSS 76.1%
KEV Pred 83%
Product Fortinet FortiSandbox fortinet
CVSS v3.1 KEV CWE-78 PoC RANSOMWARE
09 Jun/26
CVE-2026-10520
CRITICAL

The vulnerability is an OS command injection caused by improper sanitization of user-supplied input within Ivanti Sentry's command execution routines. This flaw resides in the input handling of specific components responsible for processing remote commands, allowing crafted inputs to be interpreted as shell commands. The affected feature is the command processing mechanism in Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1.

CVSS 10.0
EPSS 99.9%
KEV Pred 81%
Product ivanti Sentry ivanti
CVSS v3.1 KEV CWE-78 PoC RANSOMWARE
08 Jun/26
CVE-2026-50751
CRITICAL

This vulnerability is an authentication bypass caused by a logic flaw in the certificate validation process within the deprecated IKEv1 key exchange protocol. The flaw exists in the Remote Access and Mobile Access components of the Check Point Quantum Security Gateway, specifically in the handling of certificate validation during VPN connection establishment. The root cause is improper validation logic that fails to verify user credentials correctly, allowing unauthorized access through the affected authentication mechanism.

CVSS 9.3
EPSS 85.3%
KEV Pred 92%
Product checkpoint Quantum Security Gateway checkpoint
CVSS v3.1 KEV CWE-287 PoC RANSOMWARE
04 Jun/26
CVE-2026-8037
CRITICAL

This vulnerability is an OS command injection flaw arising from improper input sanitization within multiple API command endpoints of the Progress Software LoadMaster appliance. The root cause is the failure to validate or sanitize user-supplied parameters before passing them to underlying system command execution functions. The affected component is the LoadMaster's API interface handling command inputs, which processes these inputs insecurely, enabling injection of arbitrary operating system commands.

CVSS 9.6
EPSS 77.4%
KEV Pred 83%
Product Progress Software LoadMaster progress
CVSS v3.1 KEV CWE-77 PoC
03 Jun/26
CVE-2026-20230
HIGH

This vulnerability is a server-side request forgery (SSRF) rooted in improper input validation of specific HTTP requests within Cisco Unified Communications Manager and its Session Management Edition. The flaw occurs in the WebDialer service component, which processes crafted HTTP requests without adequate sanitization. The underlying mechanism allows unauthorized external input to influence internal server requests and file operations on the affected device's operating system.

CVSS 8.6
EPSS 88.2%
KEV Pred 77%
Product Cisco Unified Communications Manager cisco
CVSS v3.1 KEV CWE-918 PoC
14 May/26
CVE-2026-20182
CRITICAL

This vulnerability is an authentication bypass in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller and Manager. The root cause lies in improper validation during the control connection handshaking process, allowing crafted requests to circumvent authentication checks. The affected component is the peering authentication feature responsible for establishing secure control connections within the SD-WAN fabric.

CVSS 10.0
EPSS 91.5%
KEV Pred 83%
Product Cisco Catalyst SD-WAN Manager cisco
CVSS v3.1 KEV CWE-287 Exploit PoC RANSOMWARE
13 May/26
CVE-2026-0257
CRITICAL

This vulnerability is an authentication bypass affecting the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS software. The root cause lies in improper validation of authentication mechanisms allowing unauthorized users to circumvent security checks. The flaw specifically impacts the VPN authentication process, enabling access without valid credentials.

CVSS 9.1
EPSS 96.9%
KEV Pred 93%
Product Palo Alto Networks Cloud NGFW palo
CVSS v3.1 CVSS v4.0 KEV CWE-565 PoC RANSOMWARE
08 May/26
CVE-2026-42271
HIGH

This vulnerability is a command injection flaw in the LiteLLM proxy server component, specifically affecting the AI Gateway's handling of server configuration inputs. The root cause lies in two POST endpoints (/mcp-rest/test/connection and /mcp-rest/test/tools/list) that accept unvalidated server configuration data, including command, args, and env fields, which are executed via stdio transport as subprocesses with proxy process privileges. The lack of role-based access control combined with acceptance of arbitrary commands enables exploitation.

