Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Catalyst Sd Wan Manager CRITICAL 10.0
CVE-2026-20127 KEVEPSS 88%

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD…

Fix: 20.9.8.2 / 20.12.5.3+
Fix from $2,300 2026-02-25
Catalyst Sd Wan Manager MEDIUM 5.4
CVE-2026-20122 KEVEPSS 25%

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local f…

Fix: 20.9.8.2 / 20.12.5.3+
Fix from $1,600 2026-02-25
Recoverpoint For Virtual Machines CRITICAL 10.0
CVE-2026-22769 KEVEPSS 13%

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as a…

Fix: 6.0+
Fix from $2,300 2026-02-17
Chrome HIGH 8.8
CVE-2026-2441 KEVEPSS 22%

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…

Fix: 145.0.7632.75 / 145.0.7632.76+
Fix from $1,950 2026-02-13
Filezen HIGH 8.8
CVE-2026-25108 KEV

FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted…

Fix: 5.0.11+
Fix from $1,950 2026-02-13
Ipados HIGH 7.8
CVE-2026-20700 KEV

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3,…

Fix: 26.3+
Fix from $1,950 2026-02-11
Windows 10 1607 HIGH 7.8
CVE-2026-21533 KEV

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 MEDIUM 6.2
CVE-2026-21525 KEV

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,600 2026-02-10
Windows 10 1607 HIGH 7.8
CVE-2026-21519 KEV

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
365 Apps HIGH 7.8
CVE-2026-21514 KEV

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

Mitigation only
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 8.8
CVE-2026-21513 KEVEPSS 15%

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 8.8
CVE-2026-21510 KEVEPSS 26%

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Endpoint Manager HIGH 7.5
CVE-2026-1603 KEVEPSS 81%

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credenti…

Fix: 2024+
Fix from $1,950 2026-02-10
Fortios MEDIUM 5.9
CVE-2025-68686 KEV

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS …

Fix: 7.4.7 / 7.6.2+
Fix from $1,600 2026-02-10
Privileged Remote Access CRITICAL 9.8
CVE-2026-1731 KEVEPSS 88%

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execut…

Fix: 25.1 / 25.3.2+
Fix from $2,300 2026-02-06
Forticlientems CRITICAL 9.8
CVE-2026-21643 KEVEPSS 94%

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an u…

Mitigation only
Fix from $2,300 2026-02-06
Notepad\+\+ HIGH 7.5
CVE-2025-15556 KEV

Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update meta…

Fix: 8.8.9+
Fix from $1,950 2026-02-03
Endpoint Manager Mobile CRITICAL 9.8
CVE-2026-1340 KEVEPSS 86%

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Fix: after 12.7.0.0
Fix from $2,300 2026-01-29
Endpoint Manager Mobile CRITICAL 9.8
CVE-2026-1281 KEVEPSS 82%

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Fix: after 12.5.0.0
Fix from $2,300 2026-01-29
Web Help Desk CRITICAL 9.8
CVE-2025-40551 KEVEPSS 84%

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40536 KEVEPSS 72%

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated att…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Fortianalyzer CRITICAL 9.8
CVE-2026-24858 KEVEPSS 86%

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Fort…

Fix: 7.4.10 / 7.4.11+
Fix from $2,300 2026-01-27
365 Apps HIGH 7.8
CVE-2026-21509 KEVEPSS 72%

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Mitigation only
Fix from $1,950 2026-01-26
Smartermail CRITICAL 9.8
CVE-2026-24423 KEVEPSS 88%

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. …

Fix: 100.0.9511+
Fix from $2,300 2026-01-23
Langflow CRITICAL 9.8
CVE-2026-0770 KEVEPSS 57%

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote …

Fix: after 1.7.3
Fix from $2,300 2026-01-23
Smartermail CRITICAL 9.8
CVE-2026-23760 KEVEPSS 96%

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-passw…

Fix: 100.0.9511+
Fix from $2,300 2026-01-22
Unified Communications Manager CRITICAL 9.8
CVE-2026-20045 KEV

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME…

Fix: 14su5+
Fix from $2,300 2026-01-21
Debian Linux CRITICAL 9.8
CVE-2026-24061 KEVEPSS 98%

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

Fix: after 2.7
Fix from $2,300 2026-01-21
Sharepoint Server CRITICAL 9.8
CVE-2026-20963 KEVEPSS 32%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19127.20442+
Fix from $2,300 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20805 KEVEPSS 5%

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13