Cut the noise.
Know which vulnerabilities demand action.

Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.

Analytics

EPSS Trending (30d)

Threat Indicators

865
CISA KEV
251
Exploits
519
Proof-of-Concept
40.1%
Average EPSS

EPSS Hot Zone

|
Sort by:
KEV Prediction — Top%
EPSS Percentile — Top%

Emerging Vulnerabilities

19 Aug/26
CVE-2026-72530
CRITICAL

This vulnerability is a code injection flaw classified under CWE-94, caused by improper handling of user-supplied scripts within the TrueConf Server isolated environment. The root cause lies in insufficient validation and sanitization of input scripts processed on port 4307/TCP, allowing crafted payloads to escape sandbox restrictions. The affected component is the script execution environment in TrueConf Server versions 5.3.x through 5.5.5 on Windows and Linux platforms.

CVSS 9.0
EPSS 1.0%
KEV Pred in 25d
Product TrueConf Server trueconf
CVSS v3.1 CVSS v4.0 KEV CWE-94
19 Aug/26
CVE-2026-72529
CRITICAL

This vulnerability is an authentication bypass (CWE-306) affecting TrueConf Server's internal function handling. The root cause is the presence of an undocumented function accessible over network port 4307/TCP that lacks authentication controls, allowing unauthorized invocation. The affected component is the TrueConf Server software versions 5.3.x through 5.5.5 on both Windows and Linux platforms.

CVSS 9.8
EPSS 0.8%
KEV Pred in 25d
Product TrueConf Server trueconf
CVSS v3.1 CVSS v4.0 KEV CWE-306
17 Aug/26
CVE-2026-64849
CRITICAL

This vulnerability is a server-side request forgery (SSRF) caused by improper validation of webhook URLs in MLflow's webhook testing endpoint. The root cause lies in inconsistent URL validation: the _validate_webhook_url() function only checks the original URL, while subsequent HTTP requests follow redirects and re-resolve hostnames without enforcing address pinning. This flaw affects the POST /api/2.0/mlflow/webhooks/{id}/test endpoint, specifically in the webhook URL validation and delivery components.

CVSS 9.3
EPSS 8.2%
KEV Pred in 23d
Product mlflow mlflow
CVSS v3.1 KEV CWE-918 PoC
13 Aug/26
CVE-2026-73570
HIGH

This vulnerability is a command injection flaw rooted in improper sanitization of untrusted input within the SNMP notification processing component of Zimbra Collaboration Suite (ZCS). Specifically, when the optional zimbra-snmp package is installed and SNMP notifications are enabled, maliciously crafted SMTP requests can inject operating system commands. The flaw arises from inadequate input validation during the handling of SNMP notifications in affected ZCS versions prior to 10.1.20.

CVSS 8.9
EPSS 1.0%
KEV Pred in 19d
Product Zimbra Collaboration zimbra
CVSS v3.1 KEV CWE-78
11 Aug/26
CVE-2026-20349
HIGH

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

CVSS 8.6
EPSS 1.0%
KEV Pred in 17d
Product Cisco Secure Firewall Adaptive Security Appliance (ASA) Software cisco
CVSS v3.1 KEV CWE-244
10 Aug/26
CVE-2026-72898
CRITICAL

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

CVSS 10.0
EPSS 10.4%
KEV Pred in 16d
Product Metabase metabase
CVSS v3.1 CVSS v4.0 KEV CWE-89 PoC
06 Aug/26
CVE-2026-65400
CRITICAL

This vulnerability is an authentication bypass issue rooted in improper state management within the Screen Sharing service of Apple macOS. The flaw allows network-based attackers to circumvent authentication controls by exploiting how session state is handled during the authentication process. The affected component is the Screen Sharing feature across multiple macOS versions, where authentication validation does not adequately verify credential legitimacy.

