Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.5
CVE-2026-54420 KEV
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web s…
Litespeed Cpanel Plugin
2.4.8 / 5.3.2.0+
CRITICAL 10.0
CVE-2026-48558 KEVEPSS 11%
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. Whe…
Simplehelp
5.5.16+
CRITICAL 9.8
CVE-2026-35273 KEVEPSS 95%
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions t…
Peoplesoft Enterprise Peopletools
Mitigation only
CRITICAL 9.8
CVE-2026-20253 KEVEPSS 97%
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files throug…
Splunk
10.0.7 / 10.2.4+
CRITICAL 9.8
CVE-2026-25089 KEVEPSS 74%
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0…
Fortisandbox
4.4.9 / 5.0.6+
CRITICAL 10.0
CVE-2026-10520 KEVEPSS 100%
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie…
Standalone Sentry
10.5.2 / 10.6.2+
HIGH 8.8
CVE-2026-11645 KEV
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via …
Chrome
149.0.7827.103+
CRITICAL 9.3
CVE-2026-50751 KEVEPSS 83%
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote att…
Gaia Os
Patch available
MEDIUM 5.8
CVE-2026-7473 KEV
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (G…
Eos
Mitigation only
CRITICAL 9.8
CVE-2026-48907 KEVEPSS 69%
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in …
Jce
2.9.99.5+
HIGH 7.8
CVE-2026-20245 KEVEPSS 25%
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and C…
Catalyst Sd Wan Manager
20.9.9.1 / 20.12.5.4+
HIGH 7.5
CVE-2026-28318 KEVEPSS 8%
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: defl…
Serv U
15.5.4+
CRITICAL 9.8
CVE-2026-8037 KEVEPSS 99%
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary com…
Connection Manager For Objectscale
7.2.54.18 / 7.2.63.2+
HIGH 8.6
CVE-2026-20230 KEVEPSS 83%
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM …
Unified Communications Manager
14su6+
HIGH 8.4
CVE-2025-48595 KEV
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege…
Android
Mitigation only
CRITICAL 9.8
CVE-2026-46817 KEVEPSS 13%
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.…
E Business Suite
after 12.2.15
CRITICAL 9.8
CVE-2026-48027 KEV
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and remove…
Nx Console
Mitigation only
CRITICAL 9.8
CVE-2026-45247 KEVEPSS 28%
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attack…
Full Page Cache Warmer
1.11.12+
HIGH 8.8
CVE-2026-45659 KEVEPSS 10%
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20280+
CRITICAL 10.0
CVE-2026-34910 KEVEPSS 87%
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command …
Unifi Os Server
5.0.8 / 5.1.12+
CRITICAL 10.0
CVE-2026-34909 KEVEPSS 64%
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying…
Unifi Os Server
5.0.8 / 5.1.12+
CRITICAL 10.0
CVE-2026-34908 KEVEPSS 85%
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized ch…
Unifi Os Server
5.0.8 / 5.1.12+
MEDIUM 6.7
CVE-2026-34926 KEVEPSS 13%
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the s…
Apex One
14.0.0.17079 / 14.0.20731+
CRITICAL 9.8
CVE-2026-48172 KEVEPSS 19%
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best…
Litespeed Cpanel Plugin
2.4.7 / 5.3.1.0+
CRITICAL 9.8
CVE-2026-9082 KEVEPSS 88%
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This …
Drupal
10.4.10 / 10.5.10+
HIGH 7.5
CVE-2026-45498 KEVEPSS 63%
Microsoft Defender Denial of Service Vulnerability
Defender Antimalware Platform
4.18.26040.7+
HIGH 7.8
CVE-2026-41091 KEVEPSS 10%
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Malware Protection Engine
1.1.26040.8+
CRITICAL 9.8
CVE-2026-8398 KEV
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distrib…
Daemon Tools
Mitigation only
MEDIUM 6.1
CVE-2026-42897 KEVEPSS 70%
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …
Exchange Server
15.02.2562.043+
CRITICAL 10.0
CVE-2026-20182 KEVEPSS 92%
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed …
Catalyst Sd Wan Manager
20.9.9.1 / 20.12.5.4+