CVSS 8.8
EPSS 92.6%
KEV Pred 76%
Product BerriAI litellm berriai
CVSS v3.1 CVSS v4.0 KEV CWE-77 Exploit PoC
29 Apr/26
CVE-2026-41940
CRITICAL

This vulnerability is an authentication bypass affecting the login flow component of cPanel and WHM versions post-11.40. The root cause lies in improper validation of authentication tokens or session handling mechanisms, allowing unauthenticated requests to bypass normal login checks. The flaw specifically compromises the authentication logic within the web-based control panel interface, enabling unauthorized access without valid credentials.

CVSS 9.8
EPSS 98.5%
KEV Pred 80%
Product cPanel cpanel
CVSS v3.1 CVSS v4.0 KEV CWE-306 Exploit PoC RANSOMWARE
04 Mar/26
CVE-2026-20079
CRITICAL

This vulnerability is an authentication bypass in the web interface of Cisco Secure Firewall Management Center (FMC) caused by an improper system process created during device boot. The flaw resides in the handling of HTTP requests by the FMC software, allowing unauthenticated attackers to trigger unauthorized system-level script execution. The affected component is the FMC's web management interface running on specific versions prior to 7.0.3.

CVSS 10.0
EPSS 88.2%
KEV Pred 83%
Product Cisco Secure Firewall Management Center (FMC) cisco
CVSS v3.1 KEV CWE-288 Exploit PoC RANSOMWARE
25 Feb/26
CVE-2026-20127
CRITICAL

This vulnerability is an authentication bypass affecting the peering authentication mechanism in Cisco Catalyst SD-WAN Controller and Manager components. The root cause lies in improper validation of authentication requests during the peering process, which fails to enforce correct credentials. This flaw resides specifically within the peering authentication subsystem responsible for establishing trust between SD-WAN nodes.

CVSS 10.0
EPSS 88.5%
KEV Pred 80%
Product Cisco Catalyst SD-WAN Manager cisco
CVSS v3.1 KEV CWE-287 Exploit PoC RANSOMWARE
13 Feb/26
CVE-2026-2441
HIGH

This vulnerability is a use-after-free memory corruption issue occurring in the CSS processing component of Google Chrome. The root cause lies in improper management of memory lifecycle for CSS objects, leading to references to freed memory. The flaw affects the rendering engine responsible for parsing and applying CSS styles within the browser's sandboxed environment.

CVSS 8.8
EPSS 55.1%
KEV Pred 71%
Product Google Chrome google
CVSS v3.1 KEV CWE-416 PoC
06 Feb/26
CVE-2026-1731
CRITICAL

This vulnerability is a pre-authentication remote code execution caused by improper input validation in BeyondTrust Remote Support and older Privileged Remote Access versions. The root cause lies in the WebSocket endpoint /nw, which accepts binary payloads without adequate sanitization, allowing injection of operating system commands. The affected components are the WebSocket service and the mechanism that retrieves the company identifier via the /get_mech_list endpoint, which is exploited to authenticate the malicious WebSocket connection.

CVSS 9.8
EPSS 90.9%
KEV Pred 78%
Product BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA) beyondtrust
CVSS v3.1 CVSS v4.0 KEV CWE-78 Exploit PoC RANSOMWARE
06 Feb/26
CVE-2026-21643
CRITICAL

This vulnerability is a SQL injection flaw rooted in improper neutralization of special characters within SQL commands. The issue arises from insufficient input validation in the Fortinet FortiClientEMS web interface, allowing crafted HTTP requests to manipulate backend database queries. The affected component is the FortiClientEMS management system version 7.4.4, specifically its handling of SQL statements triggered by user-supplied input.