CVSS 9.8
EPSS 0.8%
KEV Pred in 12d
Product Apple macOS apple
CVSS v3.1 KEV CWE-287 PoC
02 Aug/26
CVE-2026-18577
HIGH

This vulnerability is an authentication bypass stemming from an incomplete patch applied to N-able N-central versions through 2026.3.1. The root cause lies in improper validation of authentication tokens within the access control mechanism, specifically affecting the authentication workflow component. The flaw allows bypassing normal authentication checks due to insufficient verification logic in the session validation process.

CVSS 8.2
EPSS 4.1%
KEV Pred in 8d
Product N-able N-central n-able
CVSS v4.0 KEV CWE-288 PoC
01 Aug/26
CVE-2026-18556
HIGH

This vulnerability is an authentication bypass in N-able N-central caused by improper validation of authentication mechanisms, allowing an attacker to circumvent normal authentication controls. The root cause lies in an alternate path or channel within the authentication process that fails to enforce required credentials. This flaw affects the authentication component of N-central versions through 2026.1, enabling unauthorized access through this bypass vector.

CVSS 7.4
EPSS 0.5%
KEV Pred in 7d
Product N-able N-central n-able
CVSS v3.1 CVSS v4.0 KEV CWE-288 PoC
30 Jul/26
CVE-2026-59310
CRITICAL

This vulnerability is a directory traversal flaw within the VMware vCenter Syslog server component of VMware Cloud Foundation. The root cause lies in insufficient validation of file path inputs, allowing crafted requests to access arbitrary filesystem locations. This improper sanitization enables manipulation of file paths processed by the Syslog server, exposing underlying system directories.

CVSS 9.8
EPSS 2.4%
KEV Pred in 5d
Product VMware Cloud Foundation vmware
CVSS v3.1 KEV CWE-22 PoC RANSOMWARE
29 Jul/26
CVE-2026-20316
MEDIUM

This vulnerability is an authentication bypass caused by the presence of static user credentials embedded within the Cisco Secure Firewall Management Center (FMC) web interface. The root cause lies in the use of hardcoded low-privileged account credentials that allow unauthenticated remote access. The affected component is the FMC management software's web interface authentication mechanism, which fails to enforce unique or dynamic credential validation for this account.

CVSS 5.3
EPSS 0.8%
KEV Pred in 4d
Product Cisco Secure Firewall Management Center (FMC) cisco
CVSS v3.1 KEV CWE-259
27 Jul/26
CVE-2026-63077
CRITICAL

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CVSS 9.8
EPSS 12.0%
KEV Pred in 2d
Product JetBrains TeamCity jetbrains
CVSS v3.1 KEV CWE-502 PoC
27 Jul/26
CVE-2026-16812
CRITICAL

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.

CVSS 10.0
EPSS 0.9%
KEV Pred in 2d
Product Arista Networks VeloCloud Orchestrator On-Prem arista
CVSS v3.1 CVSS v4.0 KEV CWE-78
22 Jul/26
CVE-2026-16232
CRITICAL

This vulnerability is an authentication bypass affecting the Check Point SmartConsole login process within the Quantum Security Management product. The root cause lies in improper validation of authentication tokens during the login sequence, allowing an unauthenticated attacker to retrieve a valid application login token. The flaw specifically impacts the authentication mechanism of the Management Server component when Trusted Clients restrictions are not enforced.

CVSS 9.8
EPSS 73.3%
KEV Pred 73%
Product checkpoint Quantum Security Management checkpoint
CVSS v3.1 CVSS v4.0 KEV CWE-287 PoC
17 Jul/26
CVE-2026-63030
CRITICAL

This vulnerability is a SQL injection rooted in a route confusion issue within the WordPress REST API batch endpoint. The flaw arises from improper handling of the author__not_in parameter in WP_Query, which allows crafted queries to bypass intended filtering. The affected component is the REST API batch endpoint in WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2, where route resolution errors enable injection of malicious SQL commands.

CVSS 9.8
EPSS 95.6%
KEV Pred 71%
Product WordPress wordpress
CVSS v3.1 KEV CWE-436 Exploit PoC
17 Jul/26
CVE-2026-60137
MEDIUM

This vulnerability is a SQL Injection flaw caused by improper sanitization of the author__not_in parameter within the WP_Query component of WordPress. The root cause lies in the failure to validate or escape untrusted input passed to this parameter, allowing malicious input to be interpreted as part of an SQL query. This affects the query construction logic in WordPress versions prior to 6.8.6, 6.9.5, and 7.0.2.

