Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.5 CVE-2026-54420 KEV LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web s… Litespeed Cpanel Plugin 2.4.8 / 5.3.2.0+ Fix from $1,9502026-06-14 CRITICAL 10.0 CVE-2026-48558 KEVEPSS 11% SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. Whe… Simplehelp 5.5.16+ Fix from $2,3002026-06-12 CRITICAL 9.8 CVE-2026-35273 KEVEPSS 95% Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions t… Peoplesoft Enterprise Peopletools Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.8 CVE-2026-20253 KEVEPSS 97% In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files throug… Splunk 10.0.7 / 10.2.4+ Fix from $2,3002026-06-10 CRITICAL 9.8 CVE-2026-25089 KEVEPSS 74% A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0… Fortisandbox 4.4.9 / 5.0.6+ Fix from $2,3002026-06-09 CRITICAL 10.0 CVE-2026-10520 KEVEPSS 100% An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie… Standalone Sentry 10.5.2 / 10.6.2+ Fix from $2,3002026-06-09 HIGH 8.8 CVE-2026-11645 KEV Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via … Chrome 149.0.7827.103+ Fix from $1,9502026-06-09 CRITICAL 9.3 CVE-2026-50751 KEVEPSS 83% A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote att… Gaia Os Patch available Fix from $2,3002026-06-08 MEDIUM 5.8 CVE-2026-7473 KEV On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (G… Eos Mitigation only Fix from $1,6002026-06-05 CRITICAL 9.8 CVE-2026-48907 KEVEPSS 69% A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in … Jce 2.9.99.5+ Fix from $2,3002026-06-05 HIGH 7.8 CVE-2026-20245 KEVEPSS 25% A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and C… Catalyst Sd Wan Manager 20.9.9.1 / 20.12.5.4+ Fix from $1,9502026-06-04 HIGH 7.5 CVE-2026-28318 KEVEPSS 8% SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: defl… Serv U 15.5.4+ Fix from $1,9502026-06-04 CRITICAL 9.8 CVE-2026-8037 KEVEPSS 99% OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary com… Connection Manager For Objectscale 7.2.54.18 / 7.2.63.2+ Fix from $2,3002026-06-04 HIGH 8.6 CVE-2026-20230 KEVEPSS 83% A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM … Unified Communications Manager 14su6+ Fix from $1,9502026-06-03 HIGH 8.4 CVE-2025-48595 KEV In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege… Android Mitigation only Fix from $1,9502026-06-01 CRITICAL 9.8 CVE-2026-46817 KEVEPSS 13% Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.… E Business Suite after 12.2.15 Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-48027 KEV Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and remove… Nx Console Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-45247 KEVEPSS 28% Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attack… Full Page Cache Warmer 1.11.12+ Fix from $2,3002026-05-26 HIGH 8.8 CVE-2026-45659 KEVEPSS 10% Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20280+ Fix from $1,9502026-05-22 CRITICAL 10.0 CVE-2026-34910 KEVEPSS 87% A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command … Unifi Os Server 5.0.8 / 5.1.12+ Fix from $2,3002026-05-22 CRITICAL 10.0 CVE-2026-34909 KEVEPSS 64% A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying… Unifi Os Server 5.0.8 / 5.1.12+ Fix from $2,3002026-05-22 CRITICAL 10.0 CVE-2026-34908 KEVEPSS 85% A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized ch… Unifi Os Server 5.0.8 / 5.1.12+ Fix from $2,3002026-05-22 MEDIUM 6.7 CVE-2026-34926 KEVEPSS 13% A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the s… Apex One 14.0.0.17079 / 14.0.20731+ Fix from $1,6002026-05-21 CRITICAL 9.8 CVE-2026-48172 KEVEPSS 19% LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best… Litespeed Cpanel Plugin 2.4.7 / 5.3.1.0+ Fix from $2,3002026-05-21 CRITICAL 9.8 CVE-2026-9082 KEVEPSS 88% Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This … Drupal 10.4.10 / 10.5.10+ Fix from $2,3002026-05-20 HIGH 7.5 CVE-2026-45498 KEVEPSS 63% Microsoft Defender Denial of Service Vulnerability Defender Antimalware Platform 4.18.26040.7+ Fix from $1,9502026-05-20 HIGH 7.8 CVE-2026-41091 KEVEPSS 10% Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. Malware Protection Engine 1.1.26040.8+ Fix from $1,9502026-05-20 CRITICAL 9.8 CVE-2026-8398 KEV A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distrib… Daemon Tools Mitigation only Fix from $2,3002026-05-15 MEDIUM 6.1 CVE-2026-42897 KEVEPSS 70% Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to … Exchange Server 15.02.2562.043+ Fix from $1,6002026-05-14 CRITICAL 10.0 CVE-2026-20182 KEVEPSS 92% May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed … Catalyst Sd Wan Manager 20.9.9.1 / 20.12.5.4+ Fix from $2,3002026-05-14