CVEs with confirmed in-the-wild exploitation, drawn from the CISA Known Exploited Vulnerabilities (KEV) catalog and the ENISA EU Vulnerability Database (EUVD) exploited flag, most recent first. Subscribe via the Atom feed.
Recently flagged as exploited
CVE-2026-73570 — CVSS 8.9 (high): A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is…
CVE-2026-72530 — CVSS 9.0 (critical): A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X…
CVE-2026-72529 — CVSS 9.8 (critical): A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X…
CVE-2026-64849 — CVSS 9.3 (critical): MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the…
CVE-2026-65400 — CVSS 9.8 (critical): An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9…
CVE-2026-59310 — CVSS 9.8 (critical): VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may…
CVE-2026-55040 — CVSS 9.1 (critical): Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
CVE-2025-62593 — CVSS 8.8 (high): Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE…
CVE-2026-72898 — CVSS 10.0 (critical): Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain…
CVE-2026-68820 — CVSS 7.0 (high): Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-20349 — CVSS 8.6 (high): A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure…
CVE-2026-8037 — CVSS 9.6 (critical): OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute…
CVE-2026-63077 — CVSS 9.8 (critical): In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
CVE-2026-9198 — CVSS 9.8 (critical): IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network…
CVE-2026-34486 — CVSS 7.5 (high): Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the…
CVE-2026-18556 — CVSS 7.4 (high): Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects…
CVE-2026-18577 — CVSS 8.1 (high): An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
CVE-2026-20316 — CVSS 5.3 (medium): A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote…
CVE-2026-16812 — CVSS 10.0 (critical): VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal…
CVE-2025-68686 — CVSS 5.9 (medium): An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through…
CVE-2026-50522 — CVSS 9.8 (critical): Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-16232 — CVSS 9.8 (critical): An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an…
CVE-2026-63030 — CVSS 9.8 (critical): WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the…
CVE-2026-60137 — CVSS 5.9 (medium): WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of…
CVE-2026-0770 — CVSS 9.8 (critical): Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability…
CVE-2021-27137 — CVSS 8.1 (high): An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an…
CVE-2026-58644 — CVSS 9.8 (critical): Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-39808 — CVSS 9.8 (critical): A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0…
CVE-2026-25089 — CVSS 9.8 (critical): A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0…
CVE-2026-46817 — CVSS 9.8 (critical): Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are…
CVE-2023-4346 — CVSS 7.5 (high): KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and…
CVE-2026-56164 — CVSS 5.3 (medium): Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a…
CVE-2026-56155 — CVSS 7.8 (high): Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate…
CVE-2026-15410 — CVSS 7.2 (high): Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance…
CVE-2026-15409 — CVSS 10.0 (critical): A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote…
CVE-2008-4128 — CVSS 4.3 (medium): Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated…
CVE-2026-56291 — CVSS 9.8 (critical): Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is…
CVE-2026-48939 — CVSS 9.8 (critical): A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately…
CVE-2026-56290 — CVSS 9.8 (critical): Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is…
CVE-2026-55255 — CVSS 8.4 (high): Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR)…
CVE-2026-48908 — CVSS 9.8 (critical): A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload…
CVE-2026-48282 — CVSS 10.0 (critical): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path…
CVE-2026-45659 — CVSS 8.8 (high): Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-48558 — CVSS 10.0 (critical): SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication…
CVE-2026-20230 — CVSS 8.6 (high): A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition…
CVE-2026-12569 — CVSS 9.8 (critical): A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be…
CVE-2026-34910 — CVSS 10.0 (critical): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute…
CVE-2026-34909 — CVSS 10.0 (critical): A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the…
CVE-2026-34908 — CVSS 10.0 (critical): A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make…