CVSS 5.9
EPSS 73.1%
KEV Pred 70%
Product WordPress wordpress
CVSS v3.1 KEV CWE-89 Exploit PoC
17 Jul/26
CVE-2026-9198
CRITICAL

This vulnerability is a chained authentication bypass and arbitrary code execution flaw in IBM Langflow OSS versions 1.0.0 through 1.10.0. The root cause lies in the /api/v1/auto_login endpoint, which mints SUPERUSER tokens without authentication, combined with the /api/v1/validate/code endpoint that executes user-supplied code via the unsafe use of exec(). These two components together enable unauthorized execution of arbitrary commands on default Langflow deployments.

CVSS 9.8
EPSS 18.8%
KEV Pred 67%
Product IBM Langflow OSS ibm
CVSS v3.1 KEV CWE-94 Exploit PoC
16 Jul/26
CVE-2021-27137
HIGH

This vulnerability is a stack-based buffer overflow caused by the use of an unsafe strcpy operation within the UPnP handling code of DD-WRT's ssdp.c component. Specifically, the flaw exists in the ssdp_msearch function which processes M-SEARCH requests. The root cause is the lack of proper boundary checks when copying incoming data into a fixed-size internal buffer, affecting the UPnP feature of the router firmware.

CVSS 8.1
EPSS 16.5%
KEV Pred 73%
Product DD-WRT dd-wrt
CVSS v3.1 KEV CWE-121
14 Jul/26
CVE-2026-15410
HIGH

This vulnerability is a post-authentication code injection flaw rooted in improper control over code generation within the SonicWall SMA1000 Appliance Management Console (AMC). The vulnerability arises due to insufficient validation of user-supplied input that is incorporated into command execution contexts. The affected component is the AMC interface, which processes administrative commands and configurations.

CVSS 7.2
EPSS 76.3%
KEV Pred 65%
Product SonicWall SMA1000 sonicwall
CVSS v3.1 KEV CWE-94 Exploit PoC RANSOMWARE
14 Jul/26
CVE-2026-15409
CRITICAL

This vulnerability is a Server-Side Request Forgery (SSRF) affecting the SonicWall SMA1000 Appliance Work Place interface. The root cause lies in improper validation of user-supplied URLs, allowing the appliance to be manipulated into making arbitrary HTTP requests. The flaw exists within the appliance's internal request handling mechanism, specifically in the interface that processes incoming request parameters without adequate origin verification.

CVSS 10.0
EPSS 74.2%
KEV Pred 73%
Product SonicWall SMA1000 sonicwall
CVSS v3.1 KEV CWE-918 Exploit PoC RANSOMWARE
14 Jul/26
CVE-2026-55040
CRITICAL

This vulnerability is an authentication bypass caused by weak authentication mechanisms within Microsoft Office SharePoint. The root cause lies in improper validation of authentication tokens or credentials, allowing unauthorized access. The affected component is the authentication subsystem of Microsoft SharePoint Enterprise Server 2016 and related versions, which fails to enforce proper security checks over network requests.

CVSS 9.1
EPSS 5.5%
KEV Pred 71%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-1390 PoC RANSOMWARE
14 Jul/26
CVE-2026-58644
CRITICAL

This vulnerability is a deserialization flaw occurring within Microsoft Office SharePoint's data processing components. It arises from improper handling of untrusted serialized input, allowing maliciously crafted data to be processed without sufficient validation. The affected component is the deserialization mechanism in Microsoft SharePoint Enterprise Server 2016 and related versions, which fails to securely parse incoming serialized objects over network interfaces.

