Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-20127 KEVEPSS 88% A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD… Catalyst Sd Wan Manager 20.9.8.2 / 20.12.5.3+ Fix from $2,3002026-02-25 MEDIUM 5.4 CVE-2026-20122 KEVEPSS 25% A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local f… Catalyst Sd Wan Manager 20.9.8.2 / 20.12.5.3+ Fix from $1,6002026-02-25 CRITICAL 10.0 CVE-2026-22769 KEVEPSS 13% Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as a… Recoverpoint For Virtual Machines 6.0+ Fix from $2,3002026-02-17 HIGH 8.8 CVE-2026-2441 KEVEPSS 22% Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML… Chrome 145.0.7632.75 / 145.0.7632.76+ Fix from $1,9502026-02-13 HIGH 8.8 CVE-2026-25108 KEV FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted… Filezen 5.0.11+ Fix from $1,9502026-02-13 HIGH 7.8 CVE-2026-20700 KEV A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3,… Ipados 26.3+ Fix from $1,9502026-02-11 HIGH 7.8 CVE-2026-21533 KEV Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 MEDIUM 6.2 CVE-2026-21525 KEV Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,6002026-02-10 HIGH 7.8 CVE-2026-21519 KEV Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21514 KEV Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. 365 Apps Mitigation only Fix from $1,9502026-02-10 HIGH 8.8 CVE-2026-21513 KEVEPSS 15% Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 8.8 CVE-2026-21510 KEVEPSS 26% Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-1603 KEVEPSS 81% An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credenti… Endpoint Manager 2024+ Fix from $1,9502026-02-10 MEDIUM 5.9 CVE-2025-68686 KEV An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS … Fortios 7.4.7 / 7.6.2+ Fix from $1,6002026-02-10 CRITICAL 9.8 CVE-2026-1731 KEVEPSS 88% BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execut… Privileged Remote Access 25.1 / 25.3.2+ Fix from $2,3002026-02-06 CRITICAL 9.8 CVE-2026-21643 KEVEPSS 94% An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an u… Forticlientems Mitigation only Fix from $2,3002026-02-06 HIGH 7.5 CVE-2025-15556 KEV Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update meta… Notepad\+\+ 8.8.9+ Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2026-1340 KEVEPSS 86% A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Endpoint Manager Mobile after 12.7.0.0 Fix from $2,3002026-01-29 CRITICAL 9.8 CVE-2026-1281 KEVEPSS 82% A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Endpoint Manager Mobile after 12.5.0.0 Fix from $2,3002026-01-29 CRITICAL 9.8 CVE-2025-40551 KEVEPSS 84% SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi… Web Help Desk 2026.1+ Fix from $2,3002026-01-28 CRITICAL 9.8 CVE-2025-40536 KEVEPSS 72% SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated att… Web Help Desk 2026.1+ Fix from $2,3002026-01-28 CRITICAL 9.8 CVE-2026-24858 KEVEPSS 86% An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Fort… Fortianalyzer 7.4.10 / 7.4.11+ Fix from $2,3002026-01-27 HIGH 7.8 CVE-2026-21509 KEVEPSS 72% Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. 365 Apps Mitigation only Fix from $1,9502026-01-26 CRITICAL 9.8 CVE-2026-24423 KEVEPSS 88% SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. … Smartermail 100.0.9511+ Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0770 KEVEPSS 57% Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote … Langflow after 1.7.3 Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-23760 KEVEPSS 96% SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-passw… Smartermail 100.0.9511+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-20045 KEV A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME… Unified Communications Manager 14su5+ Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2026-24061 KEVEPSS 98% telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. Debian Linux after 2.7 Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2026-20963 KEVEPSS 32% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20442+ Fix from $2,3002026-01-13 MEDIUM 5.5 CVE-2026-20805 KEVEPSS 5% Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13