Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 10.0
CVE-2026-20127 KEVEPSS 88%
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD…
Catalyst Sd Wan Manager
20.9.8.2 / 20.12.5.3+
MEDIUM 5.4
CVE-2026-20122 KEVEPSS 25%
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local f…
Catalyst Sd Wan Manager
20.9.8.2 / 20.12.5.3+
CRITICAL 10.0
CVE-2026-22769 KEVEPSS 13%
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as a…
Recoverpoint For Virtual Machines
6.0+
HIGH 8.8
CVE-2026-2441 KEVEPSS 22%
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…
Chrome
145.0.7632.75 / 145.0.7632.76+
HIGH 8.8
CVE-2026-25108 KEV
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted…
Filezen
5.0.11+
HIGH 7.8
CVE-2026-20700 KEV
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3,…
Ipados
26.3+
HIGH 7.8
CVE-2026-21533 KEV
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
MEDIUM 6.2
CVE-2026-21525 KEV
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.8
CVE-2026-21519 KEV
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.8
CVE-2026-21514 KEV
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
365 Apps
Mitigation only
HIGH 8.8
CVE-2026-21513 KEVEPSS 15%
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 8.8
CVE-2026-21510 KEVEPSS 26%
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.5
CVE-2026-1603 KEVEPSS 81%
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credenti…
Endpoint Manager
2024+
MEDIUM 5.9
CVE-2025-68686 KEV
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS …
Fortios
7.4.7 / 7.6.2+
CRITICAL 9.8
CVE-2026-1731 KEVEPSS 88%
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execut…
Privileged Remote Access
25.1 / 25.3.2+
CRITICAL 9.8
CVE-2026-21643 KEVEPSS 94%
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an u…
Forticlientems
Mitigation only
HIGH 7.5
CVE-2025-15556 KEV
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update meta…
Notepad\+\+
8.8.9+
CRITICAL 9.8
CVE-2026-1340 KEVEPSS 86%
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Endpoint Manager Mobile
after 12.7.0.0
CRITICAL 9.8
CVE-2026-1281 KEVEPSS 82%
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Endpoint Manager Mobile
after 12.5.0.0
CRITICAL 9.8
CVE-2025-40551 KEVEPSS 84%
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi…
Web Help Desk
2026.1+
CRITICAL 9.8
CVE-2025-40536 KEVEPSS 72%
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated att…
Web Help Desk
2026.1+
CRITICAL 9.8
CVE-2026-24858 KEVEPSS 86%
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Fort…
Fortianalyzer
7.4.10 / 7.4.11+
HIGH 7.8
CVE-2026-21509 KEVEPSS 72%
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
365 Apps
Mitigation only
CRITICAL 9.8
CVE-2026-24423 KEVEPSS 88%
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. …
Smartermail
100.0.9511+
CRITICAL 9.8
CVE-2026-0770 KEVEPSS 57%
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote …
Langflow
after 1.7.3
CRITICAL 9.8
CVE-2026-23760 KEVEPSS 96%
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-passw…
Smartermail
100.0.9511+
CRITICAL 9.8
CVE-2026-20045 KEV
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME…
Unified Communications Manager
14su5+
CRITICAL 9.8
CVE-2026-24061 KEVEPSS 98%
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Debian Linux
after 2.7
CRITICAL 9.8
CVE-2026-20963 KEVEPSS 32%
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19127.20442+
MEDIUM 5.5
CVE-2026-20805 KEVEPSS 5%
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+