CVSS 9.8
EPSS 45.5%
KEV Pred 78%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-502 RANSOMWARE
14 Jul/26
CVE-2026-50522
CRITICAL

This vulnerability is a deserialization flaw in Microsoft Office SharePoint's handling of untrusted data. The root cause lies in insecure deserialization logic within SharePoint Enterprise Server 2016 and related versions, where unvalidated input is processed by deserialization routines. This affects the SharePoint server component responsible for processing serialized data objects over network requests.

CVSS 9.8
EPSS 77.0%
KEV Pred 78%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-502 PoC RANSOMWARE
14 Jul/26
CVE-2026-56164
MEDIUM

This vulnerability is an authentication bypass caused by missing authentication checks on critical functions within Microsoft Office SharePoint. The root cause stems from insufficient access control enforcement in the SharePoint Enterprise Server 2016 component, allowing unauthenticated network requests to invoke privileged operations. The flaw specifically affects the authentication mechanism protecting sensitive SharePoint server functions.

CVSS 5.3
EPSS 22.4%
KEV Pred 79%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-306 PoC RANSOMWARE
09 Jul/26
CVE-2026-56291
CRITICAL

This vulnerability is an unauthenticated arbitrary file upload flaw in the Balbooa Forms extension for Joomla. The root cause lies in insufficient validation and sanitization of uploaded files within the form submission handler, allowing executable files to be accepted and stored. The affected component is the file upload functionality of the Balbooa Forms Joomla extension, which fails to restrict file types or enforce authentication checks before processing uploads.

CVSS 9.8
EPSS 76.1%
KEV Pred 67%
Product balbooa.com Balbooa Forms extension for Joomla balbooa.com
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
30 Jun/26
CVE-2026-48282
CRITICAL

This vulnerability is a path traversal flaw caused by insufficient validation of user-supplied file path inputs within Adobe ColdFusion. The affected component improperly restricts pathname access, allowing attackers to traverse directories outside intended boundaries. This weakness occurs in ColdFusion versions 2023 and earlier, impacting the file handling mechanisms responsible for directory access control.

CVSS 10.0
EPSS 99.2%
KEV Pred 82%
Product Adobe ColdFusion adobe
CVSS v3.1 KEV CWE-22 PoC RANSOMWARE
29 Jun/26
CVE-2026-56290
CRITICAL

This vulnerability is an unauthenticated arbitrary file upload flaw in the JoomlaCK.fr Page Builder CK extension for Joomla. The root cause lies in insufficient validation and filtering of uploaded files within the extension's file upload functionality. The affected component is the file upload handler that processes incoming files without proper authentication or content-type restrictions, enabling malicious payloads to be uploaded.

CVSS 9.8
EPSS 83.3%
KEV Pred 62%
Product JoomlaCK.fr Page Builder CK extension for Joomla joomlack.fr
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
23 Jun/26
CVE-2026-55255
HIGH

The vulnerability is an Insecure Direct Object Reference (IDOR) affecting the /api/v1/responses endpoint of the langflow-ai langflow product. The root cause is insufficient authorization validation allowing authenticated users to specify arbitrary flow IDs belonging to other users. This flaw resides in the API's access control mechanism for flow execution requests prior to version 1.9.1.

CVSS 8.4
EPSS 29.1%
KEV Pred 65%
Product langflow-ai langflow langflow-ai
CVSS v3.1 KEV CWE-639 PoC
20 Jun/26
CVE-2026-48908
CRITICAL

This vulnerability is an unrestricted file upload flaw in the SP Page Builder extension for Joomla. The root cause is insufficient validation and sanitization of uploaded files, allowing unauthenticated users to upload arbitrary files, including executable PHP scripts. The affected component is the file upload functionality within the SP Page Builder extension.

CVSS 9.8
EPSS 88.1%
KEV Pred 58%
Product joomshaper.net SP Page Builder extension for Joomla joomshaper.net
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
20 Jun/26
CVE-2026-48939
CRITICAL

The vulnerability is an arbitrary file upload flaw rooted in improper validation of file attachments within the iCagenda extension for Joomla. The file attachment feature lacks sufficient sanitization and filtering controls, enabling the upload of malicious files. This weakness resides specifically in the file handling component of the iCagenda extension, allowing attackers to bypass restrictions on executable content types.