CVSS 9.8
EPSS 93.9%
KEV Pred 80%
Product Fortinet FortiClientEMS fortinet
CVSS v3.1 KEV CWE-89 PoC RANSOMWARE
29 Jan/26
CVE-2026-1340
CRITICAL

This vulnerability is a code injection flaw rooted in improper input validation within Ivanti Endpoint Manager Mobile. The affected component fails to sanitize user-supplied data before processing, enabling malicious payloads to be injected and executed. The flaw resides in the core mobile management service handling remote commands or scripts without adequate security controls.

CVSS 9.8
EPSS 98.6%
KEV Pred 71%
Product Ivanti Endpoint Manager Mobile ivanti
CVSS v3.1 KEV CWE-94 Exploit RANSOMWARE
29 Jan/26
CVE-2026-1281
CRITICAL

This vulnerability is a code injection flaw rooted in improper input validation within Ivanti Endpoint Manager Mobile. The affected component fails to sanitize user-supplied input, enabling injection of arbitrary code into the execution context. The flaw exists in the core processing logic of the mobile management interface, allowing unfiltered data to be executed by the system.

CVSS 9.8
EPSS 98.7%
KEV Pred 71%
Product Ivanti Endpoint Manager Mobile ivanti
CVSS v3.1 KEV CWE-94 Exploit PoC RANSOMWARE
28 Jan/26
CVE-2025-40551
CRITICAL

The vulnerability is an untrusted data deserialization flaw within SolarWinds Web Help Desk, specifically affecting its data processing components that handle serialized input. The root cause lies in improper validation and sanitization of serialized objects received by the application, allowing maliciously crafted serialized data to be deserialized and executed. This flaw resides in the deserialization logic of the Web Help Desk service, which processes incoming serialized payloads without integrity checks or authentication.

CVSS 9.8
EPSS 84.2%
KEV Pred 76%
Product SolarWinds Web Help Desk solarwinds
CVSS v3.1 KEV CWE-502 Exploit RANSOMWARE
28 Jan/26
CVE-2025-40536
CRITICAL

This vulnerability is a security control bypass affecting SolarWinds Web Help Desk, rooted in insufficient enforcement of access restrictions within the application's web interface. The flaw allows unauthenticated users to circumvent authentication and authorization controls, exposing restricted administrative functions. The affected component is the Web Help Desk application prior to version 12.8.8 Hotfix 1, where access control mechanisms fail to properly validate user privileges on sensitive endpoints.

CVSS 9.8
EPSS 73.6%
KEV Pred 73%
Product SolarWinds Web Help Desk solarwinds
CVSS v3.1 KEV CWE-693 Exploit PoC
27 Jan/26
CVE-2026-24858
CRITICAL

This vulnerability is an authentication bypass caused by improper validation of FortiCloud SSO authentication tokens. The flaw resides in Fortinet FortiOS and associated products, where the authentication mechanism fails to correctly verify user-device bindings. This allows an attacker with a valid FortiCloud account and a registered device to exploit alternate authentication paths, bypassing standard credential checks within the FortiCloud SSO integration component.

CVSS 9.8
EPSS 85.8%
KEV Pred 81%
Product Fortinet FortiOS fortinet
CVSS v3.1 KEV CWE-288 PoC RANSOMWARE
23 Jan/26
CVE-2026-24423
CRITICAL

This vulnerability is an unauthenticated remote code execution flaw caused by missing authentication controls in the ConnectToHub API method of SmarterTools SmarterMail. The root cause is that the ConnectToHub function accepts and executes OS commands obtained from an external HTTP server without validating the source or requiring authentication. This affects SmarterMail versions prior to build 9511, specifically the ConnectToHub API component responsible for hub communication.

CVSS 9.8
EPSS 88.2%
KEV Pred 78%
Product SmarterTools SmarterMail smartertools
CVSS v3.1 CVSS v4.0 KEV CWE-306 PoC RANSOMWARE
23 Jan/26
CVE-2026-0770
CRITICAL

This vulnerability is a remote code execution flaw caused by improper handling of the exec_globals parameter in Langflow's validate endpoint. The root cause lies in the inclusion of resources from an untrusted control sphere, allowing unvalidated input to be executed within the application's global execution context. The affected component is the exec_globals parameter processing within the validate API endpoint of Langflow.

