Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Litespeed Cpanel Plugin HIGH 8.5
CVE-2026-54420 KEV

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web s…

Fix: 2.4.8 / 5.3.2.0+
Fix from $1,950 2026-06-14
Simplehelp CRITICAL 10.0
CVE-2026-48558 KEVEPSS 11%

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. Whe…

Fix: 5.5.16+
Fix from $2,300 2026-06-12
Peoplesoft Enterprise Peopletools CRITICAL 9.8
CVE-2026-35273 KEVEPSS 95%

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions t…

Mitigation only
Fix from $2,300 2026-06-11
Splunk CRITICAL 9.8
CVE-2026-20253 KEVEPSS 97%

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files throug…

Fix: 10.0.7 / 10.2.4+
Fix from $2,300 2026-06-10
Fortisandbox CRITICAL 9.8
CVE-2026-25089 KEVEPSS 74%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0…

Fix: 4.4.9 / 5.0.6+
Fix from $2,300 2026-06-09
Standalone Sentry CRITICAL 10.0
CVE-2026-10520 KEVEPSS 100%

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie…

Fix: 10.5.2 / 10.6.2+
Fix from $2,300 2026-06-09
Chrome HIGH 8.8
CVE-2026-11645 KEV

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via …

Fix: 149.0.7827.103+
Fix from $1,950 2026-06-09
Gaia Os CRITICAL 9.3
CVE-2026-50751 KEVEPSS 83%

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote att…

Patch available
Fix from $2,300 2026-06-08
Eos MEDIUM 5.8
CVE-2026-7473 KEV

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (G…

Mitigation only
Fix from $1,600 2026-06-05
Jce CRITICAL 9.8
CVE-2026-48907 KEVEPSS 69%

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in …

Fix: 2.9.99.5+
Fix from $2,300 2026-06-05
Catalyst Sd Wan Manager HIGH 7.8
CVE-2026-20245 KEVEPSS 25%

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and C…

Fix: 20.9.9.1 / 20.12.5.4+
Fix from $1,950 2026-06-04
Serv U HIGH 7.5
CVE-2026-28318 KEVEPSS 8%

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: defl…

Fix: 15.5.4+
Fix from $1,950 2026-06-04
Connection Manager For Objectscale CRITICAL 9.8
CVE-2026-8037 KEVEPSS 99%

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary com…

Fix: 7.2.54.18 / 7.2.63.2+
Fix from $2,300 2026-06-04
Unified Communications Manager HIGH 8.6
CVE-2026-20230 KEVEPSS 83%

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM …

Fix: 14su6+
Fix from $1,950 2026-06-03
Android HIGH 8.4
CVE-2025-48595 KEV

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege…

Mitigation only
Fix from $1,950 2026-06-01
E Business Suite CRITICAL 9.8
CVE-2026-46817 KEVEPSS 13%

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.…

Fix: after 12.2.15
Fix from $2,300 2026-05-28
Nx Console CRITICAL 9.8
CVE-2026-48027 KEV

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and remove…

Mitigation only
Fix from $2,300 2026-05-27
Full Page Cache Warmer CRITICAL 9.8
CVE-2026-45247 KEVEPSS 28%

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attack…

Fix: 1.11.12+
Fix from $2,300 2026-05-26
Sharepoint Server HIGH 8.8
CVE-2026-45659 KEVEPSS 10%

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20280+
Fix from $1,950 2026-05-22
Unifi Os Server CRITICAL 10.0
CVE-2026-34910 KEVEPSS 87%

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command …

Fix: 5.0.8 / 5.1.12+
Fix from $2,300 2026-05-22
Unifi Os Server CRITICAL 10.0
CVE-2026-34909 KEVEPSS 64%

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying…

Fix: 5.0.8 / 5.1.12+
Fix from $2,300 2026-05-22
Unifi Os Server CRITICAL 10.0
CVE-2026-34908 KEVEPSS 85%

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized ch…

Fix: 5.0.8 / 5.1.12+
Fix from $2,300 2026-05-22
Apex One MEDIUM 6.7
CVE-2026-34926 KEVEPSS 13%

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the s…

Fix: 14.0.0.17079 / 14.0.20731+
Fix from $1,600 2026-05-21
Litespeed Cpanel Plugin CRITICAL 9.8
CVE-2026-48172 KEVEPSS 19%

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best…

Fix: 2.4.7 / 5.3.1.0+
Fix from $2,300 2026-05-21
Drupal CRITICAL 9.8
CVE-2026-9082 KEVEPSS 88%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This …

Fix: 10.4.10 / 10.5.10+
Fix from $2,300 2026-05-20
Defender Antimalware Platform HIGH 7.5
CVE-2026-45498 KEVEPSS 63%

Microsoft Defender Denial of Service Vulnerability

Fix: 4.18.26040.7+
Fix from $1,950 2026-05-20
Malware Protection Engine HIGH 7.8
CVE-2026-41091 KEVEPSS 10%

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Fix: 1.1.26040.8+
Fix from $1,950 2026-05-20
Daemon Tools CRITICAL 9.8
CVE-2026-8398 KEV

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distrib…

Mitigation only
Fix from $2,300 2026-05-15
Exchange Server MEDIUM 6.1
CVE-2026-42897 KEVEPSS 70%

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …

Fix: 15.02.2562.043+
Fix from $1,600 2026-05-14
Catalyst Sd Wan Manager CRITICAL 10.0
CVE-2026-20182 KEVEPSS 92%

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed …

Fix: 20.9.9.1 / 20.12.5.4+
Fix from $2,300 2026-05-14