CVSS 9.8
EPSS 82.5%
KEV Pred 59%
Product icagenda.com iCagenda extension for Joomla icagenda.com
CVSS v3.1 CVSS v4.0 KEV CWE-434 PoC
18 Jun/26
CVE-2026-12569
CRITICAL

This vulnerability is a remote code execution flaw resulting from insecure deserialization of untrusted data within PTC Windchill PDMLink and FlexPLM components. Specifically, the deserialization process fails to properly validate or sanitize incoming serialized objects, allowing malicious payloads to be executed during object reconstruction. The affected components include all CPS versions and Windchill/FlexPLM releases prior to 11.0 M030, where the deserialization functionality is exposed to network input.

CVSS 9.8
EPSS 30.2%
KEV Pred 83%
Product PTC Windchill PDMLink ptc
CVSS v3.1 CVSS v4.0 KEV CWE-20 RANSOMWARE
15 Jun/26
CVE-2026-20262
MEDIUM

This vulnerability is a path traversal flaw (CWE-22) in the file upload functionality of Cisco Catalyst SD-WAN Manager's web UI. The root cause is improper validation of user-supplied input during the file upload process, allowing crafted input to manipulate file paths. The affected component is the API endpoint handling file uploads within the web management interface.

CVSS 6.5
EPSS 28.2%
KEV Pred 69%
Product Cisco Catalyst SD-WAN Manager cisco
CVSS v3.1 KEV CWE-22 PoC
14 Jun/26
CVE-2026-54420
HIGH

This vulnerability is a symbolic link (symlink) traversal issue in the LiteSpeed cPanel plugin and LiteSpeed WHM plugin components. The root cause lies in improper validation and handling of user-supplied symlink paths within the plugin's file management routines. Specifically, the plugin fails to correctly restrict symlink resolution for users with FTP or web shell access on shared hosting environments using CloudLinux/CageFS, enabling unauthorized access to filesystem locations outside intended boundaries.

CVSS 8.5
EPSS 1.4%
KEV Pred 69%
Product LiteSpeed Technologies cPanel Plugin litespeed
CVSS v3.1 KEV CWE-61 PoC
12 Jun/26
CVE-2026-48558
CRITICAL

This vulnerability is an authentication bypass caused by improper validation of OIDC identity tokens within SimpleHelp's authentication flow. The flaw arises because the system accepts identity tokens without verifying their cryptographic signatures. The affected component is the OIDC authentication mechanism in SimpleHelp versions 5.5.15 and earlier, as well as 6.0 pre-release versions.

CVSS 10.0
EPSS 11.5%
KEV Pred 68%
Product SimpleHelp simplehelp
CVSS v3.1 CVSS v4.0 KEV CWE-347 PoC RANSOMWARE
11 Jun/26
CVE-2026-35273
CRITICAL

This vulnerability is an authentication bypass flaw in the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools. The root cause is insufficient access control on HTTP endpoints responsible for environment updates, allowing unauthenticated network requests to interact with privileged management functions. Affected components are versions 8.61 and 8.62 of PeopleSoft Enterprise PeopleTools.

CVSS 9.8
EPSS 95.5%
KEV Pred 69%
Product Oracle Corporation PeopleSoft Enterprise PeopleTools oracle
CVSS v3.1 KEV CWE-306 PoC RANSOMWARE
10 Jun/26
CVE-2026-20253
CRITICAL

This vulnerability is an authentication bypass affecting the PostgreSQL sidecar service endpoint in Splunk Enterprise. The root cause is the absence of authentication controls on this endpoint, which allows unauthenticated network users to invoke file operations. The affected component is the PostgreSQL sidecar service integrated within Splunk Enterprise versions prior to 10.2.4 and 10.0.7.