CVSS 9.8
EPSS 63.0%
KEV Pred 71%
Product Langflow langflow
CVSS v3.1 KEV CWE-829 Exploit PoC
22 Jan/26
CVE-2026-23760
CRITICAL

This vulnerability is an authentication bypass in the password reset API of SmarterTools SmarterMail prior to build 9511. The flaw arises from the force-reset-password endpoint allowing unauthenticated requests without validating existing credentials or reset tokens. The affected component is the system administrator password reset functionality within the SmarterMail API.

CVSS 9.8
EPSS 96.5%
KEV Pred 73%
Product SmarterTools SmarterMail smartertools
CVSS v3.1 CVSS v4.0 KEV CWE-288 PoC RANSOMWARE
21 Jan/26
CVE-2026-24061
CRITICAL

This vulnerability is an authentication bypass in the telnetd daemon of GNU Inetutils versions up to 2.7. The root cause lies in improper handling of the USER environment variable, where passing a specially crafted value "-f root" bypasses normal authentication checks. The affected component is the telnetd service responsible for remote login sessions.

CVSS 9.8
EPSS 99.0%
KEV Pred 71%
Product GNU Inetutils gnu
CVSS v3.1 KEV CWE-88 Exploit PoC RANSOMWARE
20 Jan/26
CVE-2026-21962
CRITICAL

This vulnerability is an authentication bypass in the Oracle Weblogic Server Proxy Plug-in components for Apache HTTP Server and IIS. It arises from improper access control enforcement in the proxy plug-in, allowing unauthenticated network requests via HTTP to interact with internal server functions. The affected components include Oracle HTTP Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, and Weblogic Server Proxy Plug-in versions 12.2.1.4.0 and 14.1.1.0.0.

CVSS 10.0
EPSS 73.2%
KEV Pred 71%
Product Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in oracle
CVSS v3.1 KEV CWE-284 PoC RANSOMWARE
29 Dec/25
CVE-2025-52691
CRITICAL

This vulnerability is an unrestricted file upload flaw in SmarterTools SmarterMail's mail server component. The root cause lies in insufficient validation of uploaded file paths and names in the POST /api/upload endpoint. This allows unauthenticated users to manipulate file path parameters, bypassing normal upload restrictions and placing files arbitrarily on the server filesystem.

CVSS 10.0
EPSS 85.7%
KEV Pred 81%
Product SmarterTools SmarterMail smartertools
CVSS v3.1 KEV CWE-434 Exploit PoC RANSOMWARE
19 Dec/25
CVE-2025-68613
HIGH

This vulnerability is a critical remote code execution flaw caused by insufficient isolation in the workflow expression evaluation component of n8n. The root cause lies in the evaluation context for expressions supplied by authenticated users during workflow configuration, which is not adequately sandboxed from the underlying Node.js runtime environment. This permits execution of arbitrary code within the n8n process context via crafted expressions.

CVSS 8.8
EPSS 99.0%
KEV Pred 81%
Product n8n-io n8n n8n-io
CVSS v3.1 KEV CWE-913 Exploit PoC
19 Dec/25
CVE-2025-14847
HIGH

This vulnerability is a memory disclosure issue caused by improper handling of Zlib compressed protocol headers within the MongoDB Server's wire protocol. Specifically, mismatched length fields in the compressed data lead to reading uninitialized heap memory due to the server trusting the client-declared uncompressed size without proper memory initialization. The flaw resides in the zlib decompression logic processing OP_COMPRESSED messages, affecting multiple MongoDB Server versions across several major releases.

CVSS 7.5
EPSS 83.2%
KEV Pred 81%
Product MongoDB Inc. MongoDB Server mongodb
CVSS v3.1 CVSS v4.0 KEV CWE-130 Exploit PoC RANSOMWARE
16 Dec/25
CVE-2025-37164
CRITICAL

This vulnerability is a remote code execution flaw caused by improper input validation leading to unsafe dynamic command execution within the HPE OneView API. Specifically, the issue arises from the /rest/id-pools/executeCommand endpoint, which accepts user-supplied commands without adequate sanitization. The affected component is the HPE OneView REST API service, which processes these commands and executes them on the underlying system, enabling injection of arbitrary commands.

