CVEs with confirmed in-the-wild exploitation, drawn from the CISA Known Exploited Vulnerabilities (KEV) catalog and the ENISA EU Vulnerability Database (EUVD) exploited flag, most recent first. Subscribe via the Atom feed.
Recently flagged as exploited
CVE-2026-85706 — CVSS 10.0 (critical): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2…
CVE-2026-84869 — CVSS 9.9 (critical): A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without…
CVE-2026-42018 — CVSS 7.5 (high): JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially…
CVE-2026-42016 — CVSS 8.1 (high): JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the…
CVE-2026-86060 — CVSS 9.8 (critical): RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for…
CVE-2026-67277 — CVSS 8.2 (high): RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated…
CVE-2026-87491 — CVSS 8.8 (high): Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox…
CVE-2026-20079 — CVSS 10.0 (critical): A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote…
CVE-2026-19490 — CVSS 9.8 (critical): Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway…
CVE-2025-25249 — CVSS 8.1 (high): A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through…
CVE-2026-86218 — CVSS 9.8 (critical): N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
CVE-2026-85880 — CVSS 7.8 (high): Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-81963 — CVSS 7.8 (high): Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges…
CVE-2026-75650 — CVSS 10.0 (critical): Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in…
CVE-2026-85046 — CVSS 8.8 (high): Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a…
CVE-2026-9586 — CVSS 9.8 (critical): An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content…
CVE-2026-83549 — CVSS 7.8 (high): Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been…
CVE-2026-83548 — CVSS 10.0 (critical): A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A…
CVE-2026-82329 — CVSS 9.8 (critical): JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network…
CVE-2026-59822 — CVSS 8.2 (high): LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP…
CVE-2026-49869 — CVSS 10.0 (critical): Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses…
CVE-2026-48710 — CVSS 6.5 (medium): Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being…
CVE-2026-82078 — CVSS 9.1 (critical): An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application…
CVE-2026-81578 — CVSS 9.8 (critical): An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions…
CVE-2026-66384 — CVSS 5.3 (medium): An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVE-2026-53362 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In…
CVE-2023-49105 — CVSS 9.8 (critical): An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication…
CVE-2026-8452 — CVSS 9.8 (critical): Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if…
CVE-2022-0995 — CVSS 7.8 (high): An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can…
CVE-2021-23758 — CVSS 8.1 (high): All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of…
CVE-2019-1068 — CVSS 8.8 (high): A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka…
CVE-2015-5287 — CVSS 7.8 (high): The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain…
CVE-2015-3246 — CVSS 5.1 (medium): libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd…
CVE-2026-21962 — CVSS 10.0 (critical): Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic…
CVE-2026-73570 — CVSS 8.9 (high): A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is…
CVE-2026-72530 — CVSS 9.0 (critical): A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X…
CVE-2026-72529 — CVSS 9.8 (critical): A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X…
CVE-2026-64849 — CVSS 9.3 (critical): MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the…
CVE-2026-65400 — CVSS 9.8 (critical): An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9…
CVE-2026-59310 — CVSS 9.8 (critical): VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may…
CVE-2026-55040 — CVSS 9.1 (critical): Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
CVE-2025-62593 — CVSS 8.8 (high): Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE…
CVE-2026-72898 — CVSS 10.0 (critical): Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain…
CVE-2026-68820 — CVSS 7.0 (high): Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-20349 — CVSS 8.6 (high): A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure…
CVE-2026-8037 — CVSS 9.6 (critical): OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute…
CVE-2026-63077 — CVSS 9.8 (critical): In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
CVE-2026-9198 — CVSS 9.8 (critical): IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network…