CVSS 9.8
EPSS 96.9%
KEV Pred 61%
Product Splunk Enterprise splunk
CVSS v3.1 KEV CWE-306 PoC
09 Jun/26
CVE-2026-25089
CRITICAL

This vulnerability is an OS command injection flaw caused by improper neutralization of special elements within HTTP request parameters. The root cause lies in Fortinet FortiSandbox's failure to sanitize user-supplied input before incorporating it into operating system commands. Affected components include FortiSandbox versions 4.2.x, 4.4.0 through 4.4.8, 5.0.0 through 5.0.5, FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5.

CVSS 9.8
EPSS 73.6%
KEV Pred 80%
Product Fortinet FortiSandbox fortinet
CVSS v3.1 KEV CWE-78 PoC RANSOMWARE
09 Jun/26
CVE-2026-10520
CRITICAL

The vulnerability is an OS command injection rooted in improper input validation within Ivanti Sentry's command execution routines. Specifically, the affected component fails to sanitize user-supplied input before passing it to underlying system shell commands. This flaw exists in versions prior to R10.5.2, R10.6.2, and R10.7.1, impacting the command processing mechanism that interfaces with the operating system shell.

CVSS 10.0
EPSS 99.9%
KEV Pred 77%
Product ivanti Sentry ivanti
CVSS v3.1 KEV CWE-78 PoC RANSOMWARE
08 Jun/26
CVE-2026-11645
HIGH

This vulnerability is an out-of-bounds read and write flaw occurring within the V8 JavaScript engine of Google Chrome. The root cause lies in improper bounds checking during memory operations, allowing access beyond allocated buffer limits. The affected component is the V8 engine, which handles JavaScript execution within the browser sandbox environment.

CVSS 8.8
EPSS 2.2%
KEV Pred 68%
Product Google Chrome google
CVSS v3.1 KEV CWE-125 PoC
08 Jun/26
CVE-2026-50751
CRITICAL

This vulnerability is an authentication bypass caused by a logic flaw in the certificate validation process within the deprecated IKEv1 key exchange protocol. The flaw exists in the Remote Access and Mobile Access components of the Check Point Quantum Security Gateway, specifically in the handling of certificate validation during VPN connection establishment. The root cause is improper validation logic that fails to verify user credentials correctly, allowing unauthorized access through the affected authentication mechanism.

CVSS 9.3
EPSS 82.6%
KEV Pred 79%
Product checkpoint Quantum Security Gateway checkpoint
CVSS v3.1 KEV CWE-287 PoC RANSOMWARE
05 Jun/26
CVE-2026-7473
MEDIUM

This vulnerability is a protocol decapsulation validation flaw affecting Arista Networks EOS tunnel processing components. Specifically, the switch fails to verify the tunnel protocol type when decapsulating packets on VXLAN, decap-groups, or GRE tunnel interfaces. This improper validation causes the device to incorrectly process tunneled packets with a destination IP matching its configured decapsulation IP regardless of the actual tunnel protocol, leading to unintended packet forwarding behavior.

CVSS 5.8
EPSS 1.1%
KEV Pred 69%
Product Arista Networks EOS arista
CVSS v3.1 CVSS v4.0 KEV CWE-1023 PoC
05 Jun/26
CVE-2026-48907
CRITICAL

The vulnerability is an authentication bypass in the Joomla Content Editor (JCE) extension for Joomla, allowing unauthenticated users to create new editor profiles. This flaw arises from improper access control validation in the profile creation component of the JCE editor. The affected feature is the editor profile management functionality within the JCE extension, which fails to restrict profile creation to authorized users only.

CVSS 9.8
EPSS 68.8%
KEV Pred 54%
Product joomlacontenteditor.net Joomla Content Editor (JCE) extension for Joomla joomlacontenteditor.net
CVSS v3.1 CVSS v4.0 KEV CWE-284 Exploit PoC
04 Jun/26
CVE-2026-28318
HIGH

This vulnerability is a denial-of-service condition caused by improper handling of HTTP POST requests with Content-Encoding set to deflate. The root cause lies in the Serv-U service's inability to correctly process specially crafted compressed payloads, leading to resource exhaustion or crash. The affected component is the Serv-U FTP server's HTTP request parsing logic, which does not require authentication to be triggered.