CVSS 9.8
EPSS 90.2%
KEV Pred 81%
Product Hewlett Packard Enterprise (HPE) HPE OneView hewlett
CVSS v3.1 KEV CWE-94 Exploit PoC
12 Dec/25
CVE-2025-14611
CRITICAL

This vulnerability is a hardcoded credentials flaw involving the use of fixed AES cryptographic keys within Gladinet CentreStack and TrioFox prior to version 16.12.10420.56791. The root cause lies in the insecure implementation of AES cryptoscheme parameters embedded directly in the application code. This affects cryptographic components responsible for securing communications and file handling in publicly exposed endpoints of the affected products.

CVSS 9.8
EPSS 53.3%
KEV Pred 83%
Product Gladinet CentreStack and TrioFox gladinet
CVSS v3.1 CVSS v4.0 KEV CWE-798 Exploit PoC RANSOMWARE
10 Dec/25
CVE-2025-8110
HIGH

This vulnerability is a symbolic link (symlink) bypass flaw in the PutContents API of the Gogs self-hosted Git service. The root cause lies in improper handling of symlinks during file write operations, where the API fails to verify if the target file paths are symlinks pointing outside the intended repository directory. This allows authenticated users to manipulate file system paths, affecting the repository management component responsible for content storage.

CVSS 8.8
EPSS 85.2%
KEV Pred 81%
Product Gogs gogs
CVSS v3.1 CVSS v4.0 KEV CWE-22 PoC
09 Dec/25
CVE-2025-59718
CRITICAL

This vulnerability is an authentication bypass caused by improper verification of cryptographic signatures within the SAML response processing mechanism. The flaw resides in Fortinet FortiSwitchManager and related Fortinet products where the cryptographic signature validation logic fails to correctly authenticate SAML assertions. This defect affects the FortiCloud Single Sign-On (SSO) login component, enabling manipulation of authentication tokens without proper signature validation.

CVSS 9.8
EPSS 68.3%
KEV Pred 83%
Product Fortinet FortiSwitchManager fortinet
CVSS v3.1 KEV CWE-347 PoC RANSOMWARE
05 Dec/25
CVE-2025-34291
HIGH

This vulnerability in Langflow arises from a chained security flaw involving an overly permissive Cross-Origin Resource Sharing (CORS) configuration combined with insecure cookie attributes. Specifically, the CORS policy allows all origins with credentials enabled (allow_origins='*' and allow_credentials=True), while the refresh token cookie is set with SameSite=None, permitting cross-origin requests to include authentication tokens. The affected component is the refresh token endpoint responsible for issuing new access tokens, which improperly trusts attacker-controlled origins, enabling unauthorized token retrieval.

CVSS 8.8
EPSS 92.8%
KEV Pred 81%
Product Langflow langflow
CVSS v3.1 CVSS v4.0 KEV CWE-346 PoC
03 Dec/25
CVE-2025-55182
CRITICAL

This vulnerability is a remote code execution flaw caused by unsafe deserialization of untrusted payloads in React Server Components. The issue arises from the deserialization logic in server function endpoints that process HTTP requests, specifically within the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages. Affected versions include 19.0.0 through 19.2.0 of the React Server Components framework.

CVSS 10.0
EPSS 99.8%
KEV Pred 84%
Product Meta react-server-dom-webpack meta
CVSS v3.1 KEV CWE-502 Exploit PoC RANSOMWARE
26 Nov/25
CVE-2025-62593
HIGH

This vulnerability is a remote code execution flaw rooted in improper validation of the User-Agent header within the Ray AI compute engine’s development tooling. The defense mechanism relies on detecting the User-Agent header starting with "Mozilla" to prevent browser-based attacks, but this check is insufficient because the fetch specification permits modification of this header. The affected component is the browser interaction layer in Ray versions prior to 2.52.0, which fails to properly restrict requests, enabling exploitation via DNS rebinding attacks combined with manipulated User-Agent headers.