CVSS 7.5
EPSS 8.4%
KEV Pred 63%
Product SolarWinds Serv-U solarwinds
CVSS v3.1 KEV CWE-400 PoC
04 Jun/26
CVE-2026-8037
CRITICAL

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

CVSS 9.8
EPSS 99.3%
KEV Pred 72%
Product Progress Software LoadMaster progress
CVSS v3.1 KEV CWE-77 PoC
03 Jun/26
CVE-2026-20230
HIGH

This vulnerability is a server-side request forgery (SSRF) arising from improper input validation of specific HTTP requests in Cisco Unified Communications Manager and its Session Management Edition. The flaw exists within the WebDialer service component, which processes HTTP requests without sufficient sanitization, allowing crafted requests to manipulate internal server behavior. The root cause is the lack of validation on input parameters that control file operations on the underlying operating system.

CVSS 8.6
EPSS 83.2%
KEV Pred 69%
Product Cisco Unified Communications Manager cisco
CVSS v3.1 KEV CWE-918 PoC
28 May/26
CVE-2026-46817
CRITICAL

This vulnerability is an authentication bypass in the File Transmission component of Oracle Payments within Oracle E-Business Suite. The root cause lies in insufficient access controls on network-accessible HTTP endpoints, allowing unauthenticated users to interact with sensitive functions. The affected component fails to properly verify credentials or session state before processing requests, enabling unauthorized access to critical payment processing features.

CVSS 9.8
EPSS 13.3%
KEV Pred 79%
Product Oracle Corporation Oracle Payments oracle
CVSS v3.1 KEV CWE-269 PoC RANSOMWARE
27 May/26
CVE-2026-48027
CRITICAL

The vulnerability involves a supply chain compromise where a maliciously altered version (18.95.0) of the Nx Console extension was published briefly on the Visual Studio Marketplace and OpenVSX. This tampered package contains unauthorized code injected into the extension's distribution, affecting the integrity of the Nx Console user interface component for Nx & Lerna. The root cause is the introduction of malicious payload within the extension's published package, bypassing normal validation or review processes.

CVSS 9.8
EPSS 1.8%
KEV Pred 68%
Product nrwl nx-console nrwl
CVSS v3.1 CVSS v4.0 KEV CWE-506 RANSOMWARE
26 May/26
CVE-2026-45247
CRITICAL

This vulnerability is a PHP object injection caused by the unsafe use of PHP's native unserialize() function on user-controlled input. Specifically, the CacheWarmer cookie in Mirasvit Full Page Cache Warmer for Magento 2 versions prior to 1.11.12 is processed without validation, allowing deserialization of crafted serialized PHP objects. The flaw resides in the cache warming component responsible for handling cache refresh requests and related cookie data.

CVSS 9.8
EPSS 27.5%
KEV Pred 69%
Product Mirasvit Full Page Cache Warmer for Magento 2 mirasvit
CVSS v3.1 CVSS v4.0 KEV CWE-502 PoC
22 May/26
CVE-2026-45659
HIGH

This vulnerability is a deserialization flaw in Microsoft Office SharePoint Enterprise Server 2016. It arises from improper handling of untrusted serialized data within SharePoint's data processing components, allowing maliciously crafted input to be deserialized. The affected component is the SharePoint server's deserialization mechanism responsible for processing serialized objects received over the network from authorized users.

CVSS 8.8
EPSS 9.9%
KEV Pred 73%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-502 PoC RANSOMWARE
22 May/26
CVE-2026-34910
CRITICAL

This vulnerability is a command injection flaw resulting from improper input validation in UniFi OS Server and related UniFi firmware components. The root cause lies in the failure to sanitize user-supplied input before passing it to system-level command execution functions. Affected components include UniFi OS Server and multiple UniFi device firmware versions, where network-accessible interfaces process untrusted input without adequate validation.

CVSS 10.0
EPSS 87.0%
KEV Pred 82%
Product Ubiquiti Inc UniFi OS Server ubiquiti
CVSS v3.1 KEV CWE-20 PoC
Page 1 of 18 (865 total)