CVSS 8.8
EPSS 62.5%
KEV Pred 63%
Product ray-project ray ray-project
CVSS v3.1 CVSS v4.0 KEV CWE-94 PoC
25 Nov/25
CVE-2025-58360
CRITICAL

This vulnerability is an XML External Entity (XXE) injection affecting GeoServer's XML input processing. The root cause is insufficient sanitization and restriction of XML external entity definitions within the XML payload submitted to the /geoserver/wms GetMap operation. This flaw resides in the XML parser component handling user-supplied XML data, enabling malicious entity expansion.

CVSS 9.8
EPSS 60.5%
KEV Pred 83%
Product geoserver geoserver
CVSS v3.1 KEV CWE-611 Exploit PoC
18 Nov/25
CVE-2025-58034
HIGH

This vulnerability is an authenticated OS command injection affecting Fortinet FortiWeb versions 7.0.0 through 8.0.1. The root cause is improper neutralization of special elements in user-supplied input, allowing crafted HTTP requests or CLI commands to be interpreted and executed by the underlying operating system. The flaw resides in input handling mechanisms within FortiWeb's management interfaces that fail to sanitize command parameters adequately.

CVSS 7.2
EPSS 55.6%
KEV Pred 78%
Product Fortinet FortiWeb fortinet
CVSS v3.1 KEV CWE-78 Exploit RANSOMWARE
14 Nov/25
CVE-2025-64446
CRITICAL

This vulnerability is a relative path traversal flaw in the Fortinet FortiWeb web application firewall. It arises from improper validation of user-supplied input in HTTP/HTTPS requests, specifically within the API endpoint handling administrative system configurations. The flaw allows crafted requests to traverse directories and access restricted CGI scripts, bypassing normal access controls in the affected FortiWeb versions.

CVSS 9.8
EPSS 91.8%
KEV Pred 93%
Product Fortinet FortiWeb fortinet
CVSS v3.1 KEV CWE-23 Exploit PoC RANSOMWARE
07 Nov/25
CVE-2025-64328
HIGH

This vulnerability is a post-authentication command injection in the filestore module of FreePBX Endpoint Manager. The root cause is improper input sanitization in the check_ssh_connect() function invoked via the testconnection feature within the Administrative interface. The flaw allows execution of arbitrary commands due to unsafe handling of SSH connection parameters by authenticated users.

CVSS 7.2
EPSS 84.6%
KEV Pred 81%
Product FreePBX filestore freepbx
CVSS v3.1 CVSS v4.0 KEV CWE-78 Exploit PoC
03 Nov/25
CVE-2025-11953
CRITICAL

This vulnerability is an OS command injection in the Metro Development Server component of the React Native Community CLI. The root cause is that the server binds to external network interfaces by default and exposes an endpoint that improperly sanitizes input, allowing execution of arbitrary system commands. The flaw specifically affects the command execution handling within the server's exposed endpoint, enabling injection of shell commands on Windows platforms with fully controlled arguments.

CVSS 9.8
EPSS 94.0%
KEV Pred 84%
Product React Native Community CLI react
CVSS v3.1 KEV CWE-78 PoC
21 Oct/25
CVE-2025-61757
CRITICAL

This vulnerability is an authentication bypass in the REST WebServices component of Oracle Identity Manager. The root cause lies in improper access control validation on specific REST API endpoints, allowing unauthenticated network access via HTTP. Affected components include the RESTful interface responsible for governance and application management functions in versions 12.2.1.4.0 and 14.1.2.1.0.

CVSS 9.8
EPSS 88.6%
KEV Pred 84%
Product Oracle Corporation Identity Manager oracle
CVSS v3.1 KEV CWE-306 PoC RANSOMWARE
Page 1 of 8 (399 total)